Hacker News new | ask | show | jobs
by hn_throwaway_99 963 days ago
This is am unwarranted comparison. First, one only need to look at the respective issue reports to see that 1P is much more operationally mature than LP.

More importantly, 1Password's architecture is fundamentally more secure than LastPass' given how password vaults are encrypted with essentially master password + uncrackable random string, vs LastPass' sole use of the master password when generating the encryption key. Not saying there aren't other avenues for attack (e.g. supply chain attacks in the 1P apps), but if 1P reported that there was a big theft of encrypted vaults, I wouldn't even bother changing my passwords, as opposed to what happened with LastPass.

2 comments

> 1P is much more operationally mature than LP.

Oh, is that why they removed Wi-Fi sync in 1Password 8?

As a customer since version 4 I'm disappointed they use cloud crap like Okta and Notion. While those have their uses, if there's any company that shouldn't be doing so, 1Password is it.

Because they removed local vaults (OPVault) entirely in 1P v8 and Wi-Fi sync relies on OPVault, yes.
I took it entirely as an opportune dig at Lastpass, not an actual expectation that 1Password will actual fall that low.

That said, I am happy that 1Password's salespeople will (hopefully) finally stop saying "we haven't been hacked like that other company."