I like them both - 1password has better UX but I prefer supporting open source for personal use.
I like them both - 1password has better UX but I prefer supporting open source for personal use.
Same here. Opensource also adds to security in this case.
Also BitWarden's server has no knowledge of your phrase, and hence cannot, never ever, read your data. Forgetting your phrase means you lose your wallet. 1Pass and competitors do not have such guarantee, and allow one to retrieve access to the wallet by other means.
And how does this work when I share passwords with my colleagues in a vault? They dont have my "client generated secret key", so how can they read my passwords?
I know companies write stuff to sell their products, but I dont trust that, I prefer open source and the laws of logic over marketing.
For the record, Bitwarden's white paper is a good read as well. Available at https://bitwarden.com/help/article/bitwarden-security-white-....
(edit: fixed typos)
That whitepaper is a piece of marketing text. Not saying their audit did not take place. But they are soooooo powerful in their own system that they basically have access to everything.
BitWarden: not so much.
Alice is the one that initiates the request. She owns the vault being shared and encrypts it with Bob's pre-shared public key.
1Password says explicitly that you're not sharing the actual item in your vault and that it's creating a copy of it. It's probably generated client side and pushed to an external sharing service
I mean, I understand trusting open source but your statements seem like non-sequiturs. 1Password has been audited and has been an industry standard for a while. They seem to know security so at some level I don't find it difficult to trust them. Of course, I don't deny trusting open source and that's completely valid but not with these specific points
They cannot. That's closely related to why it is so secure, and why they can never see you data. That's why I use it.
It's sometimes called "zero knowledge".
> 1Password has been audited and has been an industry standard for a while.
MSFT products were also audited, and much used, and very insecure. Also 1Pass may be subpoena'd into sharing your data. I do not trust 1Pass, but you do you and feel free to do trust them :)