logoalt Hacker News

lrvicktoday at 12:55 AM2 repliesview on HN

It is a negligent and blatant design flaw in all popular implementations, yes. Mooltipass and Password Store are the only two password managers to do the bare minimum. That is ridiculous.

Anyone who corrects this, with a good UX solution, will win the password manager wars. It is so so so easy to do, so it is unthinkable only the CLI password manager written in bash bothers to do it.

Ask an LLM to implement it for you if you must, but no one has any excuse to skip the most basic security function of a password manager: do anything at all to protect it from malware.

The bar for password managers is in hell.


Replies

whattoday at 2:43 AM

You can’t have a good UX with this setup, which is why none of the major password mangers do it.

show 1 reply
antonvstoday at 1:20 AM

> Anyone who corrects this, with a good UX solution, will win the password manager wars.

In some technical sense, not necessarily in popularity.