Use "App folder" access type instead of "Full Dropbox"
discussions.agilebits.com
discussions.agilebits.com
Some companies after a while just need to start following the Wendy's Twitter account model where they start just telling folks like it is after they've shown they aren't going to be reasonable.
Companies who ignore the actual solutions proposed to them, and instead attack a straw-man. Claiming they're being asked to make backwards incompatible changes for all existing users, instead of providing an an opt-in alternative for users who actually care about their security.
Companies whose culture is so inept that they blindly commit the most basic of engineering fallacies: Rejecting solutions on the basis of minor flaws, while defending a incumbent solution with massive flaws, simply because it is incumbent.
Are we allowed to tell other people why?
Then what is the problem??
As someone done Dropbox integration for many of my clients, I know how easy it is to implement app folders.
I know it and you know it. We all know what kind of game agilebit is playing here.
They addressed the ease of implementation, and have a valid point - it breaks backwards compatibility. That is something I do know about, and it's a terrible thing to do. Yes, they could write a migration path. Yes, they could write all the documentation in the world to go with the migration path. But, yes, it will cause their existing customers - who aren't complaining, save a handful - pain, since the app will stop working as expected, even if only briefly. And that still doesn't address the fact that AgileBits gets to make the app they want to make, and we have the choice to use it or not.
The ease of implementation was never their rationale not to, and even was acknowledged in the thread. And my primary point was that they're only accountable to users as far as they can keep them, and have the freedom to make the application they want.
Keep in mind that, since dropbox did not have app folder concept initially, many companies used to have access to entire dropbox then moved to app folder model later. they did not break backward compatibility and they didn't make the excuses.
Do you see AgileBits' point about that?
If your own creds are able to use more than the app folder, and if your threat is Agile Bits binary, the 1P app folder permissions will do nothing, the evil binary will just use your full creds.
Sounds like clamoring for them to reduce a bunch of use cases in service of security theater.
Dropbox full access is stored on their servers and it's in clear text. Dropbox regular login/password is also stored on their servers, but encrypted via a remote master key.
If AgileBits is compromised, they can access all your DropBox files. Attackers still can't access regular login/password because of the lack of master keys.
It is my understanding that at no point, does AgileBits store my Dropbox creds. It also does not store my 1Password vault.
You don't even enter your dropbox password into the app unless you're storing it as a credential, they present an authentication dialogue for the dropbox API just like all other third-party apps accessing Dropbox and store the OAuth key on the client. Not the server. That's why you have to re-authenticate with dropbox on every device you want to set up 1Password sync.
Complexity scales super-linearly on number of features. Solutions aren't the hard part. Implementations are.
This particular request explains why this wouldn't be the case.
It doesn't sound particularly easy, because the app would then have to support two modes - the new secure mode, and a legacy mode for backwards compatibility to avoid breaking users. There certainly would be an additional maintenance burden.
But it is disingenuous to claim that it is impossible to do so.
AgileBits does not claim it's impossible to do so. To quote:
"This is not to say it's impossible, but it requires much more careful planning and consideration than changing the permission request in the application."
They also note that 'the new secure mode' would break functionality for "many customers", due to a design choice (or flaw) in the Dropbox API:
"But even if we were able to work around many of those complications and used the Dropbox API to limit permissions and use a specific app folder, there's still at least one major issue, which (as Khad explained to you a few years ago) is that Dropbox API doesn't allow sharing folders between different Dropbox accounts. That would prevent sharing a 1Password vault with others via Dropbox, which is a feature that many customers love and rely on."
Claiming that this 'wouldn't be the case' is a misleading characterization. In actuality, they would have to support two modes - a reduced-functionality 'secure' mode, and a full-functionality 'legacy' mode. While it may be distasteful that users shares password vaults using Dropbox, they have clearly chosen to continue supporting that use case.
1Password offers a paid product that competes with the usually-free Dropbox-based sharing solution. Their paid product is far more secure than the shared-Dropbox method, with both per-vault and per-device encryption keys. It offers no compromises in functionality and offers what some would consider an increase in security for shared-vault users over the 'legacy' Dropbox model discussed herein. It uses a cloud storage service other than Dropbox, but that's no more a dealbreaker than Dropbox itself would be.
So with 1Password having already implemented both "the new secure mode" (paid) and "a legacy mode for backwards compatibility" (dropbox), they clearly have already accepted the additional maintenance burden of the increased security requirements of their 'new' method.
Please identify the evidence you see supporting your claim that it is impossible, in light of their words and actions to the contrary.
I'd even just like to see evidence that is is difficult to do. I mean, I can see how it's more work than doing nothing, but I find it hard to imagine it's all that challenging.
Huh? I claimed no such thing. I said "But it is disingenuous to claim that it is impossible to do so", which means exactly the opposite of what you seem to think that I claimed.
Now, you may disagree with Agilebits' methods of assessing those qualities or the particular trade-off they're choosing to make here, but you can't claim "security" in the abstract to justify a change without articulating its costs and benefits in more-concrete terms.
(Caveat: I use Keepass2Android, which ironically DOES support limiting access to the Apps folder in Dropbox.)
Incidentally, these sorts of access concerns are why I use KeePass over Dropbox instead of 1Password or other password managers with a hosted component.
I would much rather have this scenario (and give 1Password access to my full Dropbox) vs having all of my data on AgileBits servers and paying for an account for families or yearly for each individual. If 1Password went to requiring vaults to be in a specific, app-permissed folder, it would break my workflows completely.
Full disclosure: I'm a satisfied 1P user and don't really care about what kind of Dropbox access they use, although I'm open to persuasion on the second part.
Wouldn't the synced 1Pass passwords in DB be in an encrypted blob? I would assume that if someone compromised my DB password and got full access, they wouldn't be able to access the 1Pass passwords without my 1Pass Master Password. Is that not the case?
The dispute is about 1P's ongoing access to DB after you grant it permission to connect. The claim is that giving 1P full access is an increased risk.
The only way 1P's access to DB is a risk at all is if someone got ahold of 1P's access token. The only way to do that (at least on iOS) would be to exploit 1P somehow. But every time 1P runs, I authenticate, which would give exploit code access to all my passwords, including my DB password.
I don't see a scenario where an attacker is able to access 1P's token but not able to access my DB password.
i think i agree with this.. i mean, who stores unencrypted data in Dropbox anyway?
I think the real problem here would be people uploading unencrypted 'sensitive' data to Dropbox in the first place.
Looks like AgileBit is really really nosy about what users has stored in their dropbox. and just hate to lose the luxury to access every data stored by user.
Read the Pilor's (from AgileBit) response. she gives a link to article which talks about "How to sync 1Password with Dropbox" but she lies that the article details "Why 1Password needs full access".
As it stands now, if you are compromised, whether through a hack, state action, or even a disgruntled employee, you will expose the full contents of tens of thousands of Dropboxes, a monumental security nightmare for your company.
Does 1Password have a web-based interface where you authenticate against Dropbox and it stores the credentials server-side? I didn't think it did but I'm not super familiar with 1Password.
Otherwise the only attack vector is a compromised 1Password application, right? Not saying that's impossible, but if you are opening scenarios to that line of attack then many more worse things could happen even if the app didn't have outright Dropbox credentials.
Based on 1Password's response, it sounds like the app has to locate the password file based on a settings file, which could be a little fragile. A flaw in the code logic could accidentally modify other files unintentionally.
As an example, there was once a bug in Steam on Linux that force-deleted root because a path variable wasn't checked to ensure it wasn't empty.
Also, an attacker logging in to your Dropbox would leave a trace in your activity log.
Of course, it's up to 1Password to decide whether those scenarios are a high priority or not.
edit: 1Password, not Dropbox
Not that the problem is localized to 1Password: any non-sandboxed app could do that, given the default system configuration.
For alternatives to the popular cloud services for the privacy conscious, there's a good list of open source projects and products on https://www.privacytools.io
It is so simple, I actually used to it show my mom show to set up an encrypted folder on a flash drive of important information she wanted to store in a safety deposit box.
Dropbox could support both modes, but the company has obviously made a decision to prioritize one over the other (at least for now).
I've found AgileBits a bit weird in some of the decisions. It's clear that selling a password manager for $65 is no longer working well for the company, and so the subscriptions were introduced (IIRC, shared vaults exist only in the subscription). But as the OP says in the forum post, the subscription prices are quite high from a value standpoint when people have been using Dropbox or iCloud or something else all along. I've seen that AgileBits is also a bit slow to learn from customer feedback (like the MAS-only fiasco a few years ago). As more and more apps move toward a subscription model than a one-time pay-for-a-major-version model, I foresee more customer backlash on prices.
Edit: This backlash against subscription has already happened on the app store for Facetune and Infuse, to name two apps.
I still have my bank account memorized but other then that lastpass has been awesome for me for close to 5 years.
https://blog.lastpass.com/2016/11/get-lastpass-everywhere-mu...
> The alternative solutions aren't great. $36 a year to store a couple megabytes of data is outlandish. If you'd like to transition us to this from Dropbox, the price must be drastically reduced.
That $36 is a subscription price for the alternative, which the author mentioned as "outlandish" in that forum post.
And what's wrong in saying that the company moved to subscriptions because the $65 one time sale is not working out very well? One the company's website, the pricing page lists only the subscriptions prominently. One would have to either know that there is a standalone license or scroll down to the bottom of the page to find out that a standalone license exists. For a sale page, it clearly uses a dark pattern to make it seem like subscription is the only way there. Even the page name in the URL is "sign-up".
It's a huge deal that I can control who shares and sees what vault, turn off an employee's access as soon as they are leaving the company, revoke tokens, etc.
Before this we were using Dropbox and it was a nightmare. Credentials for a bunch of things were mixed up in the wrong vaults, far more duplication, revoking access was more of a pain, etc.
1Password for a family sharing may not be worth it, maybe not even for a small 5 person shop with a very stable set of employees who are all savvy. But with 25 or so people with varying level of technical expertise and actually critical information being shared, 1Password's subscription is a godsend.
For US$48 per year (I have the launch special, but it saves me $12/year), I have four people currently signed up (I could add three more; again, the launch special gives me two extra) where we can share passwords. I also have any major version of the software released now for any platform.
More importantly, I have been able to get my parents on 1Password reliably in a way that if they are incapacitated, my brother or I can use their accounts to make sure bills are paid when they should be (at least, that will happen when we have all of their accounts added to 1Password, but that’s a relatively small thing now). This is important because neither I nor my brother live near my parents (I’m in a different country). The software versions? Pretty important: I’m on Mac and iOS; my brother is on Mac and Android; my mom is on Windows and iOS; and my dad is on Windows and iOS and Android. Keeping those up-to-date with major versions would eventually get more expensive than the peace-of-mind that I have now.
LastPass does all of this cheaper at scale for companies ($2.40–$4/user/month) than 1Password ($4–$11/user/month) but the UX for LastPass is abysmal (although it does have a dedicated Linux client for those who need that)…and I honestly don’t trust LogMeIn at all. The other one that I have any opinions about is Dashlane, and it’s second/third-hand that it’s pretty good software (I haven’t used it because I’ve integrated 1Password in my workflow so deeply).
Yes, 1Password for families is worth every penny I pay.
I use that for one of my laptops that doesn't use dropbox and just set the folder to be the folder of the sync service I'm using on it.
All my 1Password vaults are kept in my ownCloud account. Even works fine on Android where I use an app called FolderSync to keep my vault synchronized on my phone and have added it to the 1Password Android app.
may i ask: on the android app, where are you keeping the opvault file? when i pointed the android app folder sync to the opvault folder downloaded to my android phone, it said 'no vault found'. are you using the old keychain file format?
thanks kindly
In order to exploit the suggested privilege escalation, you would need to exploit the client to feed you the oauth code. If you are exploiting the 1password client, you can do ANYTHING (including grabbing passwords after you unencrypt, reading filesystem, popping up a PWNED dialog). I don't think this effort should be urgent for 1password.
This recommendation doesn't make me feel meaningfully safer
(unless 1password has some clever process jailing inside their code to isolate the decryption component from the cloud component)
Limiting the access of Dropbox is all well and great except that it breaks sharing, which many people use, in exchange you simply move the files to another folder on the same Dropbox which effectively does nothing.
Slightly off topic, but Who stores senstive files unencrypted in Dropbox anyways?
Access to my Dropbox account would compromise my gmail account (and vice versa, since I keep my backup Dropbox 2-factors in Google Drive). I consider these two accounts my most sensitive/critical accounts for that reason. Could I encrypt the files in Dropbox? Sure. But that would make it more difficult to get to those backup keys (I might be reading them off a text file from the Dropbox app on my phone, for instance).
Has this happened often? No. Like, literally once. But it has happened, and I need to be able to recover my backup 2-factor codes.
Why not use a physical 2nd factor such as a U2F key?
I use 1P for Teams and have a small personal account and have been very happy.
I would rate the browser extensions 3.5/5 -- sometimes has trouble when there are multiple browser windows and I can't exactly figure out what the "timeout" period is before I have to enter my cumbersome master password again.
I would rate the Android app 4/5 -- it has a feature to use a PIN instead of my full master password, which is fine for my usage, but that feature never seems to work.
Overall, it works fine about 90% of the time. I feel like I've gotten my monies worth. My password habits are better than before using it. I think the software could be improved and I am slightly hesitant about the companies recent push for cloud hosting (which I will never use).
Neither Windows client nor the Windows browser plugin seems to be as flexible or as polished. Until very recently it wasn't possible to add custom fields (one had to log into 1Password via the in-browser client or use the macOS/iOS client to do things like add a TOTP credential), and the browser plugin's UI is slow and more difficult to use compared to the macOS version. While the Windows client comes packaged as an MSI, I believe that it only supports per-user installs, which prevented me from deploying it using our enterprise configuration management system. Ultimately, it seems like the Windows client and browser plugin aren't supported as well as the macOS/iOS versions, which has ended up slowing our adoption of the software as most of our users run Windows (I'm getting ready to transition away from macOS myself).
The team management features of 1Password work well, but one can only access them via the in-browser web app as neither the client nor the browser plugin provide access to those features. So far I haven't run into any synchronization problems, and that includes using it in some out-of-the-way places with poor network connectivity (high latency/high packet loss/low bandwidth).
Because I was using KeePass, I could not use 1Password's built-in migration tool. Their third-party migration tool (which I grabbed from their GitHub repo) worked smoothly.
Overall, 1Password for Teams works better than the mix of KeePass and ownCloud I was using before (not to mention the questionable third-party ports of KeePass to iOS/Android or the fact that KeePass did not work at all when run under Mono on macOS). Despite the limitations and relatively poor performance of their Windows offerings (my biggest issues with the product), I will likely renew our subscription this year.
I avoid the 1Password.com cloud hosting stuff because it slightly expands the threat model in exchange for web access to my passwords on public/stranger's computers, something I view as an anti-feature.
0.Browser integration works but the auto-submit feature doesn't.
I was opposed to the subscription-based pricing. However, my wife moved to an employer where it's not possible to install 3rd party software. Since 1Password Anywhere is now defunct [1], we decided to take a family subscription so that she can use the web interface at work.
Their subscription version also works fine - I didn't notice any significant differences in my day to day use, except that sharing has become much simpler.
[1] https://discussions.agilebits.com/discussion/63045/moving-be...
"Now there certainly are some geek creed we could get from building PGP/GnuPG signatures files, and we might do it. But I'm doubtful that it actually would provide a meaningful improvement in security. On the whole, we try to avoid "security theater" even if it is of the geeky sort"
* They are a bigger target to a watering hole attack than Transmission BT.
* They think authenticating your downloaded is "security theater".
* They are #2 on http://mostvulnerable.com
What is the advantage of 1password compared to the rest of the lot? I keep seeing the name in articles so it must be popular, but I associate it with passwords stored in the cloud which sounds insane to me.
As far as advantages, I'd say that 1Password is a very slick and well-designed password manager that focuses on covering a particular common case - someone with a Mac, an iPhone/Android device and possibly a Windows PC who wants to sync their passwords between those devices and fill passwords in their browsers. It offers first-party supported browser extensions and handles conflicting sync changes well, which were two major pain points for me when I used KeePass.
If you're happy with KeePass, there's not really a compelling reason to switch. If you fit their target audience and want something with better sync/browser integration and/or a better Mac client, I think it's a compelling alternative.