To protect your privacy: email us with billing or account questions instead of posting here.

Can anyone clarify

Options

I was doing some research on 1Password and I came across this from quora with source linked below:

"SINCE A team of hackers has managed to crack more than 14,800 supposedly random passwords - from a list of 16,449 - as part of a hacking experiment for a technology website.

The success rate for each hacker ranged from 62% to 90%, and the hacker who cracked 90% of hashed passwords did so in less than an hour using a computer cluster.

The hackers also managed to crack 16-character passwords including 'qeadzcwrsfxv1331'.

Rather than repeatedly entering passwords into a website, the hackers used a list of hashed passwords they managed to get online.

Hashing takes each user's plain text password and runs it through a one-way mathematical function.

AWAY FROM 1PASSWORD - ist not safe - no password manager is safe.

SINCE THE ABOVE HAPPENED. I Don’t use any password Manager again..

My best was CLEF & DASHLANE combined. But now, I create my own SUPER PASSWORDS AND MANAGER."

Source: https://www.quora.com/How-secure-is-1Password

I was wondering if anyone can clarify if this is true or not. Because that makes me nervous using 1password if anyone can hack into it quickly.


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Sync Type: Not Provided

Comments

  • Chris Upjohn
    Chris Upjohn
    Community Member
    Options

    Hi @nosferatuwho,

    Like Kayd Young mentioned in his answer, 1Password is extremely safe and secure. My own background before switching to 1Password was using text files which was the worst idea in the world looking back.

    Since switching, I've entered over 1000 items across multiple vaults and to date haven't had the worry draw on my mind that my master directory of passwords could be compromised simply due to the lengths AgileBits go to protect our data.

    The decision ultimately is yours, but I personally have 100% trust in 1Password and the teams that work on the apps.

  • AGKyle
    AGKyle
    1Password Alumni
    edited September 2017
    Options

    Hi @nosferatuwho

    That linked article you mention is... questionable... extremely... questionable.

    1. How to create a hack proof password.

    Just use 1Password's password generator, it does effectively the same thing with fewer options.

    1. Save it in a secure folder?

    It goes into zero detail about how to setup this secure folder so there's no clue what that means. How that folder is protected, if at all, is going to matter a lot. 1Password will be a far more secure option than what most people setup in this regard and a lot more convenient.

    1. How Secure Is My Password? Not very

    https://howsecureismypassword.net/

    enter password1234 and it says 4 years... why does this provide such inaccurate results? Read here but the short story is that in order to actually determine password strength you really need to know how it was generated. Without knowing how it's generated the password strength checkers in all applications will fail to give you a proper strength.

    1Password can only accurately provide strength information for character passwords generated within 1Password itself. Everything else is going to be off and potentially quite inaccurate. The same issue will arise when using this site. I don't generally recommend it because it can make people feel they have strong passwords when the reality is that they do not.

    I can continue to break this entire article down if you wish, but with some minor research into this site, which I won't be mentioning because the answer won't shock you. It's a link generating site. Look at the twitter for that site :)

    Also, if you google the site's name, without the .com, you'll see this snippet:

    With A Backup Plan. Discover Routes To Generate Alternate Income Streams. Become A <sitename> Elite. Subscribe to Receive All ELITE BASE Updates ...

    Basically, do not trust a single thing that site has to say, they just try to direct views to the page to generate income.

  • pervel
    pervel
    Community Member
    Options

    My best was CLEF & DASHLANE combined. But now, I create my own SUPER PASSWORDS AND MANAGER.

    Yea he is totally disinterested and just trying to help people, right? :)

    (Sarcasm may occur.)

  • (Sarcasm may occur.)

    ;)

    Ben

This discussion has been closed.