Hacker News new | ask | show | jobs
by voska 2541 days ago
It also changes the risk profile. AgileBits is a big target, my local machines are not.
1 comments

Ben from 1Password here. We've designed the model so that we aren't a big target. The Secret Key helps with that. https://support.1password.com/secret-key-security/
That's a strange statement, you're a big target because you're holding lots of peoples secret data. Doesn't matter how you model it, unless your model is to have minimal data/clients.
Minimal data of value, yes. Did you read about the Secret Key?
Ben, everyone here understands the model. It isn't sophisticated and it isn't particularly special. You have a lot of [encrypted] sensitive data. On your network. On servers you own. You are a target. Once the bad guys get the data, they'll worry about the individual keys and whom they want to target.

I'm one of the many people who are both dropping 1P and advising friends and family to do the same as a result of this episode.

Yes I read about the secret key, before I became a customer of 1Password. Your response concerns me. I understand you're encrypting the data, and have put in great effort to do so. This doesn't prevent your servers being a target for all sorts of other exploits, hacking of your webservers injecting back doors etc. The fact you halve a lot of clients with secret data makes you a target.