4 ms·
That's true, but it would also be true of a desktop app using an offline vault, and is also true of all the other desktop apps you run. The risk of someone runn
by JackC 7y ago
That's true, but it would also be true of a desktop app using an offline vault, and is also true of all the other desktop apps you run. The risk of someone running malicious code on your machine is a reason to use two factor auth, not a reason to avoid cloud storage for encrypted files.
- DavideNL 7y ago> but it would also be true of a desktop app using an offline vault Well you can set an application firewall to block all internet access of the 1Password app. So, it can't update automatically, and when you manually update it and it would contain malicious code, it still can't connect/upload anything to the internet. You can even use 1Password sync via iCloud, which is handled externally - not by 1Password, but by macOS. Unfortunately, this can not be done on an iOS device (no app firewall), since Apple locks down everything and decided users may not control their own devices anymore :'(
- wool_gather 7y agoFWIW, Apple has a "VPN" API that can be used to implement a firewall (or a proxy, or etc.). I don't know whether there's a usable commercial product that does that, but if you're really into it you can certainly write your own.
- DavideNL 7y agoYea, but it doesn't really work because you cannot block on the application level. You can only block hostnames/ip-addresses, and these often change with updates, so you'd have to constantly monitor and block new hosts after the app starts leaking again.