1Password Blue Ocean Strategy
securityboulevard.com
securityboulevard.com
I was pretty unhappy when 1Password switched to a subscription model, which is partially why I chose to leave.
1Password's mobile experience also isn't great, especially when compared to iOS's native keychain syncing abilities.
All in all, I'm fairly bearish on 1Password for the personal use case. If you're not in the Apple ecosystem, Google has similar capabilities. If you want to be agnostic, then there are free alternatives as well.
What about identity information or other documents you would not want to store unencrypted, but also need ready access to?
What about shared vault behavior in 1pw? Even if Apple offered this, it seems unlikely to be built for share outside their ecosystem.
If I'm the CTO/CIO of a company that spends millions on security, I want to use an app which places this much attention to detail over such seemingly minor aspects vs something a couple bucks cheaper.
Based on his description, I'm not seeing the "zero-knowledge" mechanism. As described, 1Password (or a hacker on their server) would still be able to associate site-to-IP.
The cryptographically generated one-time URLs he mentioned would only prevent a MITM from knowing which what's being requested. The icon server still needs to know which site's icon to send to the requester.
Additionally, it appears 1Password falls back to fetching a site's favicon if they don't have an icon. So it would seem it's only leaking this info to 1Password so that it can fetch higher quality icons.
Unless I've missed something, this sacrifices security for aesthetics.
The thread referenced: https://twitter.com/mitchchn/status/1484225379854426114
EDIT: Yeah, this is not the "zero-knowledge" service implied: https://support.1password.com/rich-icons-privacy/