Earlier quoted context omitted.
I'd be ok with paying an annual fee for the app. What I have zero interest in is increasing my attack surface solely for their bottom line. I'm also increasingly uncomfortable with the company handling my passwords engaging in the sort of spin and dark patters we've seen from AgileBits in the past few years.
I'm curious about how you see the attack surface increasing when using 1Password. My knowledge of how it works is that it always stores your passwords in an encrypted blob that can only be decrypted with a combination of username, "master password", and vault password. So no matter if it's in Dropbox, 1Password's servers, or your own hard drive, if anyone obtains a copy of the password file they still have to crack i…
When I keep it on an airgapped machine that's a lot harder than when it sits on 1password's internet facing servers.