Do you have a view on 1Password versus LastPass?
Do you have a view on 1Password versus LastPass?
LastPass has been exploited a few times in ways that could have given up passwords. Their UX and server infrastructure seems to be a mess of php scripts, that itself doesn't have to be insecure but is a code smell. Their commercial support looks unmaintained. Both platforms support "cloud" based syncing but since 1Password's is pretty new I can't speak to it.
1Password does local encryption outside of the browser, LastPass will encrypt locally in the browser.
1Password can leverage other file transports to sync passwords, iCloud, DropBox, or any shared directory. LastPass does it all with their servers.
LastPass's web interface if compromised can have you give away the password to all your passwords. 1Password has a much smaller risk of this and would probably have to include a malicious software update.
1Password Families/Teams exists and I'm not familiar with it but it probably has a similar attack vector to LastPass's web interfaces.
You know, they both offer end to end encryption with similar attacks. Overall these companies are big targets and I'd rather keep my passwords offline or synced via side channels in a standalone app like 1Password.
PS I'd be amiss if I didn't mention dashlane https://www.dashlane.com/ I hear good things and it's passed review at a few companies who know their stuff, but that's all I know.
One of the first things I learned about security was not to tell the user which credential was incorrect.
Disclaimer: I'm not a security expert.
My only contribution is that I suspect that in practice almost every site leaks this info if you try hard enough, via some form of timing attack. You can get off-the-shelf "constant time string comparison" algorithms, but it's impractical to write anything much larger in a constant-time fashion, certainly nothing as complicated as a full authentication flow, especially in the light of the complexity of the systems we program on nowadays, with so many layers of caching to exploit for timing, etc. I've leaned in the direction of going for the user-friendly approach in my code, though I've only come around to that recently.
Tavis Ormandy found some really bad vulnerabilities in Dashlane (and 1Password). [1] [2] [3] [4]
[1] https://bugs.chromium.org/p/project-zero/issues/detail?id=89...
[2] https://twitter.com/taviso/status/769391927892598784
I don't know anything about Windows 1Password, but for macOS, I strongly recommend 1Password over any of the alternatives.
A central cloud service using closed source applications for storing passwords just seems like an easy target for assailants.
Use 1Password.
Use Dashlane.
I have wondered if running 1Password through wine would introduce some not-considered attack vector, but I've yet to hear it.