Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is a false dichotomy. Nobody is claiming that mindlessly clicking "update" guarantees safety.

I run a private fork of the bitwarden client, anyway. Their stock one partially trusts the iteration count of the PBKDF provided by the server, and can be tricked into sending a low-iteration hash of the master password.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: