10 ms·
How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe the
by FatActor 4y ago
How do we know 1Password doesn't have similar glaring oversights like LP?
We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word.
Granted, if I had to chose today, I would instantly pick 1Password based on what I can find on google, and LP has far, far more leaks than 1P.
But let's not kid ourselves that 1P is somehow more trustworthy without audits. And I'll eat crow if 1P has proof that they are routinely audited by 3rd parties.
EDIT: removed snark.
EDIT#2: If Signal can publish open source, why cant 1Password? If security is done right, the source code should be visible to everyone without jeopardy, or at least that's what I've been led to believe.
EDIT#3: Thanks for the link y'all, here it is at top level: https://1passwordstatic.com/files/security/1password-white-paper.pdf https://1passwordstatic.com/files/security/1password-white-p... ... mmmm crow
EDIT#4: We trust browsers too much. 1P stores the secret key on every device so that you only have to enter your passphrase. I'd really like that code to be public because that's a great way to lose control of everyone's secret key. Extensions worry me because they are a critical component in any password manager's usability-vs-security. But perhaps that is a digression or worth an Ask HN.
- samwillis 4y agoThere is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-paper.pdf https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.
- FatActor 4y agoThank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.
- beckingz 4y agoMost people don't read open source and instead trust that the experts will catch any issues....
- FatActor 4y agoIt's turtles all the way down. Would you rather NOT have the option for other experts to see the code?
- danShumway 4y agoOf course not, I'd rather the code be Open and audited. Being Open Source is in some ways a multiplier on security because it allows more expert review. But the expert review is the important part; if security-critical code is Open Source but hasn't been looked at by anyone other than the main developers, the Open Source part is a multiplier on zero. It's a little bit more complicated than that, and there are a lot other factors at play as well even outside of security. We're not really getting into stuff like future-proofing and what happens if 1Password gets a lot worse in the future. It's complicated. But the gist is that while it would be a lot better if 1Password was Open Source, it's still in its current state probably got more eyes on it than some Open Source security projects do.
- JamesBarney 4y agoWhen the tool is opened sourced honest and rogue security experts are going to go through it. Now how much value is the first adding versus the second removing is the case. And based on incentives for each, an honest security research maybe getting a small bug bounty, and a rogue one potentially gaining access to 10's of thousands of accounts I think it might be a net negative overall.
- function_seven 4y agoEven so, the number of experts looking at the code will increase if it's open, right? I know the concept of "many eyes makes all bugs shallow" isn't the panacea we once thought it was; that still there can be bugs lurking in widely-read sources. But it must be smaller than the number of bugs that exist in code read by a smaller group.
- EMIRELADERO 4y agoStill doesn't explain why it's all not at least source-available. I'm not going to complain if they don't use open-source licenses such as MIT or (A)GPL, but straight up not making the source code publicly readable at all is a big strike against it.
- dagi3d 4y agoMaking it opensource is no guarantee at all(if there could be any), for instance it could be more dangerous: anyone could spot a security hole and take advantage of it without reporting it, there is no guarantee there would be a responsible disclosure.
- EMIRELADERO 4y agoAre you vouching for security through obscurity?
- dagi3d 4y agoWhen systems and code are audited and pentested by third parties, I don't see any benefit of actually making anything public.
- samwillis 4y agoThere is good insight into this from this comment from them in 2014: https://1password.community/discussion/comment/114870/#Comment_114870 https://1password.community/discussion/comment/114870/#Comme...
- EMIRELADERO 4y agoThat seems to be about transitioning to an open-source model. I don't mean that. I mean simply having their git repo publicly accesible in a read-only fashion. No external contributions, no license, etc. I see no reason not to do this, especially for such a security-oriented service. You should be striving for as much transparency as possible.
- joshe 4y agoWhich people? I've been very reluctant to use their cloud solution as I trust Dropbox more for security. So I still fight 1password to keep the vault stored in Dropbox. I figure there are maybe 4 organizations who are active enough to prevent a full download of all their user's data. Google, Dropbox, Amazon, and Facebook. (Maybe Apple, but they seem lethargic.) Because they store all the passwords to all of our services they are a huge target.
- irrational 4y agoMy company forced us to use Box and actively blocks Dropbox on all work computers. They did an audit and didn’t like what they saw in Dropbox.
- soraminazuki 4y agoYou trust Dropbox? The company that infamously invited to their board a former government official responsible for authorizing warrantless mass surveillance?
- dijit 4y agoi think “trusting dropbox more” is not what i would necessarily expect. nonetheless i think the provider of my password manager should not themselves host my password vault. If anyone from 1password is reading this: I trust you, but you make it hard to do so if you cannot be flexible about not hosting everything. fd: I use 1password at home and for work.
- manmal 4y agoHow would you run a shared vault for work on a „dumb“ file hosting service? With the ability to add/remove team members, recover vaults in case of password loss etc? What about the fact that master passwords can be brute forced if they are weak, just as LP customers are now affected?
- dijit 4y agoI mean, crypographically we’ve had solutions to those exact problems for 30 years. PGP might not be very usable but it also had mechanisms to do this. if you are scared of people copying the vault before they lose access to the storage: you’ll be very sad to know that this is already possible with the SaaS solutions. if you're worried about people breaking the vault if they have access: then its even more of a reason to control the access.
- alecco 4y ago> Finally, it's been built by people who are respected in the security industry. Source for this? To me, the celebrity endorsement makes me doubt it's a serious business.
- weakfortress 4y ago1password has a document on their security arch: https://1passwordstatic.com/files/security/1password-white-paper.pdf https://1passwordstatic.com/files/security/1password-white-p.... This alone lends credence to their claims. To this date there has been no major breaches despite being a large target (albeit smaller than LP). Moreover, the fact that your vault is both password protected and locked behind a secret key is about as good as you can get in terms of commercially offered security. That's not to say they couldn't be lying. But after careful evaluation I've gone to them and people much more experienced in security have also moved to them as well. FWIW a "source code audit" or "making it open source" does not imply intrinsic security. You are putting far too much weight in either a firm to do the right thing with money, or the existence of sufficiently motivated OSS researchers mining what might be millions of lines of code. We still find bugs in the Linux kernel regularly despite it quite literally having tens of millions of eyes on it. What makes you think this would do anything more than assuage your fears through security kabuki? In fact, OSS while sounding nice introduces an entirely new attack vector that a company may simply not have the staff to mitigate. To use the Linux kernel once more vulnerabilities have been deliberately injected into the kernel more than once. There have been game breaking SSL bugs. Huge overflow problems, etc. I love OSS. It is not a panacea. Signal chose this model - it does not imply it is the best, the most practical, or the most secure.
- deleted 4y ago[deleted]
- EMIRELADERO 4y agoIf a document alone lends credence to their claims, the source code would do wonders. It's not about public contributions, it's about transparency and good faith.
- maccard 4y agoWhy do you trust the source code is actually what they deploy to your device, or that what they build isnt linked against extra libraries, maybe even internal library?
- deleted 4y ago[deleted]
- joegahona 4y agoI asked this a few days ago on a similar thread. Some good info here: https://news.ycombinator.com/item?id=34137643 https://news.ycombinator.com/item?id=34137643
- deleted 4y ago[deleted]
- danShumway 4y agoImportant piece of context here: if LastPass was the only password manager on the market, that's what I would recommend people use, even after the breach. Having a password manager is a big boost in security even if that manager is LastPass. Personally, I stick to Open Source solutions (KeepassXC), but I don't typically recommend other people use KeePass unless they're technically inclined -- because the biggest risk with a password manager in my opinion is user error, and so I want to focus on that even if it means that someone isn't using an Open Source program. All that to say, that this line: > Granted, if I had to chose today, I would instantly pick 1Password is a pretty good summation of the situation. I do think 1Password is a lot likely to be a lot more secure than LastPass, but even if I wasn't confident about that, the situation many users are in is: - they should be using a password manager, so they do need one today - an online password manager is a better fit for most users than an offline solution - 1Password is (I think) slightly easier to use than Bitwarden and is more often recommended by security professionals. ---- But Bitwarden would still be a fine choice for people who want to use something Open Source, and offline solutions are great for people who feel comfortable with them (I keep my password manager offline because I have the technical skills to do so, so I like the added boost of security from my vault not sitting open on a server someplace). But the important thing is that they use a password manager in the first place, since using actually secure unique passwords across every site is basically impossible for most people without one. It's not so much that I assume 1Password is perfect, I just think it's the best choice for a lot of people right now based on the information we have. I'm not going to recommend KeePassXC to my parents, it's important to me that their solution be online and managed by a professional. A lot of security is about making the best choice available based on imperfect information and based on individual context. I used to recommend LastPass to people who I knew weren't willing to pay money, because (again) I wanted them to be using a password manager no matter what, and if they weren't willing to pay for 1Password, they might as well use something free. But even that advantage kind of dried up a little bit, LastPass has gotten a lot less generous about what they offer for free.
- dkokelley 4y agoI don't buy the "if it's open source we can see/audit/trust the service" argument. 1. Bugs get missed all of the time in OSS. There is no guarantee that the more eyes the better, and in fact there may be a negative correlation due to the bystander effect [citation needed]. 2. A software service is a complex interaction between many pieces of software. Two perfectly secure, audited pieces of software could interact in an exploitable way. 3. Just because the service provider tells you "this is the code, this is how we keep you secure, etc." doesn't mean it's true in practice. A bad actor could modify the code in production before the next version of "audited, trusted, OSS" is vetted. 4. Security practices outside of the code also matter (arguably more so), and even an organization with good policies can fail to follow them at times. Ultimately, we're trusting the people behind the services we use to be honest and do their best. It seems that LastPass has demonstrated they aren't as deserving of that trust lately, but THE SAME THING COULD HAPPEN AT ANY ORGANIZATION. Footnote: LP/1P could push an update that grabs everything necessary to decrypt your password vault the next time you log in.
- buu700 4y agoSource code is necessary for trust, but not sufficient.
- dkokelley 4y agoIt's a nice data point, but it's not necessary to me. Do you have the source code to your mail service provider or your online banking software? [1] Having the source code available says a few nice things: 1. This company is confident enough to show their work 2. This company is "good" at software engineering (or it could reveal the opposite) [1] I know some people can and do run their own mail servers. I can respect that, but I trust the Google devs and organization to be properly competent and incentivized to do a good job keeping my email account safe.
- buu700 4y agoMy mail provider and bank may be fine for their intended purposes, but I definitely don't trust them for storage of secrets or keys.
- sanjayio 4y agoThe older versions of 1Password are BYOH, bring your own hosting. I use it because I don’t want a single source of failure. My information is encrypted and stored in another cloud service. It doesn’t matter if that cloud service is breached. It doesn’t matter if 1Password is breached.
- casenjo 4y agoIt's a shame because it's an excellent product, I really wish 1P understood this. Their removal of the cloud sync feature and insistence on moving to a subscription-based model is infuriating and drove me away from them. I want to be in control of where my vault is synced to and the only way of doing that is by staying stuck with the older 1Password 7.
- brightball 4y agoOne of the primary reasons I switched to Bitwarden. That and prioritizing Linux.
- ilyt 4y agoHow good is browser addon in comparison to lastpass? This and vaultwarden being mature enough might be final push to make us move
- brightball 4y agoI prefer it, but I haven’t used LastPass in about 3 years so I can’t give an up to date opinion.
- ilyt 4y agoWell it didn't got any better for last 3 years so your opinion is most likely still current
- deleted 4y ago[deleted]