The 1Password Community forums are in read-only mode from Jan 28th - Feb 4th, 2025. Find out more.

How do I make sure that 1P5 for OS X and 1P for iOS are using the OPVault format?

odysseus
odysseus
Community Member

Title says all. There's a security issue detailed here:

http://www.telegraph.co.uk/technology/internet-security/11939920/Password-manager-1Password-criticised-for-leaking-users-bookmarks.html


1Password Version: 5.4
Extension Version: 4.4.3
OS Version: 10.11
Sync Type: Dropbox

Comments

  • [Deleted User]
    [Deleted User]
    Community Member

    Read all about the problem here https://blog.agilebits.com/2015/10/19/when-a-leak-isnt-a-leak/ but like odysseus I would like to know how to check that 1P5 for OS X and 1P for iOS are using the OPVault format before I start trying to convert a vault (that might already be OPVault)

  • [Deleted User]
    [Deleted User]
    Community Member

    Sorry to be a bother.... I misread when a "leak isn't a leak" Think I understand now:

    If your using iCloud to Sync, 1Password has always used the OPVault security design and continues to do so.
    If your using Dropbox and Folder Sync, 1Password will, by default, use the Agile Keychain format for greatest compatibility.
    If your your using Dropbox and Folder Sync want to convert now see https://support.1password.com/switch-to-opvault/

    Per the above link "Eventually, OPVault will become the default sync format everywhere, but during the transition you can still enable OPVault using this hidden preference" Cool.

  • Hey @odysseus,

    It sounds like you're in the same situation I was: I also sync with Dropbox. To switch to OPVault, simply follow the guide that the clever toasted added to his post right above this one. Specifically, the Convert existing vaults section. Once you do that, you'll need to reconnect any other devices to the new OPVault for syncing and you should be set. Let us know if you have any questions about the process.

  • SausalitoDog
    SausalitoDog
    Community Member

    Come ON, Agile.

    Do you really think we should have to use Terminal commands to change YOUR app to a more secure format???

    That's NOT what I signed up for...and not what I want to take chances with. How about a real world safe upgrade from the company we bought the app from?

    Tom O'Connell

  • Megan
    Megan
    1Password Alumni

    Hi everyone,

    I just wanted to chime in here. I think @toasted outlined it pretty well, but I want to reiterate that the .agilekeychain format is still secure. I use it to sync my own data via Dropbox. We wouldn't have this data format available for users at all if we thought that it was insecure.

    We're taking the steps necessary to make the migration simpler for all users, but for the interim, you will have to use those Terminal commands to tell 1Password that you'd like .opvault format to be used when syncing new vaults. We know this is not ideal and we do apologize for the inconvenience.

    Of course, we're happy to help if you hit any snags during the process.

This discussion has been closed.