5 ms·
I use 1Password. To my non-security-expert eyes, the two weakest spots in how I use 1Password are: (a) The plugin I use on the browser, (b) The fact that I use
by sinatra 11y ago
I use 1Password. To my non-security-expert eyes, the two weakest spots in how I use 1Password are: (a) The plugin I use on the browser, (b) The fact that I use Dropbox to sync the password keychain.
I can maybe move the keychain to an encfs encrypted folder in Dropbox. Then, I won't be able to use 1Password mobile app. And for the plugin, perhaps I can disable the plugin and copy-paste the password directly from the app.
Would love to get others' feedback. UPDATE: It appears I can combine sync through encfs folder and manual sync through phone to achieve sync on all devices.
- why-el 11y agoI dropped all plugins. I open the app each time I need a password. Slightly inconvenient, especially at presentations where I had to type the master password and noticed attendees dripping off since it was too long, but this is a situation I am not keen on optimizing on.
- sinatra 11y agoThanks! I also disabled the plugin. As 1Password asks for my password every few hours anyway (I lock the screen every time I leave the desk), hopefully it won't be as inconvenient as I originally thought.
- why-el 11y agoActually mine asks for it on every occasion almost. I know it sounds silly, but I type my master password with lightening speed now so. :D
- yuvipanda 11y agohttps://defuse.ca/audits/encfs.htm https://defuse.ca/audits/encfs.htm is an EncFS security audit, that didn't come out too clean. If you install encfs on debian it pops up a warning screen telling you to not use it for anything too sensitive atm.
- sinatra 11y agoYeah, I'm aware of some of those security issues (I understand that it can't help me if I am targeted. But, I may be safe in broad hack attempts). However, I just don't have any solution that has the convenience & stability of Dropbox + encfs. What do you use for syncing docs securely?
- danieldk 11y agoGenuinely wondering, which part of 1Password's encryption don't you trust? Or is it about metadata leakage?
- stock_toaster 11y agoThe 1password keychain is of course encrypted[1] (I think[3] that dropbox syncing uses the older agile keychain format?). I personally sync my 1password keychain with icloud. Apple claims[2] that iCloud data is encrypted during transfer, as well as encrypted at rest. If I was more concerned about that aspect of it, I would probably just sync with wifi. I do not use the browser plugin (personal preference). [1]: https://support.1password.com/opvault-overview/ https://support.1password.com/opvault-overview/ [2]: https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303 [3]: https://support.1password.com/switch-to-opvault/ https://support.1password.com/switch-to-opvault/
- sinatra 11y agoYeah, the keychain is obviously encrypted, but I still feel uneasy about it being naked on Dropbox. The reason I'm leaning towards using encfs + Dropbox vs iCloud is that although I definitely trust Apple more with my data (compared to Dropbox), I feel that an encryption controlled by me at client side will be safer.
- mef 11y agoThe 1password keychain is encrypted locally before being transferred to Dropbox.
- devit 11y agoThe weakest spot against targeted attacks is probably the fact that a 0-day in your browser compromises everything.
- jonknee 11y agoYou can sync through WiFi and it's pretty painless. A computer serves as a WiFi server and then mobile devices (or other computers) sync off that when they are on the same network.