6 ms·
How many customers are using Google Password Manager? How much revenue does it generate? What would it cost to add E2EE? How would it affect the UX? How much re
by rpedroso 1mo ago
How many customers are using Google Password Manager? How much revenue does it generate? What would it cost to add E2EE? How would it affect the UX? How much revenue would it generate? What projects would have to be de-prioritized to fund this work?
I agree, a password manager without E2EE is unusable in my eyes. However, I can also understand the institutional reasons this might be the case. I don't think it reflects an organizational aversion to E2EE.
- ameliaquining 1mo agoGoogle Password Manager does in fact have E2EE. It's quite straightforward to enable. Your interlocutor is complaining that it's not the default, which I'm quite sure is a deliberate decision made on the grounds that the typical user, the one for whom the default matters because they won't tweak their settings, needs workable account recovery more than they need defense against the specific kinds of security threats that make E2EE relevant.
- Cider9986 1mo agoLastPass, designed for regular users and one of the most popular password managers, had a breach of user vaults. If they hadn't implemented E2EE then it would have been more devastating than it was (crypto wallets were found from vaults with weak master passwords).
- ameliaquining 1mo agoGoogle's security record at avoiding that kind of breach is just about the best in the industry, and their system that handles custody of password manager secrets is designed to withstand even a compromise of their production infrastructure (https://security.googleblog.com/2022/10/SecurityofPasskeysintheGooglePasswordManager.html https://security.googleblog.com/2022/10/SecurityofPasskeysin...). I would advise almost all users to worry more about getting locked out of their password database than about that. Of course, I would also advise almost all users not to self-custody cryptocurrency.
- Cider9986 1mo agoYour link is about them using E2EE not that they can be as secure as E2EE for users without it. Users would lose their passkeys if they lost all secrets and devices. Google couldn't recover them. They can still and should still continue using great security practices while protecting E2EE data. >Of course, I would also advise almost all users not to self-custody cryptocurrency. There's no point in crypto if you're not holding your own keys. It's the antithesis of cryptocurrency. People can have highly secure self custody wallets on a modern iPhone or Pixel. And their seeds would have been safe if LastPass didn't have terrible security or they used long passphrases.
- deleted 1mo ago[deleted]