One downside is that i’ll have no more passkeys. The vault syncing, i can do via SyncThing.

    • rumba@lemmy.zip
      link
      fedilink
      English
      arrow-up
      10
      arrow-down
      1
      ·
      edit-2
      23 hours ago

      So was LastPass. But when they’re source code leaked, turned out their encryption method was crappy. Just because something is encrypted doesn’t mean that it’s safe.

      The key is that proton pass and bit warden and keypass are open source and have all passed independent security audits.

        • rumba@lemmy.zip
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          2
          ·
          21 hours ago

          What is this fight club? /s

          You could totally talk about E2EE if the client was SA/Electron. If the blob is just getting transferred and stored and the passphrase is never transferred, that’s E2EE.

          Come to think of it, if they throw in extra keys when you make your blob, it’s still E2EE, even if they have a key for it. Perhaps we need to think differently about E2EE being then end all.