Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

1P is zero knowledge. What does Nordpass really have over 1P?


Nordpass lets you self-host your password database.

1Password stop doing that and makes you use only their own cloud infrastructure.


I trust 1P cloud storage more with their well thought out security concept than Dropbox or self-hosted nextcloud. The 1P security whitepaper goes into great detail why their cloud concept is not at all comparable to just hosting the vault on block storage.


There are companies who are pulling in the rein with regard to its placement of sensitive data, encrypted at rest or not. That is, going cloud-less (or more accurately, privately-owned public cloud, and more often, private cloud)

The prevailing concern isn't insecurity of using public cloud by using zero knowledge, but the containment/confinement of potential damage when an end user lose control of their password manager app (hacked, laptop-stolen or accidentally leaked) by having this delete feature at the self-hosted server. This is something that Netwirx PasswordSafe really excels at.

SOC 2, HIPAA, ISO 27001 and various military guidelines are a few reasons why.


And yes, apps should also password-protect and event-log the URL configuration field separately from the password used in database(s) as well ... from any change, accidentally or maliciously.

That is following inline with still-so Common Criteria guideline.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: