3 ms·
I don't know the details there, but I'd be surprised if the user was storing their Dropbox credentials in 1Password configuration. I'd expect it uses OAuth to c
by Perceptes 10y ago
I don't know the details there, but I'd be surprised if the user was storing their Dropbox credentials in 1Password configuration. I'd expect it uses OAuth to create a token that provides 1Password with scoped access.
- tlunter 10y agoBut how does the user log into dropbox when they go to the website? They probably store those generated credentials within the 1password vault.
- chrisrhoden 10y agowhich is encrypted.
- phs2501 10y agoIf 1password has been injected with malicious code, whoever has done so will have all your encrypted credentials the next time you unlock your vault, including presumably your full Dropbox creds. (Caveat: I use Keepass2Android, which ironically DOES support limiting access to the Apps folder in Dropbox.)
- whok 10y agoKeepass follows best practices more than 1Password. http://mostvulnerable.com/ http://mostvulnerable.com/