4 ms·
I wonder if 1Password is equally susceptible or less so, due to the way that the extension works. Because 1Password has a native application, I believe the brow
by jd007 10y ago
I wonder if 1Password is equally susceptible or less so, due to the way that the extension works. Because 1Password has a native application, I believe the browser extensions merely communicate with the native application to retrieve passwords to fill when needed, instead of handling your whole decrypted vault.
- JoelTheSuperior 10y agoPrecisely this. The LastPass extension actually handles the decryption, whereas the 1Password one merely communicates with the app. 1Password should therefore be significantly more secure.
- mentat 10y agoIf it auths the application, which it didn't for quite some time. Tavis has found plenty of issues with 1Password and their team has been much more hostile and less responsive.
- jfindley 10y agoCan you please provide a source for this? The 1Password only bug I can find filed by tavis is [0], in which 1Password were very responsive and thankful of tavis' efforts. I note that can't find anything on twitter that even remotely supports your allegations either. 0: https://bugs.chromium.org/p/project-zero/issues/detail?id=888&can=1&q=1password https://bugs.chromium.org/p/project-zero/issues/detail?id=88...
- crestfallen 10y agoI'm super interested in this. After a super brief Google search, I was unable to find Tavis's results. Could you kindly direct me to them?
- tripzilch 10y ago> whereas the 1Password [extension] merely communicates with the app. wait. the communication goes what way?? You make it sound like the 1Password extension (that doesn't handle encryption, therefore is not authenticated) can request password and credential data from the 1Password app, like it's pulling data from it? How does the 1Password app know that whatever process is making that request is in fact made by that particular browser extension, prompted by user-action on the extension that is the same user as the one that unlocked the encrypted password vault in the app? And if it doesn't why are you storing your passwords in it :) Are we all clear on what a password manager is? Maybe we should start with a good definition, such as: A password manager is an application that manages an encrypted database, that when unlocked by the user, can be prompted by the user, to decrypt an entry from the database, and send one or more fields of that entry to a specified receiving application's input/login field(s). Communication only flows from the user prompting, to the password manager, to the receiving application. Not the other way around. Ok that's not a full definition yet, it also needs a bit about how to store the encrypted database, how not to sync it, not keeping any keys or plaintext in memory any longer than strictly necessary, etc etc. But it's good if we'd have a definition like that, something that is waterproof by definition.
- palant 10y agoI only had a quick look at 1Password browser extensions source code but there were no obvious red flags - much unlike LastPass. Let's see what Tavis Ormandy digs up, supposedly he found some issues.
- stuartlogan 10y agoAgreed, all seems fine checking here.