Live data from Hacker News

You have secrets; we don’t. Why our data format is public

blog.agilebits.com

41–42 of 42 posts

Re: You have secrets; we don’t. Why our data format is public

#41

What's the difference between: 1) entering your 1Password master password in untrusted software and 2) running untrusted software which could potentially keylog your 1Password master password? Agilebits likes to talk about how 1Password protects against keylogging ( http://help.agilebits.com/1Password3/security.html and note the author here http://mackeyloggerprotection.com/ ) but what's stopping attackers/malware fr…

I'd really like to direct people to our discussion forums where questions like this our discussed. It's kind of hard to provide user support spread out over a range of sites.

There are some counter measures in 1Password to try to thwart keyloggers. The details vary from OS. As far as we know, our defenses work against existing keyloggers, but we also know that this is an arms race that we can only lose.

If your machine is compromised, then you can no longer trust anything on it. So while we believe that our current counter measures work against current threats, we can't state with much confidence that they will continue to do so. We've been fortunate in that keyloggers tend to be simple and go for the low hanging fruit.

Cheers,

-j

Re: You have secrets; we don’t. Why our data format is public

#42
post #31

Earlier quoted context omitted.

My biggest worry is that apparently 1Password can be cracked in only 5 seconds: http://www.informationweek.com/security/encryption/security-... "Belenko said that he himself had been using 1Password Pro, which may be the most-installed password manager for Apple iOS. But he ceased using it after testing the application's cryptography. "When we recovered my master password in five seconds? That was a moment," he said.…

That is simply not true. I recommend that people actually read Elcomsoft's outstanding report on the security of password managers on mobile devices. At Blackhat, Andre demonstrated a Chosen Ciphertext Attack (CCA) against PKCS CBC padding scheme. And 1Password (along with pretty much everyone else who used common recommended libraries) did use that padding. But there is a whole lot more that would need to be put in…

I see a lot of your blog posts but not a single place where I can read what exactly you implement in the application I can buy now. I see you write about your "next generation format" that's going to be good etc. And that you write about Dropbox. I don't want to use Dropbox, I'm interested just to see that you really know what you're doing locally for the start.
Post reply on HN