3 ms·
I really wanted to use 1Password for Teams, I don't mind paying a subscription model, and their whitepaper on their hosted solution is really quite thorough: h
by mnutt 9y ago
I really wanted to use 1Password for Teams, I don't mind paying a subscription model, and their whitepaper on their hosted solution is really quite thorough:
https://1password.com/security/ https://1password.com/security/
My big issue is still with the web app allowing you to unlock your vault and access your passwords. They acknowledge in the whitepaper that it's theoretically possible that an attacker could MITM your SSL connection and serve malicious javascript, stealing both your master password and any secrets you access. They list certificate pinning and DNSSec as unimplemented future actions they may take, but also need to take into account that their web app servers themselves may be compromised.
All of this could ideally be mitigated by centrally hosting encrypted password databases, but either a) having the extension/desktop app cryptographically verify all server pages and assets, or b) allowing the web UI to be entirely disabled. If they did either of those I'd sign up for an enterprise account in a heartbeat.
- AGKyle 9y agoThis is something we plan to tackle in the future. Probably via some sort of downloadable local copy of the web client. But it's possible we integrate it into each app somehow. It's still something I think we're trying to think through to try to get right before we act. As it stands, the only reason you need to login to the web client is for administration purposes and sign up. After that the native clients handle the rest. That said, as you indicated, we're aware of this potential vector of attack and acknowledge it. Kyle AgileBits