Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In other threads about this I was reminded that 1Password also has a security key that is known only to the client, and thus would not be leaked in the event of a cloud breach. In order to unlock the vault, one needs both pieces of information: the secret key and the master password. The secret key is cached on the client, which is why I had forgotten about it, but it is required for unlocks nonetheless

Thus the advantage goes to 1Password here, since Bitwarden does not require that "second factor" known only to the client (and I'm not talking about 2FA for logins, I mean for the vault)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: