← Back to context

Comment by pwdisswordfishq

2 days ago

What supply-chain attack do you suspect pwsafe of being at risk of?

Nothing in particular. In my head all that needs to happen is some form of update (dependency, core project or the Android version on my phone) and sneaks in something that reads the unencrypted file and sends it over the internet somewhere.

I wish android and windows had flat seal, as far as I can remember that can prevent all network access for a given app.