Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Nastypouch

@Nastypouch@hachyderm.io
mastodon 4.6.6
  • Open on hachyderm.io

I'm a software engineer, cat dad, and general bighugenerd.

0 Followers
0 Following
4 Posts
Joined November 12, 2022
pronouns:
he/him

Posts

Open post
Nastypouch
Nastypouch @Nastypouch@hachyderm.io · Dec 27, 2022
Nastypouch
@Nastypouch@hachyderm.io

I'm a software engineer, cat dad, and general bighugenerd.

hachyderm.io
Replying to @Nastypouch@hachyderm.io
@epixoip@infosec.exchange It's entirely possible his perspective has changed since then of course, but I don't think "I know the 1Password engineers know what they're doing" addresses the more fundamental problems of providing this sort of software. The question isn't *if* vulnerabilities are found, it's how the team will respond when they inevitably are.
0
0
0
0
Open post
Nastypouch
Nastypouch @Nastypouch@hachyderm.io · Dec 27, 2022
Nastypouch
@Nastypouch@hachyderm.io

I'm a software engineer, cat dad, and general bighugenerd.

hachyderm.io
Replying to @epixoip@infosec.exchange
@epixoip@infosec.exchange @Casper042@mastodon.social @squelch41@retrochat.online @Goutham@techhub.social @bgeerdes@mastodon.cloud @Jerry@hear-me.social @abhivm@mastodon.social @SOOKIE@tech.lgbt @jally@bbq.snoot.com @eclectic_citizen@convo.casa @sherridavidoff@infosec.exchange @jstangroome@infosec.exchange @BenAveling@infosec.exchange @NilsRenaud@m.g3l.org @thor@mast.ttk.is @arpcomics@mastodon.online @cambraca@musicians.today @pkellner@techhub.social @Nazo@hachyderm.io @davelee212@hachyderm.io @CivilDev@hachyderm.io @edbro@swecyb.com @yeleek@infosec.exchange Since you mention Tavis, it's worth noting that he found an "astonishingly bad" vulnerability in 1Password and actually *recommended* LastPass (if one was determined to use a cloud-based solution) because they had a competent security team: https://twitter.com/taviso/status/1167404993260818434?s=20&t=y6PdkfVHC81v1Gglfe6-kA
1
2
1
0
Open post
Nastypouch
Nastypouch @Nastypouch@hachyderm.io · Dec 27, 2022
Nastypouch
@Nastypouch@hachyderm.io

I'm a software engineer, cat dad, and general bighugenerd.

hachyderm.io
Replying to @Nastypouch@hachyderm.io
@epixoip@infosec.exchange Regardless of the competence of the people working on it, I don't think cloud-hosted passwords are a good idea because of the relative value in compromising one of the providers or finding vulnerabilities in the code. The core functionality of a password safe is simple and easier to get right, and I think where we're tending to run into trouble is when we see third parties start to try to provide all-in-one syncing/autofill/hosted password management solutions.
0
0
0
0
Open post
Nastypouch
Nastypouch @Nastypouch@hachyderm.io · Dec 27, 2022
Nastypouch
@Nastypouch@hachyderm.io

I'm a software engineer, cat dad, and general bighugenerd.

hachyderm.io
Replying to @epixoip@infosec.exchange
@epixoip@infosec.exchange You're right that the security of your password manager shouldn't ever depend on whether or not the vault is available to others, but my criticism has never been about that. Any solution that injects custom JavaScript into your browser to fill passwords is a bad one and has a host of security concerns that probably can't be fully addressed.
0
1
0
0

Remote instance

hachyderm.io
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:42:32 UTC