Master passwords are now inherently online? And q's about an upgraded install
My understanding of the way 1P worked, up through version 6, was pretty simple: passwords were stored in the vault, encrypted with the master password. It was therefore safe to store the vault on line, as the encrypted data was useless to anyone else.
It's not clear to me how things stand now. As of V7, there's a "Secret Key" which is meant to stay offline. I have my problems with this scheme - it's not clear to me how my security is improved by needing an unmemorizable secret that must be stored somewhere. But more immediately, it seems that now we're expected to expose our master password to your servers. It's required to log into your web site, which means you're either storing it, or some hash of it, but in any case you're getting the clear text in flight (well, in your server, not on the wire, because https), which means anyone capturing your web server will then capture at the least the master passwords of anyone who logs in (if not the entire user base). How is this good?
When I converted to 1P V7, It seems to have created a "master password" for logging into the web service, but my old master password was retained on the Mac I was upgrading. How does that work? Vault items are encrypted on my disk with my local (old) master password, but encrypted on your server with the new password? Or something else?
I just got a new Mac and installed 1P V8 while moving things over. This 1P insists on using the master password that matches the online password. Is there some way I can change my LOCAL 1P vaults to the older master password, while leaving the online password alone, so this Mac will behave like my other Mac?
Is there a clear document that describes your current security model?
Your "Emergency Kit" is, in fact, a "steal my life" kit if anyone ever gets their hands on it. I think that at the very least you should have the ability to use key splitting to generate multiple kit parts, so that different parts can be stored in different locations (or with different third parties), allowing for a generalized n of m scheme (say, I give out key parts to all six siblings and cousins, and can reconstitute the secret key from any four parts).
1Password Version: 8.8.0
Extension Version: Not Provided
OS Version: Not Provided
Browser:_ Not Provided
