• @[email protected]
    link
    fedilink
    English
    211 months ago

    If they have vaults downloaded, then they can rapidly brute force the vault passwords and would like be able to decrypt a lot of them.

      • @[email protected]
        link
        fedilink
        English
        211 months ago

        Good point. It’s been such a long time since I’ve had to use the secret that I forgot it existed.

    • @[email protected]
      link
      fedilink
      English
      411 months ago

      It’s not as simple as brute forcing the password, it’s also encrypted using a secret key. You essentially have 2 factor encryption on the vaults.

      • @[email protected]
        link
        fedilink
        English
        -111 months ago

        If a user was social engineered, not very tech savy to catch on to it and revealed the master password, you’d only need to guess the encryption key, no?

        • @[email protected]
          link
          fedilink
          English
          311 months ago

          Yes, but the encryption key is very likely more secure than the users password to begin with.