>
I gave up using 1Password when I realized the loopback is cleartexted when autofilling passwordsThere's a forum post or blog post or something (I forget) by 1Password about why this is, and it basically boils down to, it's impossible to be completely certain that the other end is the process you're trying to talk to, so there's no point in encrypting the traffic on the wire. Any process with permission to sniff the traffic (i.e. root) also is capable of intercepting the connection entirely and pretending to be the other end, so encryption doesn't really get you anything. Remember, both ends are processes on the same machine, so you can't use certificates or signatures to prove identity as the keys would have to be on the local machine where the attacker can find them.
> a host of other vulns like the .opvault format not used as the default
It was used as the default for iCloud, just not for Dropbox because of compatibility concerns with older versions of 1Password. According to a forum post from 2 years ago, "In time, all users will be converted to the newer format" (https://discussions.agilebits.com/discussion/comment/139552/...). I'm not actually sure whether they've made the switch yet, since I already stopped using Dropbox for syncing.
> and too many other vulns to count
Please elaborate. I've heard of far fewer issues with 1Password than competing services. I've certainly never seen anything that even remotely qualifies as "too many other vulns to count". So I'm extremely skeptical of this claim.
> The master password is also a single point of failure and once you get that, you get everything
You also need to have the actual data. I'm skeptical that KeePass is any better. From reading wikipedia, it needs a master password and/or a key file. If you use a master password, that's the same as 1Password. If you use a key file, anyone who gets access to your machine can now decrypt all your passwords so that seems worse. If you use both a master password and keyfile, anyone who gets access to your machine (i.e. to get your KDBX file) and has your master password can also get at everything, and it's also not clear how using a combination like this even works if you're syncing your KBDX file with any other machines (e.g. using Dropbox). Wikipedia also says you can use the Windows current user details instead of a password/key file, but again, any attacker that gets access to your machine now has all the information necessary to decrypt your KBDX file.
> With KeePass even if they have the master password, they also need a key, and a machine ID so a copy of the KDBX file is useless to an attacker (unless the can emulate your machine UUID)
They don't need to emulate your machine UUID, they just need to apply the cryptographic operations to decrypt the KBDX file themselves. If an attacker gets access to your machine (e.g. to get your KBDX file), they can get all that other info too (assuming you even set up KeePass to use that info).