3 ms·
In 1Password: - the master key derives from 1. your password, and 2. a long, random key that you type manually on each new device (so you can’t brute-force the
by joconde 5y ago
In 1Password:
- the master key derives from 1. your password, and 2. a long, random key that you type manually on each new device (so you can’t brute-force the password just from the server’s data, and you can’t decrypt the data just from your hard drive without the master password),
- none of these keys ever leave your devices (encryption and decryption happen client-side),
- the key is deleted from RAM, locking the vault, if you’re inactive for too long.
That makes some attacks hard. It will be defeated if malware can get 1. your secret key and 2. your master password. But in that case, your login cookies and what you type in login forms are vulnerable too, so there isn’t much difference.