I don't think I can trust a password manager that isn't open source. Cloud or not.
I don't think I can trust a password manager that isn't open source. Cloud or not.
Can you trust the manufacturer of your personal devices?
Sooner or later you're trusting somebody, unless you literally smelted your own machine starting from ore and a bucket of sand, and then wrote every line of code for it, including the compiler, yourself.
Maybe you should inventory all the entities you're trusting already.
The only major vuln are the updates, and that would have to be a backdoor delivered to everyone, otherwise the mismatched hashes would be noticeable. The surface area is smaller with the client side encrypted version.
It was really difficult in the beginning to earn the trust but 1Password is now over 13 years old and there are over 15 million users.
We started 1Password Teams project in 2015 and since then we had several external audits: https://support.1password.com/security-assessments/
We are currently in the process of completing the SOC 2 compliance audit.
We also have the highest paid bug bounty program in BugCrowd: https://bugcrowd.com/agilebits