Hacker News new | ask | show | jobs
by artdigital 967 days ago
You’re not really “trusting a company with the keys to your digital life”.

The vault is encrypted with a password that never gets transmitted, and even if your password and vault gets stolen, without the additional “secret key” that also never leaves your device (and you should probably print and store somewhere safe), an attacker won’t be able to do much with it.

The inclusion of an additional secret key makes a huge difference in this setup. but yes, it would be much nicer if I could use my own sync store like in the past… (looking at EnPass currently which also has a secret key setup and own sync store)

2 comments

You realize that trust is not just about privacy the day your vault disappears from all your devices with no option whatsoever for recovery[1].

[1] https://1password.community/discussion/120403/delete-family-...

But you have to trust them that the secret key never gets transmitted, unless you compiled it yourself.
Also, malicious code can be pushed to the website if you are logging in through that. You have to trust that their infrastructure is safe.