minus-squareRustyNova@lemmy.worldtoPrivacy@lemmy.ml•Bitwarden CLI was compromised as part of an ongoing Checkmarx-related supply chain attacklinkfedilinkarrow-up1arrow-down8·7 days agoOh definitely. Not saying it’s impossible But here it would be arguably harder. Need to first get in the repos, and requires the user to log in to the password vault. Syncthing is easier to compromise, but good luck decrypting the vault linkfedilink
minus-squareRustyNova@lemmy.worldtoPrivacy@lemmy.ml•Bitwarden CLI was compromised as part of an ongoing Checkmarx-related supply chain attacklinkfedilinkarrow-up3arrow-down15·7 days agoI don’t use it. That’s the point. linkfedilink
minus-squareRustyNova@lemmy.worldtoPrivacy@lemmy.ml•Bitwarden CLI was compromised as part of an ongoing Checkmarx-related supply chain attacklinkfedilinkarrow-up3arrow-down5·7 days agoOf what app? Keepass? Was from the Debian repos. Syncthing what’s from the syncthing repos linkfedilink
minus-squareRustyNova@lemmy.worldtoPrivacy@lemmy.ml•Bitwarden CLI was compromised as part of an ongoing Checkmarx-related supply chain attacklinkfedilinkarrow-up10arrow-down4·7 days agoDamn. I’ll stick with my keepass + syncthing combo linkfedilink
Oh definitely. Not saying it’s impossible
But here it would be arguably harder. Need to first get in the repos, and requires the user to log in to the password vault. Syncthing is easier to compromise, but good luck decrypting the vault