Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Wed, 9 Jan 2013 10:23:20 -0600
From: Jeffrey Goldberg <>
Subject: Re: Re: 1Password 4 Cloud Keychain format for your cracking pleasure

On 2013-01-09, at 12:37 AM, Dhiru Kholia <> wrote:

> This really shows the confidence you guys have in your security design!

Or the hope that if someone spots something we missed, they will let us
know before there's an exploit in the wild. But ultimately it is the
belief that if we couldn't make the design details public "for security
purposes", then there definitely would be something wrong with the design. 

> I really like the resilience of 1Password against data corruption
> which is missing in other passwords managers.

Authenticated encryption and data authentication are, to my mind, the
biggest improvements in this design.

> Thanks for the heads up. A sample profile.js file (with known Master
> Password) would be really useful.

I've attached a tarball of a complete sample 1Password 4 Cloud
Keychain. Master Password is "fred".

> Also, are there any plans to update
> utility?

We didn't write that and have no connection to its author. I don't
foresee us putting time and effort into producing an open data
parser, but considering that our design document for the Cloud format
is much more complete than for the Agile Keychain Format,I expect
that someone will.



Jeffrey Goldberg
Chief Defender Against the Dark Arts @ AgileBits 

Download attachment "fred-data.tar.gz" of type "application/x-gzip" (22165 bytes)

Download attachment "smime.p7s" of type "application/pkcs7-signature" (4393 bytes)

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.