Ask HN: How safe are our password managers in face of LLM cyber attacks?
Posted by muddi900 2 days ago
Hey
With LLMs having infinite attack resources compared to human researchers, how safe are we?
We already know that you don't need top tier frontier models to create an attack vector. You can just loop a mid-sized model until it bears result. Or run a small swarm of agents to achieve the same goal
How long until a criminal actor with running exo[1] over 2 mac studios breaches password managers?
I understand that the storage of passwords might be encrypted, but they might find vulnerabilities at the client or transport level.
How may we mitigate this?
[1] https://news.ycombinator.com/item?id=49585683
Comments
Comment by denn-gubsky 1 hour ago
I prefer self-hosted and hardware password managers. This does not completely mitigate the risk, but makes the attack surface smaller. Another question is your local network perimeter protection. I don't feel safe even with reverse proxy like tailscale, and thinking about local LLM Agent based network safety monitor.
Comment by laruss5 14 hours ago
[flagged]