Just seen Keybase also exists, but the reference to .kbdx makes me think you mean KeePass?

If so I don't like the idea of publishing all my passwords to a public service like Nostr, even if encrypted. Seems like an unnecessary risk/honeypot scenario. There is the keyfile/password combo that adds another layer of encryption I guess.

I prefer security by obscurity, where a non-standard solution poses the biggest effort to attackers.

Reply to this note

Please Login to reply.

Discussion

Currently I'm using syncthing to keep my keepass database in sync between my devices. It was a little bit of a pain to get working but I wanted to keep that attack surface as small as possible.

Yes, typo, keepass.

I'm more worried about censorship and denial of access to the passwords, rather than the encryption breaking.

That's damn interesting. 128bit password for a 128bit seed, published in the clear. I like it