4 ms·
Ask HN: What will happen the day 1Password is thoroughly breached?
I see some people using this for "every" password, I shudder to think the day it will inevitably will breach, but it got me thinking would it be maybe nothing or you think it'd be even bigger disaster than I am thinking. And what about plaid, which one is going to be worse plaid or 1password?
- Barrin92 5y ago1password and pretty much any other password manager around only have access to your passwords in encrypted form, so the answer is, pretty much nothing provided only you know your master password.
- lifeplusplus 5y agothey are encrypted not hashed so they can be decrypted
- Barrin92 5y agoThat sentence doesn't make any sense. 1password, on your device before anything ever reaches their servers encrypt your data with a combination of your master password and a secret key that only you have access to. That is 128bits of entropy, which makes any decryption technically unfeasible. https://support.1password.com/1password-security/ https://support.1password.com/1password-security/
- version_five 5y agoAs has already been said, it's not like they have a spreadsheet of each users passwords. Someone with more of a security background could explain better, but even if they were "breached", the attackers would still need each individuals password at minimum, possible still their "recovery kit" which for everyone is high entropy enough that it is not guessable with the amount of energy in the universe. (I have all my passwords in 1password, but if there is s legit weakness I'd definitely like to know it)
- seized 5y agoThem being breached shouldn't matter. Unless their encryption is terrible, or your master password is weak, or they get SolarWinds style breach. If you're really worried, use 2FA as much as possible and you can consider peppering your passwords. https://en.m.wikipedia.org/wiki/Pepper_(cryptography) https://en.m.wikipedia.org/wiki/Pepper_(cryptography)
- josephcsible 5y agoPeppering is something that a service does on its backend to make the hashes it stores more secure. It's not something that you as an end-user of a service can do in any meaningful way.
- seized 5y agoNo, you're thinking of salting.
- josephcsible 5y agoWhat I said is true of both peppering and salting.
- josephcsible 5y agoA lot of people are downplaying this, as if the only way that 1Password could be breached is if their raw data all gets stolen, because everything important would be encrypted. But what if their Web site instead gets modified to serve a client that exfiltrates everyone's master passwords as they log in?
- troydavis 5y ago1Password addresses this and a lot more in https://support.1password.com/1password-security/ https://support.1password.com/1password-security/ . An excerpt: > Your account password is never stored alongside your 1Password data or transmitted over the network. If you want a lot more detail, pages 10-11 of https://1passwordstatic.com/files/security/1password-white-paper.pdf https://1passwordstatic.com/files/security/1password-white-p... are good places to start.
- josephcsible 5y ago> Your account password is never stored alongside your 1Password data or transmitted over the network. Sure, the legitimate client doesn't do that. But unless you do a full audit of 1Password's JavaScript every time you visit it to log in, an attacker who breaches their servers could switch out the legitimate client for an identical-looking malicious one that does do that.
- troydavis 5y agoThat’s a big reason why 1Password recommends using native clients, not the Web interface. Page 68 of https://1passwordstatic.com/files/security/1password-white-paper.pdf https://1passwordstatic.com/files/security/1password-white-p... covers that in detail, but the gist is “Use (code-signed) native clients as much as possible.”
- josephcsible 5y agoYes, using a native client would help, since now the server that would need to be compromised is 1Password's build-box, and it'd be much more difficult to get away with targeting only a few specific users with a modified client. What would help a lot more is if the clients were all fully open source with a 100% reproducible build process.
- aborsy 5y agoThe passwords might be encrypted. But an attacker could make a small modification to JS code, or push a bad application update to everyone. Both website and the Apps can be compromised. This is actually how governments broke E2E-encrypted chat systems of criminals: by taking over the central server and from there updating everyone.
- notemaker 5y agoEncrochat for the curious.