Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Nastypouch

@Nastypouch@hachyderm.io
mastodon 4.7.3
  • Open on hachyderm.io

I'm a software engineer, cat dad, and general bighugenerd.

39 Followers
48 Following
4 Posts
Joined November 12, 2022
pronouns:
he/him
Open post
Nastypouch @Nastypouch@hachyderm.io
· 46mo ago
Replying to
@epixoip@infosec.exchange @Casper042@mastodon.social @squelch41@retrochat.online @Goutham@techhub.social @bgeerdes@mastodon.cloud @Jerry@hear-me.social @abhivm@mastodon.social @SOOKIE@tech.lgbt @jally@bbq.snoot.com @eclectic_citizen@convo.casa @sherridavidoff@infosec.exchange @jstangroome@infosec.exchange @BenAveling@infosec.exchange @NilsRenaud@m.g3l.org @thor@mast.ttk.is @arpcomics@mastodon.online @cambraca@musicians.today @pkellner@techhub.social @Nazo@hachyderm.io @davelee212@hachyderm.io @CivilDev@hachyderm.io @edbro@swecyb.com @yeleek@infosec.exchange Since you mention Tavis, it's worth noting that he found an "astonishingly bad" vulnerability in 1Password and actually *recommended* LastPass (if one was determined to use a cloud-based solution) because they had a competent security team: https://twitter.com/taviso/status/1167404993260818434?s=20&t=y6PdkfVHC81v1Gglfe6-kA
twitter.com
1
5
1
0
Open post
Nastypouch @Nastypouch@hachyderm.io
· 46mo ago
Replying to
@epixoip@infosec.exchange Regardless of the competence of the people working on it, I don't think cloud-hosted passwords are a good idea because of the relative value in compromising one of the providers or finding vulnerabilities in the code. The core functionality of a password safe is simple and easier to get right, and I think where we're tending to run into trouble is when we see third parties start to try to provide all-in-one syncing/autofill/hosted password management solutions.
0
0
0
0
Open post
Nastypouch @Nastypouch@hachyderm.io
· 46mo ago
Replying to
@epixoip@infosec.exchange It's entirely possible his perspective has changed since then of course, but I don't think "I know the 1Password engineers know what they're doing" addresses the more fundamental problems of providing this sort of software. The question isn't *if* vulnerabilities are found, it's how the team will respond when they inevitably are.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:02:35 UTC