1Password and the Crypto Wars
blog.agilebits.com
1Password and the Crypto Wars
1–10 of 111 posts
Re: 1Password and the Crypto Wars
#2Re: 1Password and the Crypto Wars
#3req: lastpass's response
Re: 1Password and the Crypto Wars
#4That said, gag orders are gag orders. You can decide not to play as Lavabits did but you cannot reasonably tell some non-US employee to blab about your NSL since you will go to jail anyway and Federal Prison is Federal Prison.
Re: 1Password and the Crypto Wars
#5Re: 1Password and the Crypto Wars
#6Nicely done. I appreciate the stand they are taking here. That said, gag orders are gag orders. You can decide not to play as Lavabits did but you cannot reasonably tell some non-US employee to blab about your NSL since you will go to jail anyway and Federal Prison is Federal Prison.
They've pretty much just said that they would shut down abruptly should an order ever come to them that they couldn't announce. Lavabit sets an interesting precedent really, I expect abrupt shutdowns to happen often this year.
Re: 1Password and the Crypto Wars
#7http://learn.agilebits.com/1Password4/Security/keychain-desi...
Re: 1Password and the Crypto Wars
#8Nicely done. I appreciate the stand they are taking here. That said, gag orders are gag orders. You can decide not to play as Lavabits did but you cannot reasonably tell some non-US employee to blab about your NSL since you will go to jail anyway and Federal Prison is Federal Prison.
> But the very real possibility that we would shut ourselves down (which would be public) rather than sabotage what we do and love should act as some deterrent to those who might wish to compel us to introduce a backdoor. They've pretty much just said that they would shut down abruptly should an order ever come to them that they couldn't announce. Lavabit sets an interesting precedent really, I expect abrupt shutdown…
"The office of La Batalla, the P.O.U.M. paper, which was not defended, had been raided and seized by the Civil Guards at about the same time as the Telephone Exchange, but the paper was being printed, and a few copies distributed, from another address...
The Civil Guards were still occupying strategic points. Huge seizures of arms were being made from C.N.T. strongholds, though I have no doubt a good many escaped seizure. La Batalla was still appearing, but it was censored until the front page was almost completely blank. The P.S.U.C. papers were uncensored and were publishing inflammatory articles demanding the suppression of the P.O.U.M. The P.O.U.M. was declared to be a disguised Fascist organization, and a cartoon representing the P.O.U.M. as a figure slipping off a mask marked with the hammer and sickle and revealing a hideous, maniacal face marked with the swastika, was being circulated all over the town by P.S.U.C. agents...
At various points in the town there were posts manned by Civil Guards of Carabineros who stopped passers-by and demanded their papers. Everyone warned me not to show my P.O.U.M. militiaman's card but merely to show my passport and my hospital ticket. Even to be known to have served in the P.O.U.M. militia was vaguely dangerous. P.O.U.M. militiamen who were wounded or on leave were penalized in petty ways--it was made difficult for them to draw their pay, for instance. La Batalla was still appearing, but it was censored almost out of existence, and Solidaridad and the other Anarchist papers were also heavily censored. There was a new rule that censored portions of a newspaper must not be left blank but filled up with other matter; as a result it was often impossible to tell when something had been cut out." - George Orwell, Homage to Catalonia (1938)
I wouldn't expect that particular warning sign to persist for long.
Re: 1Password and the Crypto Wars
#9Nicely done. I appreciate the stand they are taking here. That said, gag orders are gag orders. You can decide not to play as Lavabits did but you cannot reasonably tell some non-US employee to blab about your NSL since you will go to jail anyway and Federal Prison is Federal Prison.
Re: 1Password and the Crypto Wars
#10It's pretty clear that the highest risk is pure-cloud services. There, it's trivial to get a legal order or technical compromise to steal the data. A "hostproof", download-on-each-use app, like LastPass, is essentially the same risk as a cloud app. (this is the hushmail and lavabit vulnerability.)
The safest is some kind of purely-client software, with local data, which operates online, and is never updated. Ideally open source, with a trustworthy build process.
In between is software like 1Password. I wouldn't consider 1Password + Dropbox sync to be safe -- NSA has open-door access to Dropbox if they wish to get a single user's data (and possibly more). Tricking a user into download a compromised version of 1Password wouldn't be terribly difficult even without the cooperation of AgileBits.
You can use 1Password more safely (local-only, infrequently updating, some kind of local-firewalling in the client, etc.). Without the client being open source, it's really difficult to do more. It's probably a hell of a lot safer on OSX than it is on iOS, since at least some OSX users are likely to do real network monitoring, or otherwise be on some kind of debugging enabled system, or something with just weird bugs, uncover a problem, and then dig into it and find a backdoor -- on mobile, there's little risk of that.