3 ms·
I agree that a compromised 1Password application poses a much bigger threat than Dropbox access. But instead of a malicious attack, I would argue that it's more
by level3 10y ago
I agree that a compromised 1Password application poses a much bigger threat than Dropbox access. But instead of a malicious attack, I would argue that it's more important to protect against a bug or faulty code.
Based on 1Password's response, it sounds like the app has to locate the password file based on a settings file, which could be a little fragile. A flaw in the code logic could accidentally modify other files unintentionally.
As an example, there was once a bug in Steam on Linux that force-deleted root because a path variable wasn't checked to ensure it wasn't empty.