The 1Password 7 Beta for Mac
blog.agilebits.com
blog.agilebits.com
One pro-tip I learned last year is to replace Google Authenticator with 1Password's 2FA solution. It is really well implemented and copies the 2FA code to the clipboard when you fill in a login, and then removes it a minute or so later. You do need to make sure you're 1Password recovery information is someplace secure because you're in a bad place if you ever lost your devices.
At that point it’s no longer two-factor, it’s just two steps in the same authentication.
https://blog.agilebits.com/2015/01/26/totp-for-1password-use...
Hope that clears things up for both of you. Let me know if you have any questions though!
Kyle
AgileBits
And definitely the TOTP integration. I love how after you hit Cmd-\ to fill in your username and password, it automatically copies the TOTP value to the clipboard for instant-pasting on the nice screen. Such a great feature.
They run a brilliant service though that I can use on my OS X & Android daily drivers, their Android app is top notch -- which even supports fingerprint authentication -- so I can't complain.
First off - thanks for making 1Password, I've been an unpaid brand ambassador since 2011. I've successfully converted over 5 users (rather lit if you ask me fam).
I was wondering if you can comment on plans for 1Password standalone (non-cloud) version. For me (and few others I'd imagine based on[1]) it is a must have feature. I'd be happy to pay subscription fee of using your software - just that I want absolutely nothing to do with hosting my passwords in 1Password Cloud - this was the argument I used to use during LassPass vs 1Password debates - "with 1Password, you can sync your vault any way you want (rsync/dropbox/lan sync)".
[1] https://discussions.agilebits.com/discussion/76885/1password...
We never comment on future plans simply because they're subject to change. We can't promise something now and expect the software world to be the same in 1 year or 2 years.
All I think is reasonable to say in this case is that 1Password 7 for Mac (and Windows) both have standalone licenses available, as we have traditionally sold (per user, per platform, for that particular version, in this case 7.x) and those standalone licenses support syncing to standalone vaults (Dropbox, iCloud, Folder, and WLAN for Mac. Dropbox for Windows).
Note that version 7 is likely only going to support our OPVault format, NOT AgileKeychain. Import from AgileKeychain, but not sync to AgileKeychain.
Hope that helps, but I realize you might be asking what about version 8, or 9, or future version x. We simply can't answer that question because it's too far in the future. It's like asking me to promise that I'm going to buy a house in 1-2 years when I have no idea what the future holds.
Thanks for converting those users though! You've helped us continue to do what we love to do. We wouldn't be here without users like yourself helping make 1Password as great as it can be.
Kyle
AgileBits
I like how this team keeps iterating and tweaking things, even though they've largely already solved the issues with password management for me. And they aren't just adding superfluous features.
I am most excited about markdown in notes!
Is that the new version of Zawinski's Law:
Question 1: Can someone comment on the actual severity of them storing all my passwords remotely? I don't like the idea of it, but it seems like they're a reputable company so I assume they have good systems in place. I have the standalone right now but it's getting to be a pain to move from computer to computer, and I don't trust dropbox sync.
Question 2: Lets say the online version gets hacked... and they steal all the vaults, does that mean they only need my master password to get in? What about people who have weaker master passwords. Can people brute force the password vault in the same way that someone can if they have a hash database of passwords?
Edit >> Forgot to post the link to the article https://blog.elcomsoft.com/2017/08/attacking-the-1password-m...
It's the only thing you'll have to remember, so while a pass phrase that length would normally be a hurdle, it isn't hard to remember. It'll be a pain to type at first but you'll get muscle memory before too long.
6 Characters? If your master password is only 6 characters then yes, you are screwed if your vault leaks.
The random Secret Key provides the additional protection against brute forcing accounts even when the master password is weak.
For an attacker to guess your password, they need to run a bunch of guesses through the same encryption process, and only when they get the same encrypted result they’ll know they have the correct unencrypted one. This is time consuming, so attackers may use rainbow tables[1] — essentially a list with a ton of precomputed passwords they can check. To counteract this you salt[2] a password, essentially adding random data to it. So now even if we have the same password, since our salt (random data) will be different, the resulting encrypted version will also be different.
Even if the attacker gets your vault and secret key, they’ll still need to brute-force[3] the password.
Ars Technica’s has an excellent explanation of all this[4].
[1]: https://en.wikipedia.org/wiki/Rainbow_table
[2]: https://en.wikipedia.org/wiki/Salt_(cryptography)
[3]: https://en.wikipedia.org/wiki/Brute-force_attack
[4]: https://arstechnica.com/information-technology/2013/05/how-c...
See Key Derivation on page 24 for this specifically. We call it 2SKD.
Page 26 also shows how the secret key and the master password are combined. From that other keys are derived.
It's actually a very fascinating process, combined with our use of SRP, I have to say I rather love how well all of this meshes together.
In the situation where someone gets your data from our server, which is the big thing people are worried about, they're going to have to combine a guess for your master password and the secret key to perform a guess.
They could in theory get your secret key from your local devices, as these are saved there, but your Master Password protects in that case as it's not stored anywhere (unless you've enabled features like Touch ID or Face ID, but those are protected in other ways).
Your Secret Key protects your data on our server. It makes brute forcing that data an incredibly expensive process.
Your Master Password also helps protect your data on our server, but it also protects your data locally.
Let me know if that helps explain things.
Kyle
AgileBits
Can Apple then get my Master Password (along with FBI w/warrant, etc)?
The key pair is generated in, and never leaves, the Secure Enclave. It's how this feature was designed by Apple.
Kyle
AgileBits
This is, of course, no substitute for a nice long password whose characters are members of the largest alphabet you can think of, but it's something.
I'm not qualified to analyze a security system in detail, but 1Password have published the mechanism they use to secure vaults. You might want to check it out for more details:
https://1password.com/files/1Password%20for%20Teams%20White%...
The most important part here is the Secret Key which provides additional 128 bits of entropy.
Mostly it looks like new eye candy, and apparently some speedups, not that it was slow before.
Apple's keychain, while uglier than a Fiat Multipla and harder to use than a Wiimote on a CRT, at least does get this right.
But apparently bold text and 21st century 1337speak sell better than a CLI integration. Unfortunately, I can't say I'm surprised.
I guess the silver lining is: this can only mean password managers are not just used by security professionals anymore, and are actually becoming mainstream. Hurray :/
I had no idea they had a CLI implementation, and I've been looking for something that manages server/api keys as well as cloud service passwords. I imagine there's a better way to do this using enterprise key management software, but I no longer work for a place w/ this kind of budget.
for enterprise key management, I recommend Hashicorp Vault (https://www.vaultproject.io/) it's OSS so no giant budget required.
There is a CLI available as a 3rd party app that works with newer 1P versions and talks to your local 1P vault: https://github.com/peacetara/slab/blob/master/src/python/REA...
Honestly the more I use it the less I understand how any company can allow employees to store AWS creds in a plain text file :/ lack of alternatives, I’m afraid. As is apparent from this thread :)
Interesting they intentionally moved from multithreaded to singlethreaded.
Here's the first screenshot of the flow I found: https://releasenotes.docs.salesforce.com/en-us/winter17/rele...
iOS11 added a new variant on this, with a little key icon in the keyboard when you're in a password area, but it's only filling from the system keychain and isn't open to third parties. (Yet?)
See: https://techcrunch.com/2017/06/08/ios-11s-new-password-autof...
https://blog.agilebits.com/1password-apps/
There are likely other apps that are not on this list, but if they don't tell us they have added support it's difficult for us to add them.
You can request your favorite app add support, often times it only takes a developer 15 minutes or so to add it. Details in our github repo here:
https://github.com/agilebits/onepassword-app-extension
Let me know if you have any questions! I handle all of our app extension customer support and code maintenance.
Kyle
AgileBits
One piece of feedback is that when I was comparing your product to Dashlane, they had much better tools to migrate your existing passwords. Specifically Dashlane has a tool to migrate all your passwords in your Mac OS keychain automatically to their manager. I remember y'all having a solution as well but it was a lot more complex and wasn't something that my mom or dad could do without me watching them.
So my main feedback is to build solutions and UX that cater towards your grandma, not to the HN crowd. These are the users that you need to convert over because they have the biggest security risks.
As you can imagine it's quite difficult to take complex topics like this and make it easy to digest for people not familiar with it.
I hope we can continue to make small steps in the right direction in each release. If we wanted to make 1Password as simple to use as possible we could certainly do that by removing all the fancy features that most of our power users find useful, but that would anger them greatly.
We started as a power user tool, so our roots are there. We can't abandon that entirely. We just have to work harder to simplify in ways that aren't going to remove these useful tools.
As for the Mac OS Keychain import bits. There is actually no official way to do this that isn't an incredibly ugly hack. Apple doesn't provide a mechanism to get data out of the macOS keychain, and the one way they do, while it can be scripted requires asking for the user account's password for each item. I suspect if we looked at how other tools do this they are doing some incredibly wonky things that you might be afraid to understand :)
I understand that the point remains, they import, we don't... but it's a tight rope. We don't want to do things that potentially risk us losing goodwill with our users by doing weird things in the background to make it work seamlessly.
Kyle
AgileBits
The 1Password mini used to be a separate process and it was using XPC to communicate with the main app.
I've recently set up 1Password for my parents and it works fine. The applications are still a little too complicated for them though, the gap between a physical notebook containing passwords and 1Password is large. Thankfully the UX on iPhone/iPad with TouchID is simple enough.
https://blog.agilebits.com/2018/03/20/introducing-1password-...
Kyle
AgileBits
We want our Windows users to be happy as well, and if you have features that are vital to you please write into our support. They use these requests to help gauge what to work on next, and the list is long so the more we hear from users about what they value the better we can prioritize that list.
As a Mac and iOS developer on the team I am very impressed by how quickly our Windows team has caught up.
Thanks,
Kyle
AgileBits
Example:
1)search for entries using two or more strings
2)search for entries without two or more certain text. Example, find all entries unrelated to entertainment in "All Items", search for -tag:book -tag:movie -tag:streaming -tag:tv
And saving a search so that I don't have to retype the search language when I QA my 1PW data!
However, it looks like it pings Troy's service to do its magic so not everything is kept locally. (I don't blame them, for speed, and for not needing a many-gig database download for each client.
Still, a cool feature, but something to be aware of.
https://blog.agilebits.com/2018/02/22/finding-pwned-password...
1Password X is a Chrome extension, but it's also a full-featured 1Password client! Additionally, 1Password X does work without an internet connection. In version 1.5 we added an offline cache so you can boot up your laptop, unlock 1Password X and get that WiFi password or whatever item you need. If you haven't checked it out lately, I'd highly recommend taking a peek at this recent blog post: https://blog.agilebits.com/2018/03/13/1password-x-better-sma...
&drew
I'm sure 1Password takes security very seriously, but it seems like a big potential attack vector so I prefer a bit less obvious way to store my passwords.
--
Jamie Phelps
Code Wrangler @ AgileBits