[-] ChiefGhost295@lemmy.one 15 points 2 months ago* (last edited 2 months ago)

Since the vault is end-to-end encrypted, it shouldn’t matter where it is hosted, even if it is in the cloud. Here is what a security researcher and a password cracker Jeremy M. Gosney has said about this after the LastPass incident.

”Is the cloud the problem? No. The vast majority of issues LastPass has had have nothing to do with the fact that it is a cloud-based solution. Further, consider the fact that the threat model for a cloud-based password management solution should *start* with the vault being compromised. In fact, if password management is done correctly, I should be able to host my vault anywhere, even openly downloadable (open S3 bucket, unauthenticated HTTPS, etc.) without concern. I wouldn't do that, of course, but the point is the vault should be just that -- a vault, not a lockbox.”

[-] ChiefGhost295@lemmy.one 6 points 4 months ago

You are right that Proton is currently self-funded by its paying customers, but to be accurate, they have actually taken VC money before.

[-] ChiefGhost295@lemmy.one 13 points 5 months ago

I don't see an option for a 24-month plan.

[-] ChiefGhost295@lemmy.one 22 points 6 months ago

Interestingly, the article mentions twice how Proton doesn't do flashy marketing campaigns when that is precisely the aspect people have criticized Proton for years, usually around Black Friday when they portray the discount as much better than what it is.

[-] ChiefGhost295@lemmy.one 16 points 6 months ago

This is also not their only controversy. When someone proposed in their forums that Kagi should add a widget that would help people get help if they are searching for suicide material, Kagi refused because that isn't the result that the person was searching for.

[-] ChiefGhost295@lemmy.one 28 points 10 months ago

The Firefox hardening project Arkenfox only recommends uBlock Origin. Everything else is redundant.

[-] ChiefGhost295@lemmy.one 6 points 11 months ago

I think this article by Mullvad explains this well.

[-] ChiefGhost295@lemmy.one 5 points 11 months ago

I would also remove DuckDuckGo Privacy Essentials. It is redundant if you are using uBlock Origin.

[-] ChiefGhost295@lemmy.one 36 points 1 year ago

They need to make money somehow, and regardless, all the crypto stuff is actually turned off by default, so criticizing Brave for this makes little sense to me.

[-] ChiefGhost295@lemmy.one 12 points 1 year ago

According to their privacy policy, they are using both AdMob and Facebook trackers on their other apps, so that may happen to Raivo as well at some point.

view more: next ›

ChiefGhost295

joined 1 year ago