4 ms·
It's not a trap, it's just convenient to use. I can export my data in a CSV format that can be imported in another password manager if I choose to do so in the
by wilsonnb2 8y ago
It's not a trap, it's just convenient to use. I can export my data in a CSV format that can be imported in another password manager if I choose to do so in the future.
- meroje 8y agoThe format is also openly documented [1] so theoretically third party clients can emerge to consume that data. > We believe security shouldn't be proprietary. 1Password only uses standard, documented data formats and encryption methods, so you can import and export your most important information at any time. [1] https://1pw.ca/whitepaper https://1pw.ca/whitepaper
- craftyguy 8y agoIt's a trap because you have no way to audit the code, you have no idea what they are doing with your information, and some of us are unwilling to trust the word of a charismatic CEO.
- Analemma_ 8y agoI have no way to audit the code of an open-source password manager either, because I'm not a security/encryption expert. So either way I have to trust in third-party auditors, and 1Password has been audited and found secure.
- craftyguy 8y agoIn that case, would you rather trust a crowd of people not affiliated with the company, or (best case) a handful of other companies paid by the company (with an almost certainly controlled press release)? I'd choose the former, but 1password and other proprietary solutions don't want you to choose that.
- Analemma_ 8y agoFor encryption and security software, I'd rather trust experts. "The crowd" is useless no matter how big it is are if they don't understand the domain, hence why even FOSS can contain security howlers like Heartbleed or the Debian OpenSSL fiasco. Which is not to say that FOSS can't be secure, but getting back to my original point, since either way I have to trust experts, I might as well pick the product that wins on functionality and polish.
- craftyguy 8y agoWho said folks in 'the crowd' aren't experts? Sure, many aren't, and there's noise, but you get that same thing even with 'professional auditors' (some pass themselves as experts but aren't). In the latter case, at the end of the day, you have to trust some charismatic CEO because you have no other option if you want to use their product. That's a terrible wager to take from a security perspective.
- deleted 8y ago[deleted]
- wilsonnb2 8y agoI also have no way to audit how UPS handles my packages, how my dentist handles my records, how Papa Johns handles the ingredients that make my pizza, etc. It's pretty standard to not be able to audit a company, and most of us do business with all of those companies anyways.
- craftyguy 8y ago> how UPS handles my packages It's pretty obvious when UPS mishandles your packages, it's either missing, damaged, visibly opened (e.g. security tape broken). It's likely very rare that they would 'mishandle' a package in such a way that you would not be able to notice. Companies like 1password can (and likely do) use your information in ways that are impossible for you to detect, so this analogy does not apply. > how my dentist handles my records In the US, you have HIPAA, and there are big penalties for mishandling medical records. The same does not exist for businesses like 1password, so this analogy does not apply. > how Papa Johns handles the ingredients that make my pizza, There are sanitation and food handling laws (in the US), and food service companies can get shut down for mishandling food. The same does not exist for businesses like 1password, so this analogy does not apply. Edit: Since HN's commenting system arbitrarily limits the depth of comments: My point is that your analogies are not similar. In your analogies, there are legal penalties for violation, whereas in the case of 1password, there are 0 legal penalties and very likely 0 financial penalties for malicious behavior when it comes to your information. In case you still don't believe me, see: Equifax. We can all trust their CEO now, right? (wrong)
- wilsonnb2 8y agoAll of my analogies are intended to be similar situations, not identical situations. It's inaccurate to say that they don't apply because they aren't identical. Yes, there are regulations and consequences for mishandling food and patient data but I still have no personal way to ensure that these practices are followed. In the end, you have to trust the entity that you are doing business with. The same applies to 1Password.