4 ms·
I use 1Password, and migrated over to their subscription service some time ago. A password manager seems like the best overall option at this time. However, gi
by devnulll 5y ago
I use 1Password, and migrated over to their subscription service some time ago. A password manager seems like the best overall option at this time.
However, given they have all the password for many people, how are they not one of the biggest targets in the world? In their old Dropbox model, I understood the security model. In the service model it's moved to "Just Trust Us".
Is there anyone who can help me understand how this model is secure?
- judge2020 5y agohttps://1password.com/security/ https://1password.com/security/ It's basically E2EE (where the encryption key is your master password + secret key, which looks similar to a guid), with the caveat being that 1password is still accessible via the browser so you do have to trust they're not compromising you by saving your secret key + master password separately (that is, unless you're auditing the login page every time you open it).
- djrogers 5y agoErr, have you checked with them? https://support.1password.com/security-assessments/ https://support.1password.com/security-assessments/ They've gone pretty far above and beyond what we're used to seeing wrt sharing security details, audit results, and architecture information.