Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's an interesting idea, but is it really usable? If you ever need to change the master key, you'll have to update all the websites you are using, and you won't even know on which websites you used the password manager with since there is no database. I just don't see how I could ever want this. Or is it assumed that master keys never need to be changed?


It's true that changing the master key is a pain, but you don't have to do it for every website at once. Though it might be hard during the transition to remember which sites have the updated key.

Not having a database certainly has its downsides.

Re usability: I've been using it for a couple days now, and I find it pretty tolerable. It's nice to not have to memorize a new password when I sign up for something. I did change my master key once; it took about 5 minutes to update all my passwords. If you only do that once every few months or once a year, it's not so bad.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: