Hacker News new | ask | show | jobs
by roustem 2954 days ago
Better security and better user experience to start with.

Unlike most of competing products, 1Password encrypts pretty much all information, including vault names, item titles, URLs, tags. It is easier to list what's not encrypted. It is also probably the only product using SRP.

Now check out what information is sent in plaintext or base64-encoded in other products.

1 comments

As far as I am aware lastpass and keeper are the only two password managers to receive soc II security reports.

Also I'm pretty confident the entire lastpass vault is encrypted locally as well.

1Password service has completed SOC 2 type 1 and 2 certification as well. It is more about internal company processes and how they are followed than encryption.

"Hey your data is safe just because we have SOC 2 certification" -- that's not want you want to hear.

About vault being encrypted locally: https://hackernoon.com/psa-lastpass-does-not-encrypt-everyth...