Live data from Hacker News

1Password and the Crypto Wars

blog.agilebits.com

61–70 of 111 posts

Re: 1Password and the Crypto Wars

#61
post #60
post #55

“I would strongly recommend against anyone trusting their private data to a company with physical ties to the United States.” (Assuming being a Canadian company counts..)

Is that a quote from the article, or do you just use quotes for emphasis of your own words?

It's from the Lavabit mail.

Re: 1Password and the Crypto Wars

#62
I think if your are building closed crypto products you need to be (1) not a US company (2) have multiple technical people in various different countries not likely to be politically compatible. Even better have no connections to the US at all other than selling products there. Then at least you have a chance to avoid the pressure to compromise.

Re: 1Password and the Crypto Wars

#63

Earlier quoted context omitted.

>Lavabit sets an interesting precedent really "The office of La Batalla , the P.O.U.M. paper, which was not defended, had been raided and seized by the Civil Guards at about the same time as the Telephone Exchange, but the paper was being printed, and a few copies distributed, from another address... The Civil Guards were still occupying strategic points. Huge seizures of arms were being made from C.N.T. strongholds,…

There was a new rule that censored portions of a newspaper must not be left blank but filled up with other matter; as a result it was often impossible to tell when something had been cut out. http://www.theonion.com/articles/let-me-explain-why-miley-cy...

It would have been funnier if the article had claimed that the reason Miley Cyrus occupied the top spot was because the NSA had censored their top story about spying.

Re: 1Password and the Crypto Wars

#64
post #2

req: lastpass's response

Could you link to it please?

LastPass has not made a direct statement. On their forums, however, a customer asked where data was hosted and this post was made by the CEO:

LastPass is "host proof" hosted meaning that your sensitive data is encrypted with a key we at LastPass NEVER have, removing many of the concerns PRISM raises with most cloud service providers. LastPass can't be forced to give the encryption key to your data as it has never hit our servers!

https://forums.lastpass.com/viewtopic.php?f=12&t=89195

Re: 1Password and the Crypto Wars

#66
post #43

Earlier quoted context omitted.

Any good cross multi-device alternatives?

Preferably with my own server (owncloud?) as a central keychain?

Yeah that'd be great. I have a dirty solution of syncing my latest keychain backup with owncloud but that's merely for backup

Re: 1Password and the Crypto Wars

#67

Back in April, there was an attack on 1Password that managed to exploit some flaws in its crypto scheme to achieve a sizable speedup. [1] To this day, they have not managed to rollout the new 1Password 4 Cloud Keychain that is supposed to fix these flaws. [2] Lots of smooth talk, but apparently security is not a blocker. 1: http://hashcat.net/forum/thread-2238.html 2: http://discussions.agilebits.com/discussion/14780…

Any good cross multi-device alternatives?

Personally, I am a Last Pass user. It is well included in most browsers out there and you have access to it on your mobile if you subscribe to the premium offer (12 dollars per year).

Re: 1Password and the Crypto Wars

#68
post #58
post #21

In for a penny, in for a pound. If you care about security enough to use a password safe you might as well also use an open source solution that has even a remote chance of having its code looked at by more people than the ones trying to sell it to you. I mean, I know 1Password is all pretty and animated and things, but things like KeePass aren't so ugly as to be unusable.

I used both KeePass and 1Password is not just about the pretty interface as you make it to be. Entire UX is much better. Also, even if some 3rd party looked at the code, it doesn't really matter because they are really transparent about the file storage format, there are even some open source cli tools to extract data. Also it is a fact that no data leaves your control. No server side storage or something like that.…

With LastPass, all data are encrypted locally on your machine so except if there is a backdoor in their extensions/desktop applications, you are normally pretty safe.

Re: 1Password and the Crypto Wars

#69

Back in April, there was an attack on 1Password that managed to exploit some flaws in its crypto scheme to achieve a sizable speedup. [1] To this day, they have not managed to rollout the new 1Password 4 Cloud Keychain that is supposed to fix these flaws. [2] Lots of smooth talk, but apparently security is not a blocker. 1: http://hashcat.net/forum/thread-2238.html 2: http://discussions.agilebits.com/discussion/14780…

Isn't this the attack that reduced the strength of their PBKDF2 scheme by one (1) bit? Because they were unnecessarily calling PBKDF2 twice, where a normal system would have called it once and expanded the resulting key, resulting in exactly the same speed characteristics?

Your snark would sting more if you knew what you were talking about.

The reason nobody's hair lit on fire over this is that it's a stupid issue.

Re: 1Password and the Crypto Wars

#70

Earlier quoted context omitted.

Any good cross multi-device alternatives?

Personally, I am a Last Pass user. It is well included in most browsers out there and you have access to it on your mobile if you subscribe to the premium offer (12 dollars per year).

AFAIK LastPass is an online password manager, i.e., you do not only trust a software vendor like AgileBits for 1Password, but you trust your actual passwords to an online provider. Is that wise given that LastPass could get hacked or asked by authorities to provide your passwords – if there's not already an existing legal access channel?
Post reply on HN