Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes you need to trust the software. But unless you don't store it on your computer, you need to trust software. The hard part is to figure out which software and whom to trust.

I would definitely use the browser password manager, if I could choose where to sync the data to. I think it's possible with firefox, but it's not straight forward.

I personally trust pfp, because the creator is doing audits of browser addons and publishes them on his blog. They are very well explained.

Also the code is quite compact compared to the other password managers. LastPass, 1Password and Bitwarden have more than 100,000 lines of code, including many third party dependencies. So an audit of PfP is more feasible.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: