6 ms·
> if they get breached, I'm fucked. This part is not true -- your data is encrypted with a randomly generated key that is kept locally. You could freely post t
by JackC 7y ago
> if they get breached, I'm fucked.
This part is not true -- your data is encrypted with a randomly generated key that is kept locally. You could freely post the data they have all over the internet and it would be fine.
- sroussey 7y agoThe really worry has nothing to do with the data being on a server and more about their update servers sending malicious code.
- JackC 7y agoThat's true, but it would also be true of a desktop app using an offline vault, and is also true of all the other desktop apps you run. The risk of someone running malicious code on your machine is a reason to use two factor auth, not a reason to avoid cloud storage for encrypted files.
- DavideNL 7y ago> but it would also be true of a desktop app using an offline vault Well you can set an application firewall to block all internet access of the 1Password app. So, it can't update automatically, and when you manually update it and it would contain malicious code, it still can't connect/upload anything to the internet. You can even use 1Password sync via iCloud, which is handled externally - not by 1Password, but by macOS. Unfortunately, this can not be done on an iOS device (no app firewall), since Apple locks down everything and decided users may not control their own devices anymore :'(
- wool_gather 7y agoFWIW, Apple has a "VPN" API that can be used to implement a firewall (or a proxy, or etc.). I don't know whether there's a usable commercial product that does that, but if you're really into it you can certainly write your own.
- DavideNL 7y agoYea, but it doesn't really work because you cannot block on the application level. You can only block hostnames/ip-addresses, and these often change with updates, so you'd have to constantly monitor and block new hosts after the app starts leaking again.
- Cthulhu_ 7y agoThat MAY be the case (I'd love for a number of independent parties auditing the security, NOT paid for by AgileBits), but it's still a single point of failure. What if they have data loss? What if that data loss causes local data to be lost due to a sync operation? I've always used the Dropbox approach + backups. If Dropbox has an outage the file is still synced locally. If Dropbox deletes the file via a sync operation I still have my backups. If I delete the files Dropbox has an undelete option. All I want is control over the files.
- voska 7y agoIt also changes the risk profile. AgileBits is a big target, my local machines are not.
- bwoodruff 7y agoBen from 1Password here. We've designed the model so that we aren't a big target. The Secret Key helps with that. https://support.1password.com/secret-key-security/ https://support.1password.com/secret-key-security/
- AdamGibbins 7y agoThat's a strange statement, you're a big target because you're holding lots of peoples secret data. Doesn't matter how you model it, unless your model is to have minimal data/clients.
- bwoodruff 7y agoMinimal data of value, yes. Did you read about the Secret Key?
- microdrum 7y agoBen, everyone here understands the model. It isn't sophisticated and it isn't particularly special. You have a lot of [encrypted] sensitive data. On your network. On servers you own. You are a target. Once the bad guys get the data, they'll worry about the individual keys and whom they want to target. I'm one of the many people who are both dropping 1P and advising friends and family to do the same as a result of this episode.
- deleted 7y ago[deleted]
- lolsal 7y ago> This part is not true -- your data is encrypted with a randomly generated key that is kept locally. You could freely post the data they have all over the internet and it would be fine. Do we know this is true? I assume it is, but I haven't checked the source or verified that I can encrypt/decrypt my data with my key, or that there isn't a master key that 1password has that can access it.
- bwoodruff 7y agoHi lolsal. Ben from 1Password here. Implementation details can be found here: https://1pw.ca/whitepaper https://1pw.ca/whitepaper If you have any questions our security team would be happy to elaborate. They can be reached at support+security@1password.com
- lolsal 7y agoI think it's awesome that you publish a whitepaper, but it's just a whitepaper, not source. It doesn't prove anything. Edit: also there seems to be a lot of this: > We’re sorry. This section of this document is not yet ready. Any- thing you see in this section is at most an outline of things to come.
- bwoodruff 7y agoWe're offering a (mostly) closed source solution. You can evaluate the source for the web app, and the browser extensions. If your argument is that folks shouldn't ever consider using something closed source then obviously 1Password is probably not going to be a good fit and we're at a bit of an impasse. > Edit: also there seems to be a lot of this: Some, yes. I'm not sure I'd say 'a lot', but yes, it is a work in progress. Our security team should be able to elaborate on any points that we have yet to detail, though, if you're interested.
- 33Backpack33 7y agoI've confirmed it because you can see the data that the web browsers sends and it was encrypted. I've also tested this on LastPass and Bitwarden and from what I can see 1Password does it the best.