I just happened upon this thread and security of all types is my specialty so I just wanted to say that nothing here is personal. I’m trying to be helpful giving folks “actual security” as in not “better than putting passwords in plain text files”. Lazy idiots will be lazy idiots with Keepass as well. I can’t tell you how many stories I’ve heard from colleagues that those people aforementioned just put the main Keepass password in a plain text file.
I upvoted the OP and your reply for bringing TM novelty and awareness.
I do see what you’re going for, but the mitigations you wrote can be found everywhere on the Internet for over a decade. It’s average commodity information combined with that fact that we are not more secure these days, but less secure in 2024 that ever.
In the case of password databases, this is de facto less secure than paper and pencil, which is not extreme by any measure and actually takes little effort.
10/10 and notice all the nitpicking of one irrelevant detail. That’s a credibility attack. The main thrust of the argument is 100%. It was just something personal that stuck out to the author. If that related Signal experience isn’t true there are thousands more that are.
10/10 especially for the physical security mention. So-called Cybersecurity “Wisdom” will tell you that physical access means game over and that YOU DO NOT NEED TO PROTECT AGAINST IT. It’s a cohencidence that that group that tells that lie benefits the most from the telling of it.