5 ms·
I hope they roll out a new 1password version soon. I was just thinking of starting using it, after the linode incident, but now I might wait for the fixed versi
by nixarn 13y ago
I hope they roll out a new 1password version soon. I was just thinking of starting using it, after the linode incident, but now I might wait for the fixed version.
- tptacek 13y agoThat's silly. Even in the least charitable interpretation of what's happened, 1Password's security margin went from N (where N was a hypothetical security level believed to have been achieved by 1Pw, not some objective standard) to N/2. N/2 in this case is still light years past salted hashes.
- jholman 13y agoI'm actually seeing N/4 in that hashcat.net/forum thread. See hashcat.net/forum/thread-2238-post-13424.html#pid13424 , or alternately just the last line of the original TFA, which says "reduce [work required] from 8000 to 2002". I'm not sure how this is "least charitable", it seems to be pretty much the only interpretation. Either way, I'm not seeing the significance at all. I look forward to a reply from atom to penultimate post in that thread (#24) in which guinndupont explicitly asks for the real-world significance. And I agree with Thomas and miles, that the vendor response is wonderfully direct, informative, reasonable, helpful, non-weaselly, etc. Props to him.
- tptacek 13y agoI used the word "charitable" because the "N" in this measurement is a hypothetical measurement of how much more secure 1Password could have been. But if that's a valid analysis, it's just as valid to say they should have been using scrypt. Which, sure, but who cares?
- caf 13y agoSince N is generally measured in bits, I'd say it's reduced to N-1.
- rdl 13y agoI hope they roll out a new version for better syncing between computers and phones, but I'm pretty comfortable with the security in 1Password 3 today. There really isn't a good way for anyone except Apple to make a great password manager on iOS, though, without getting every single app vendor to write to a password manager's API. But 1Password on iOS is pretty good. (what doesn't work so well is that you have to manually cut and paste passwords into browser or other apps; I'm not comfortable running a browser inside 1password)
- jonknee 13y agoDropbox syncing works well for me.
- rdl 13y agoI don't want the encrypted file containing ~all of my passwords in an unencrypted Dropbox folder somewhere. If I control access to my keyfile, I'm at least protected somewhat against brute force, weaknesses in the software, someone stealing my master passphrase casually, etc.
- nwh 13y agoThey also have a USB synching tool if you're not comfortable with Dropbox (I'm not). http://discussions.agilebits.com/discussion/11935/first-public-beta-of-1password-usb-sync-mac-os-x http://discussions.agilebits.com/discussion/11935/first-publ...
- rdl 13y agoI still use their wifi sync, but it never worked very well. The problem I have (which isn't THAT MUCH of an outlier) is that I have an MBA, a MBP17-desktop, an iPad, and an iPhone. I want to be able to use all of my normal/boring/personal/medium-sec passwords from all of my devices, want to be able to add new services from any of those devices, and I want to be able to do password updates from any of those devices. Ideally without ever connecting cables -- my iPhone/iPad get plugged into a charger in the car or by the bed, but not connected to either of the Macs. All of their sync seems to be built around one Mac, one or two iOS devices; the USB, the older wifi, etc. Dropbox is the only solution they offer which is many-to-many. I'm also essentially terrified of corruption or losing the data file, so any but the most cautious and transparent sync scares me.