In theory at least, online services would be more safe than a locally decrypted vault. If your computer is compromised, the bad actors can pull your encrypted vault for an unlimited brute force attack. Of course, this can be mitigated by increasing the decryption time. However, if your vault is already decrypted, then bad actors can just pull all your password from your memory.
I, for one, am decrypting my vault once when I start my PC. In theory, if I were to use an online solution, bad actors wouldn’t be able to pull my vault from memory.
Appoxo@lemmy.dbzer0.com 1 year ago
Bitwarden for example does public reports and is pretty cheap at 10€ per year. But the base (free) offering is more than enough. The fee is only to have TOTP and a bit of encrypted cloud storage. bitwarden.com/help/is-bitwarden-audited/
dan@upvote.au 1 year ago
And to keep the company alive. It’s cheap enough that IMO it’s worth paying for if you get a lot of value from it, even if you don’t need the paid features.