SQRL went through all these things in slow motion. Or at least that's how it felt listening to the "Security Now" podcast.
SQRL went through all these things in slow motion. Or at least that's how it felt listening to the "Security Now" podcast.
Note that the recommended operation for GoKey requires the use of a seed file. Instead of deriving passwords directly from the master password, it derives them from a file of random data that is decrypted by the master password.
While it's true that this seed file doesn't require the ongoing synchronization that a vault does, it's something that you need to have, and to manage with care.
Double plus ungood.
But even if it rarely changes, how would that file be synced in practice? Probably dropped in a Syncthing or Nextcloud folder. And if you do that, you may as well drop a Keepass file in there, and not have to deal with the many problems that this "vaultless" solution cause.