3 ms·
1Password and Mac OS X Keychain used to do that.[1] They'd leave the URL and title in plain text, amongst some other metadata. I think both no longer do, but t
by runlevel1 4y ago
1Password and Mac OS X Keychain used to do that.[1] They'd leave the URL and title in plain text, amongst some other metadata.
I think both no longer do, but the fact that they once did was very surprising to me.
[1]: https://1password.community/discussion/12237/metadata-is-not-encrypted https://1password.community/discussion/12237/metadata-is-not...
- mdaniel 4y agoIn their defense, the treat model was way different back when they were using local vaults; I suspect the old "cloud storage" model they used placed each individual user who chose to sync opvault to the cloud at some risk, but short of Dropbox or OneDrive themselves getting popped, the cloud attack against 1P vaults was very limited It doesn't escape me that their threat model could still be that, if they'd relent the cloud-only licensing choice