Google uploading your plain text passwords

Hank Nussbacher hank at interall.co.il
Sat Jun 12 18:12:17 UTC 2021


On 12/06/2021 08:31, Damian Menscher via NANOG wrote:
>
> 
> The Chrome password manager is convenient, and the sync can be 
> incredibly handy (I can sign into stuff on different computers or even 
> my phone without needing to copy over the passwords), but you might 
> consider leaving your highest-value passwords out of that system, or 
> really any system.  Personally, my financial passwords are not known by 
> Chrome, myself, or even my password manager.  (Yes, you heard that right 
> -- no single entity knows the passwords.  How?  By using a simple 
> secret-splitting scheme -- I memorize part of the password, and my 
> password manager stores the rest.)

Or:
https://doubleoctopus.com/

-Hank

> 
> Damian



More information about the NANOG mailing list