← Back to context

Comment by dwb

2 days ago

Well, they’re not minimum-viable if they don’t work, which they won’t for most users. It’s not a simple matter of the database being unlocked or locked, as I say it’s at least a per-process authentication, protected by the 1Password daemon. I’m not saying it’s a perfect system, but exaggerated mischaracterisation, with no apparent thought to the experience of the average user, doesn’t help your argument. You don’t seem to put much value in memory protection or process sandboxing. Yes with enough exploits you can do anything, but that’s true in any case. The fact is, 1Password is good enough for most people, and even at least one bank that I’m aware of. I’m willing to be convinced of a better implementation, but the fact you’re so scathing of something that works and has UX benefits over per-secret keying is off-putting. All design is trade-offs.