Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The default for anything in that setting should be that phoning out (or trying to do so) is qualified as a security incident. Especially if it happens right after you've entered your credentials.


Yeah, LittleSnitch helps with that.

I’d be fine with telemetry if it recorded locally in a way which was fully inspectable and human readable and which I could send IFF I wanted to, but with a password manager I’d be scared even of just a long list of events; passwords and keys themselves are so low entropy vs long lists that you could easily encode something…




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: