Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There aren't security issues with 1Password really, but there are other issues, mostly around the company AgileBits. From my other comment on this thread:

These days AgileBits(the 1password people) are doing everything they can to get everyone onto a subscription plan, and are breaking local vaults slowly. Most people don't seem to recommend it anymore.

The only security issue really is the online vault(which isn't a security issue per-say, but is a security weakness since your passwords are no longer under your direct control). This may or may not be an issue for you, depending on your security posture.



Thanks! So would you know what he meant with that tweet? Was he just annoyed at the subscription plan...? It seems out of place given that he's a security researcher from what I gather?


No, and that tweet was from Aug. 2016 with nothing further from him about 1password, unless I missed it, so clearly he didn't feel compelled to either continue his research or he didn't find anything worth disclosing. Your guess as to which is meant.

But other researchers have played with 1password and most have historically had good things to say about it, except recently when they started pushing everyone to the online vaults like I mentioned.

And yes, he is a security researcher for Google.


Anecdotally, I haven’t had any problems with my local vaults (yet), though I rarely use 1Password on Windows.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: