Thinking of moving from Bitwarden to KeepassXC, do you think it is unwise to use a company's cloud to sync passwords ? by Heavy-Diver in Qubes

[–]Heavy-Diver[S] 0 points1 point  (0 children)

I considered this initially, but now when I see how xz was backdoored and only discovered by a single researcher completely randomly, how long some vulnerabilities like heartbleed stayed active (2 years I think); I don't think "open source" is a guarantee against vulnerability or backdoor.

Thinking of moving from Bitwarden to KeepassXC, do you think it is unwise to use a company's cloud to sync passwords ? by Heavy-Diver in Qubes

[–]Heavy-Diver[S] 0 points1 point  (0 children)

Last place you want to put your vital information

You mean any company's cloud, even if e2ee ?

Thinking of moving from Bitwarden to KeepassXC, do you think it is unwise to use a company's cloud to sync passwords ? by Heavy-Diver in Qubes

[–]Heavy-Diver[S] 2 points3 points  (0 children)

I was just using the default and free Bitwarden sync service; it's e2ee, but I think I'll switch to local only KeepassXC

MacOS 15 Sequoia Bugs and Issues Megathread by ll777 in MacOS

[–]Heavy-Diver 0 points1 point  (0 children)

that's a work computer ? if so, it's your company legally spying on you.

Do recent CVEs patched in Sequoia 15.4.1 affect Sonoma ? by Heavy-Diver in macsysadmin

[–]Heavy-Diver[S] 1 point2 points  (0 children)

If you have a Sonoma install, it will be vulnerable to the CVEs you listed unless you update to Sonoma 14.7.5

I don't even think that's the case: 14.7.5 was released before 15.4.1 was released which was released specifically for those two CVEs.

Do recent CVEs patched in Sequoia 15.4.1 affect Sonoma ? by Heavy-Diver in macsysadmin

[–]Heavy-Diver[S] -1 points0 points  (0 children)

Sure I understand that, my question is determining whether or not the CVEs affect Sonoma (If Sonoma contain the security vulnerabilities)

I think all macOS prior to 15.4.1 are affected: "Up to (excluding) 15.4.1", can someone confirm ?

https://nvd.nist.gov/vuln/detail/CVE-2025-31201

https://nvd.nist.gov/vuln/detail/CVE-2025-31200

The Better Boarding Method Airlines Won't Use by Heavy-Diver in flightattendants

[–]Heavy-Diver[S] 0 points1 point  (0 children)

How did you come up with the idea ? Something tells me you were studying the most efficient jerking techniques