Live data from Hacker News

1Password and the Crypto Wars

blog.agilebits.com

11–20 of 111 posts

Re: 1Password and the Crypto Wars

#11
post #4

Nicely done. I appreciate the stand they are taking here. That said, gag orders are gag orders. You can decide not to play as Lavabits did but you cannot reasonably tell some non-US employee to blab about your NSL since you will go to jail anyway and Federal Prison is Federal Prison.

What if you put release procedures in place that make it so your foreign offices will detect if a compromised release goes out?

For instance, require code review from the foreign offices to approve building a new release, and require that the foreign offices build copies of the new release from the code they reviewed and that they verify that their builds match the release candidate binary before the release can go live on the server?

Re: 1Password and the Crypto Wars

#12

Notable missing phrase: "open source"

That's not a notably missing phrase, because it's not open source. Maybe it's notable because you don't trust closed source security products, but if so, you didn't say that. :) Not that I disagree with you. I use 1Password, but in my opinion the fact that it is closed source is definitely a mark against it. If there was anything built on top of, say, GPG that had remotely similar functionality, I would totally use that. Maybe there is and I don't know about it.

Re: 1Password and the Crypto Wars

#14
post #11
post #4

Nicely done. I appreciate the stand they are taking here. That said, gag orders are gag orders. You can decide not to play as Lavabits did but you cannot reasonably tell some non-US employee to blab about your NSL since you will go to jail anyway and Federal Prison is Federal Prison.

What if you put release procedures in place that make it so your foreign offices will detect if a compromised release goes out? For instance, require code review from the foreign offices to approve building a new release, and require that the foreign offices build copies of the new release from the code they reviewed and that they verify that their builds match the release candidate binary before the release can go l…

An interesting thing for an open source project might be to put code-signing keys (for a reviewer) out with pseudonymous people on the Internet -- real identities unknown to the developers.

I'd be happy to only use releases of 1Password which were signed by both AgileBits and a few nyms with a long history of being awesome (e.g. Satoshi).

Re: 1Password and the Crypto Wars

#15
post #12

Notable missing phrase: "open source"

That's not a notably missing phrase, because it's not open source. Maybe it's notable because you don't trust closed source security products, but if so, you didn't say that. :) Not that I disagree with you. I use 1Password, but in my opinion the fact that it is closed source is definitely a mark against it. If there was anything built on top of, say, GPG that had remotely similar functionality, I would totally use t…

"Maybe it's notable because you don't trust closed source security products, but if so, you didn't say that."

Yes, that was my point :)

That said, at least they document the format.

Re: 1Password and the Crypto Wars

#16
post #11
post #4

Nicely done. I appreciate the stand they are taking here. That said, gag orders are gag orders. You can decide not to play as Lavabits did but you cannot reasonably tell some non-US employee to blab about your NSL since you will go to jail anyway and Federal Prison is Federal Prison.

What if you put release procedures in place that make it so your foreign offices will detect if a compromised release goes out? For instance, require code review from the foreign offices to approve building a new release, and require that the foreign offices build copies of the new release from the code they reviewed and that they verify that their builds match the release candidate binary before the release can go l…

Better yet, enact a policy that before a release goes online, all foreign offices have to audit every change, compile and verify the binary matches, then sign the binary. If a release goes online that isn't signed by all locations, it's obvious something's wrong.

Re: 1Password and the Crypto Wars

#17
post #12

Notable missing phrase: "open source"

That's not a notably missing phrase, because it's not open source. Maybe it's notable because you don't trust closed source security products, but if so, you didn't say that. :) Not that I disagree with you. I use 1Password, but in my opinion the fact that it is closed source is definitely a mark against it. If there was anything built on top of, say, GPG that had remotely similar functionality, I would totally use t…

You might be interested in STRIP[1] which is built on SQLite and SQLCipher, the latter being an open-source encryption codec for the former. It's up to the user to decide whether and how to use Dropbox, Google Drive, etc., for syncing.

Disclosure: My employer makes STRIP.

[1] http://getstrip.com/

Re: 1Password and the Crypto Wars

#18
Back in April, there was an attack on 1Password that managed to exploit some flaws in its crypto scheme to achieve a sizable speedup. [1] To this day, they have not managed to rollout the new 1Password 4 Cloud Keychain that is supposed to fix these flaws. [2]

Lots of smooth talk, but apparently security is not a blocker.

1: http://hashcat.net/forum/thread-2238.html

2: http://discussions.agilebits.com/discussion/14780/which-prod...

Re: 1Password and the Crypto Wars

#19
post #12

Notable missing phrase: "open source"

That's not a notably missing phrase, because it's not open source. Maybe it's notable because you don't trust closed source security products, but if so, you didn't say that. :) Not that I disagree with you. I use 1Password, but in my opinion the fact that it is closed source is definitely a mark against it. If there was anything built on top of, say, GPG that had remotely similar functionality, I would totally use t…

Does KeePass and derivatives count as remotely similar? They work well for me

Re: 1Password and the Crypto Wars

#20
post #6

Earlier quoted context omitted.

> But the very real possibility that we would shut ourselves down (which would be public) rather than sabotage what we do and love should act as some deterrent to those who might wish to compel us to introduce a backdoor. They've pretty much just said that they would shut down abruptly should an order ever come to them that they couldn't announce. Lavabit sets an interesting precedent really, I expect abrupt shutdown…

>Lavabit sets an interesting precedent really "The office of La Batalla , the P.O.U.M. paper, which was not defended, had been raided and seized by the Civil Guards at about the same time as the Telephone Exchange, but the paper was being printed, and a few copies distributed, from another address... The Civil Guards were still occupying strategic points. Huge seizures of arms were being made from C.N.T. strongholds,…

There was a new rule that censored portions of a newspaper must not be left blank but filled up with other matter; as a result it was often impossible to tell when something had been cut out.

http://www.theonion.com/articles/let-me-explain-why-miley-cy...

Post reply on HN