How would you attack a local-first password manager?

(apps.microsoft.com)

2 points | by merimens 9 hours ago ago

4 comments

  • merimens 9 hours ago

    If possible, please try this in practice:

    create a vault or backup file then attempt to break or extract data from it without the master password

    I’m particularly interested in attacks on user-created database/backup files.

  • eesmith 8 hours ago

    Pay the developer enough to take over distribution, add a backdoor, deploy as part of the next update.

    Alternatively, use threats of physical violence, including from the government, or appeal to the developer's patriotism, greed, nobility, etc., to install that backdoor.

  • merimens 8 hours ago

    [dead]

  • merimens 9 hours ago

    [dead]