3 ms·
Is that same risk present if you use the app? My understanding is the app decrypts the vault locally. I guess they could put out a malicious update but then yo
by nerdawson 4y ago
Is that same risk present if you use the app?
My understanding is the app decrypts the vault locally. I guess they could put out a malicious update but then you’d be impacted whether there was a cloud-free option or not.
- nicolas_t 4y agoYes, but I think it would be harder to push a malicious update especially since currently 1password doesn't send information on the license when checking for updates. So a malicious update wouldn't be targeted as easily as logging in a web app. Additionally exfiltrating the data would be harder for a locally stored vault..