This part is not true -- your data is encrypted with a randomly generated key that is kept locally. You could freely post the data they have all over the internet and it would be fine.
This part is not true -- your data is encrypted with a randomly generated key that is kept locally. You could freely post the data they have all over the internet and it would be fine.
Do we know this is true? I assume it is, but I haven't checked the source or verified that I can encrypt/decrypt my data with my key, or that there isn't a master key that 1password has that can access it.
Edit: also there seems to be a lot of this:
> We’re sorry. This section of this document is not yet ready. Any- thing you see in this section is at most an outline of things to come.
> Edit: also there seems to be a lot of this:
Some, yes. I'm not sure I'd say 'a lot', but yes, it is a work in progress. Our security team should be able to elaborate on any points that we have yet to detail, though, if you're interested.
I've always used the Dropbox approach + backups. If Dropbox has an outage the file is still synced locally. If Dropbox deletes the file via a sync operation I still have my backups. If I delete the files Dropbox has an undelete option.
All I want is control over the files.
I'm one of the many people who are both dropping 1P and advising friends and family to do the same as a result of this episode.
Local data should be backed up as always, don’t rely on a cloud service to sync.
Personally I use two hard drives on my machine with time machine and regularly rotate them to ensure I have a recent backup and a less recent, network disconnected backup in case something like this should happen.
Well you can set an application firewall to block all internet access of the 1Password app. So, it can't update automatically, and when you manually update it and it would contain malicious code, it still can't connect/upload anything to the internet. You can even use 1Password sync via iCloud, which is handled externally - not by 1Password, but by macOS.
Unfortunately, this can not be done on an iOS device (no app firewall), since Apple locks down everything and decided users may not control their own devices anymore :'(
You can only block hostnames/ip-addresses, and these often change with updates, so you'd have to constantly monitor and block new hosts after the app starts leaking again.