Hacker News new | ask | show | jobs
by dmak 1254 days ago
To each it's own, but 1Password security design looks pretty solid. Here is their white paper: https://1passwordstatic.com/files/security/1password-white-p...
2 comments

No system is perfect. You're making a trade off by self-hosting but at least when something goes wrong you know who to blame and what to improve. When something goes wrong in someone else's environment you're lucky to even know what went wrong, and you have no one to hold accountable.

So it's not IF something goes wrong, it's WHEN something goes wrong. Going around thinking IF something goes wrong is delusional, even if you end up being lucky and right.

You're right. I'm sure their security design is 100% bulletproof and none of my sensitive data will ever be leaked. And even if it were somehow possible for it to be leaked, I'm also sure the company would be completely forthcoming as quickly as possible.
A system which literally never sends my password information to any computers controlled by 1Password seems better than the LastPass nonsense, and more to the point, seems at least as secure as anything I would create. While LastPass was breached many times over the last few years, 1Password has never been breached.

Your sarcasm isn't helpful, and serves only to falsely conflate the insecure design and horrible history of LastPass with the best-in-class 1Password. Nothing is ever 100%, but 1Password is closer than anything else I know about, including most one-off systems used by people who don't use password managers.

It'll be better than rolling your own password manager and self-hosting it for your team.