4 ms·
What kind of sync is that? Only if you manage your vaults externally (e.g. Dropbox)?
by tucif 7y ago
What kind of sync is that? Only if you manage your vaults externally (e.g. Dropbox)?
- Mathnerd314 7y agoI was thinking about the sync you get with a premium membership (https://support.1password.com/sync-options/ https://support.1password.com/sync-options/), but I guess the thread is about syncing with Dropbox. It's quite an old thread, this paper suggests they use the "secure remote password" protocol for memberships, so perhaps the master key isn't stored for that: https://1password.com/files/1Password%20for%20Teams%20White%20Paper.pdf https://1password.com/files/1Password%20for%20Teams%20White%... It's definitely stored for Touch ID/fingerprint 1password access though (https://support.1password.com/touch-id-security-ios/ https://support.1password.com/touch-id-security-ios/). One of their employees wrote about it here: https://discussions.agilebits.com/discussion/106629/ios-security-breach https://discussions.agilebits.com/discussion/106629/ios-secu.... His response is basically that OS-level 0days aren't in their threat model, so they're continuing their usual bug-fixing routine. And it's true, nothing can really stop a rootkit from sniffing passwords as they're being used, besides winning the anti-rootkit race. Perhaps 1password could have a little more explanation of the insecurity of using Touch ID / Face ID though rather than simply saying it's as secure as possible.