←back to thread

95 points thunderbong | 7 comments | | HN request time: 0.203s | source | bottom
Show context
MaxGripe[dead post] ◴[] No.41912044[source]
[flagged]
1. maqp ◴[] No.41912065[source]
NO ONE should trust a website delivering JS that could do who-knows what the next time they skip reading the code. Like, send the inputs to a third party.

Please delete this project and your comment.

If you want to be helpful, write native code that user can read, compile, and install, and persistently use without risk of backdoor-out-of-the blue.

replies(4): >>41912177 #>>41912233 #>>41912718 #>>41913148 #
2. Matumio ◴[] No.41912177[source]
Do you read your password manager's code every time it updates? Probably not, because you trust the author's reputation.

I wouldn't trust this page with my passwords either, but not because of the reasons that you mention. I haven't checked, but maybe it is simple enough to read the code in its entirety and then self-host? If so, nothing wrong with that.

3. DatenF ◴[] No.41912233[source]
It's hosted on GitHub Pages so you don't need to check if the code has changed. Just look for any commits. From what I can see, the last one was three months ago
replies(2): >>41912486 #>>41912506 #
4. rerdavies ◴[] No.41912486[source]
That assumes that the code was honorable in the first place. I think you have to assume that this was not posted by someone with honorable intentions.
5. 0points ◴[] No.41912506[source]
I forge git commits now and then so I know this but maybe it is not common knowledge. Git commits can be forged.

Content and dates can be changed.

6. de_elusive ◴[] No.41912718[source]
Very rude comment imho.

Do 1password/lastpass extensions not include remote code/resources? Of course they do.

7. MaxGripe ◴[] No.41913148[source]
1. You can fork this repository and do whatever you want with it (e.g., self-host). The license is public domain.

2. If you save this page to your disk, everything will still work offline.