Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> But if you have storage for the special cases, why not just store the passwords to begin with?

1. because compromises do not give up the password

2. because storage then becomes optional, it's still usable if it's not installed on the device you're using, as long as you remember the metadata. (or keep trying different combinations until you get it, there aren't that many different combinations as long as you rarely increment a counter).



#1 is true too for an encrypted password database.

Unless of course by "compromise" you meant the master password being stolen, in which case such a compromise would result in all your passwords being stolen with both types of password managers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: