4 ms·
Not really. At least not in the 1Password case. Having access to the 1Passswrd Master Password and your entire encrypted vault still doesn't get the attacker w
by a10c 5y ago
Not really. At least not in the 1Password case.
Having access to the 1Passswrd Master Password and your entire encrypted vault still doesn't get the attacker what they need. To decrypt your vault, you also need to know the 128 bit secret key which is also used in the encryption strategy that is stored offline (e.g. on a piece of paper in your safe or via another already authenticated device)
https://support.1password.com/secret-key-security/ https://support.1password.com/secret-key-security/
- miked85 5y agoThis is not true for the standalone version of 1Password.
- a10c 5y agoThe article is about Cloud-based Password Managers.
- movedx 5y agoIt’s 100% true of the standalone version of 1Password because there is only one version of 1Password - the standalone version. Everything else interacts with it. Your secret key is still required to decrypt passwords via the desktop application (which is the only version - everything else interacts with this.)
- a10c 5y agoI believe he was referring to the old 1Password that let you handle the storage of your encrypted vault (which doesn't incorporate the secret key encryption approach)
- miked85 5y agoYes, I was - and it still exists and gets updates. 1Password goes out of their way to not promote it though.
- movedx 5y agoAnd rightly so.
- miked85 5y agoIt has nothing to do with security - they want to move everyone to a subscription model for reoccurring revenue. I can't blame them for that, but it isn't necessarily the best for customers.
- movedx 5y agoBut that’s why you have choices - you’re not going to agree with or want what everyone is offering you. And like wise, that’s why businesses decide what choices to offer you - they’re not going to be able to serve every need. In this case it is about security, I believe. Primarily because of the additional secret material needed to encrypt the vault, but also because I trust them to store that vault securely for me versus my self. I’m lazy. I’m forgetful. They’re not. It’s literally they’re business and they’re getting better at it daily (one would hope at least.)
- miked85 5y agoThat would be news to me. I have never used a secret key with 1Password and a local vault.
- movedx 5y agoThen sounds like you're working with a diminished product that's less secure.
- miked85 5y agoI am curious how managing secrets locally is less secure than a cloud based solution?
- simondotau 5y agoIn principle there’s no difference, but 1Password did happen to improve the security in parallel with their transition to a cloud-centric product. That being said it’s worth noting that behaviour can be as important as technology. For example if a cloud-centric solution is more convenient, its users are less likely to engage in security compromising behaviours such as copying and pasting passwords, or declining to use a password manager at all outside of their local device context.
- movedx 5y agoI was referring to additional piece of secret material required to decrypt the vault. It increases the key length by 128 bits. This is important in the general, overall scheme of things based on how your mother will use the product. You’re not as good as they are at storing the vault, monitoring it, backing it up, and observing any and all access to that vault and reacting to access that’s not authorised. That’s literally their job and you have to trust someone to do that job well at some point (trust is the backbone of a healthy society) Of course you can get as good, and better, but the time and energy required would burn hundreds of hours you might consider spending doing something that generates more money, therefore negating any (reasonable) price they put on their product.