One downside is that i’ll have no more passkeys. The vault syncing, i can do via SyncThing.

  • rumba@lemmy.zip
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    1
    ·
    edit-2
    17 hours ago

    So was LastPass. But when they’re source code leaked, turned out their encryption method was crappy. Just because something is encrypted doesn’t mean that it’s safe.

    The key is that proton pass and bit warden and keypass are open source and have all passed independent security audits.

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        2
        ·
        16 hours ago

        What is this fight club? /s

        You could totally talk about E2EE if the client was SA/Electron. If the blob is just getting transferred and stored and the passphrase is never transferred, that’s E2EE.

        Come to think of it, if they throw in extra keys when you make your blob, it’s still E2EE, even if they have a key for it. Perhaps we need to think differently about E2EE being then end all.