Hacker News new | ask | show | jobs
by tlunter 3445 days ago
But how does the user log into dropbox when they go to the website? They probably store those generated credentials within the 1password vault.
1 comments

which is encrypted.
If 1password has been injected with malicious code, whoever has done so will have all your encrypted credentials the next time you unlock your vault, including presumably your full Dropbox creds.

(Caveat: I use Keepass2Android, which ironically DOES support limiting access to the Apps folder in Dropbox.)

Keepass follows best practices more than 1Password.

http://mostvulnerable.com/