Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I prefer supporting open source for personal use.

Same here. Opensource also adds to security in this case.

Also BitWarden's server has no knowledge of your phrase, and hence cannot, never ever, read your data. Forgetting your phrase means you lose your wallet. 1Pass and competitors do not have such guarantee, and allow one to retrieve access to the wallet by other means.



1Password's servers also cannot read your data. They use a client generated secret key in addition to your usual password to encrypt your vaults. It's been detailed pretty well

https://support.1password.com/secret-key-security/


Are all clients open source? If I loose all my keys is there no way to recover the data?

And how does this work when I share passwords with my colleagues in a vault? They dont have my "client generated secret key", so how can they read my passwords?

I know companies write stuff to sell their products, but I dont trust that, I prefer open source and the laws of logic over marketing.


1Password has a pretty good white paper explaining their security design (PDF behind the link): https://1passwordstatic.com/files/security/1password-white-p.... The parts "How Vault Items Are Secured" and "How Vaults Are Securely Shared" go into sharing passwords in a vault.

For the record, Bitwarden's white paper is a good read as well. Available at https://bitwarden.com/help/article/bitwarden-security-white-....

(edit: fixed typos)


So I'm reading on pg 22. The red block. How hard is it for 1Pass --basically a mandated MITM-- to send a false request to Alice when Bob made a request?

That whitepaper is a piece of marketing text. Not saying their audit did not take place. But they are soooooo powerful in their own system that they basically have access to everything.

BitWarden: not so much.


> How hard is it for 1Pass --basically a mandated MITM-- to send a false request to Alice when Bob made a request?

Alice is the one that initiates the request. She owns the vault being shared and encrypts it with Bob's pre-shared public key.


If you loose bitwarden keys what will they do to recover data? They have similar security protocols so I doubt being open source would help that. It's not about being open source or not. That's just security

1Password says explicitly that you're not sharing the actual item in your vault and that it's creating a copy of it. It's probably generated client side and pushed to an external sharing service

I mean, I understand trusting open source but your statements seem like non-sequiturs. 1Password has been audited and has been an industry standard for a while. They seem to know security so at some level I don't find it difficult to trust them. Of course, I don't deny trusting open source and that's completely valid but not with these specific points


>If you loose bitwarden keys what will they do to recover data?

They cannot. That's closely related to why it is so secure, and why they can never see you data. That's why I use it.

It's sometimes called "zero knowledge".

> 1Password has been audited and has been an industry standard for a while.

MSFT products were also audited, and much used, and very insecure. Also 1Pass may be subpoena'd into sharing your data. I do not trust 1Pass, but you do you and feel free to do trust them :)


How does that work for their web based browser extension?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: