Master Password Backup
Privacy Guides Community [Unofficial]
May 11, 2026
Colter:
> Aren’t generatours like that of KeePass random?
Does KeePass prefer printable characters (seems like)? If so, by definition, the password (even if chosen at random) doesn’t cover all UTF8/UTF16 code points and hence cannot said to be “uniformly random”. That said, I could be I am mistaken, as I am not a cryptographer.
Colter:
> This sounds way to complicated and error prone.
Key management is the hardest thing in cryptography.
Colter:
> what is the difference with escrow keys?
Escrow keys can be rotated out and/or disabled. Ideally, these are 32-byte random & have strict domain separation; that is, one-time, context-specific use: You’re not typing it anywhere or copypasting it everywhere, for example (like you would be your password when using the password manager or any other application).
Discussion in the ATmosphere