Hacker News new | past | comments | ask | show | jobs | submit login

Regarding Chrome, here's a good place to start:

https://noncombatant.org/2014/03/11/privacy-and-security-set...

There are also people who use Chromium, or particular configurations of Chromium, instead of Chrome. That's fine. But don't use forks of Chromium, no matter who maintains them, even if it looks like a sizable effort. You don't want your browser to be any number of days behind the Chromium patch cycle.

I use the browser integration for 1Password on OS X (I might not if I was on Windows). I'm generally not that worried about localhost privilege escalation. I am very worried about how well I can reason about cloud-based storage of any sort, and how it will interact with things like my browser.

KISS: keep your secrets out of cloud systems and your backups offline.

If you're very sophisticated, I like Tarsnap for online backups. But you have to be very sophisticated to use it.




If you're very sophisticated, I like Tarsnap for online backups. But you have to be very sophisticated to use it.

I think you're overstating this a bit. You have to be comfortable at a UNIX command line. Surely that alone doesn't qualify someone as "very sophisticated"?


Very sophisticated varies on the demographics of the group, For HN no, for the general population yes.


Right, I can believe that. Maybe that's what tptacek meant.


Yes, it very much does.


>You don't want your browser to be any number of days behind the Chromium patch cycle.

Since Chromium does not upgrade itself, do you happen to have a suggestion on how to be arrange to be notified when a new patch is released?


> I am very worried about how well I can reason about cloud-based storage of any sort, and how it will interact with things like my browser.

In that case, why 1password over keepassx?


1Password doesn't store secrets in the cloud, as far as I know. You have to manually back up the database and some users choose to store that encrypted db in the cloud.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: