Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I agree that this is probably a bit to complicated for normal users.

My personal problem with lastpass is that by default your passwords are recoverable which means that by default lastpass or someone with access to their system has access to your passwords (you can disable this and read the source to their obfuscated javascript app for chrome to make sure that it is really doing what they say, encrypting locally then sending).[1]

Keepass at least is opensource and it works well when you use dropbox so long as you aren't accessing it on many different computers on a daily/weekly basis, then it just becomes a pain in the ass.

[1] This may have changed but I don't think they would appeal to many users if it has, and they do have an option to disable it but the obfuscated javascript is what stopped me from looking further.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: