Register FAQ/Rules Forum Spy Search Today's Posts Mark Forums Read

Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate.

 
Go Back   Mac Forums > iPhone and iPod Touch Forums > iPhone News Discussion
TouchArcade.com - iPhone Game Reviews and News

Reply
 
Thread Tools Search this Thread  
Old Oct 9, 2007, 12:45 PM   #1
MacRumors
macrumors bot
 
Join Date: Apr 2001
1Password: Store Passwords on your iPhone



Switchersblog details a new feature in the latest beta of 1Password -- a Mac password manager application.

The new version adds a "Sync to iPhone" feature which exports all your stored passwords into an encrypted Safari Bookmarklet. The Bookmarklet is accessible from the iPhone's Safari bookmark list and protected by a password.





The beta version of the software is available on their beta forum.

Article Link
MacRumors is offline   Reply With Quote
Old Oct 9, 2007, 01:51 PM   #2
ozziegn
macrumors 6502
 
Join Date: Aug 2007
a web applet application that allows me to store all of my important passwords? sure, where do I sign up?

NOT!
__________________
13" 2.53 MacBook Pro

Apple branded for life
ozziegn is offline   Reply With Quote
Old Oct 9, 2007, 01:55 PM   #3
chr1s60
macrumors 65816
 
Join Date: Jul 2007
Location: California
Store all your passwords and gain access to the Fido network... where do I sign up?
__________________
15" MacBook Pro 3.06GHz, iPod 4G 20GB, iPod Classic 120GB, iPod Shuffle 4G, White iPhone 3G S⃣ 16GB,tv 160GB
chr1s60 is offline   Reply With Quote
Old Oct 9, 2007, 02:21 PM   #4
traderx1
macrumors member
 
Join Date: Mar 2007
Quote:
Originally Posted by ozziegn View Post
a web applet application that allows me to store all of my important passwords? sure, where do I sign up?

NOT!
i can understand your fear, a web applet that stores your personal passwords. In reality, the information is NEVER stored on another server/computer (if the makers of this dandy program read, please correct me). You actually have the program called 1password on YOUR computer, put in your website passwords, and there is a sync to iPhone button. Click on that, and the info gets sent to your iphone on the next sync. You are also asked to pick/type a password to retrieve this info. After syncing, go to your iphone, then safari, then bookmarks, and touch 1password. It then asks for your password, that you chose earlier, and all your info shows up on the iphone. So the key here is that the information was NEVER transmitted to over the net. To test this theory, and make sure that I was not sending some information that I did not want to, I put my phone in airplane mode and I was still able to retrieve my info using safari. I mainly use this to store my password, and look up the info so i can type it in another computer that i use at work. If you are connected to the net on your iphone, you can just click on the link to website, and safari will send you there and fill in the password info for you. It is a pretty good program and now with the iphone sync it got a whole lot better. Being an earlier adapter of the iphone, my gripe has always been no to-do list, and no way to encrypt financial/personal things. Well 1password has made a work around that lets us store secure data. No it is not the best program for the purpose, but it is the BEST thing we have on the iphone now, and being that this a version 1 of this feature, i would imagine it only gets better. One additional feature that would be nice is to be able to enter data that is not necessarily financial/website orientated such as Drivers License number, health information, and other data. All in all a great start by the company, and hopefully they build on it. Very clever programming to get around the "No 3rd Party Apps"
traderx1 is offline   Reply With Quote
Old Oct 9, 2007, 03:21 PM   #5
Mr. Zorg
macrumors member
 
Join Date: Sep 2007
Quote:
Originally Posted by traderx1 View Post
i can understand your fear, a web applet that stores your personal passwords. In reality, the information is NEVER stored on another server/computer (if the makers of this dandy program read, please correct me).
Guys, please pay attention to traderx1's post... He's nailed what most of you seem to be missing. This is basically just an adaptation of the previously released bookmarklet app that write a javascript/dhtml app with your encoded passwords into a Safari bookmark. Nothing's sent over the net. Very clever.

Now, that said, I do have two concerns (I have not tried it yet):

1) Previously when I was using bookmarklets, it made starting Safari very sluggish (on both my mac and my iphone). Presumably this is because if the size of the bookmarklets I had. I'm sure the bookmarks system was never optimized to carry such large amounts of data. Hopefully this generates a very small amount... Don't know.

2) According to their site it uses some pretty strong cryptography (448 bit blowfish). While blowfish is a very fast cipher, I wonder just how fast it would run in javascript on the (relatively limited) horsepower of the iphone...

I guess one way to find out is to try it.
Mr. Zorg is offline   Reply With Quote
Old Oct 9, 2007, 06:58 PM   #6
dteare
macrumors newbie
 
Join Date: Jun 2006
Quote:
Originally Posted by Mr. Zorg View Post
Guys, please pay attention to traderx1's post... He's nailed what most of you seem to be missing. This is basically just an adaptation of the previously released bookmarklet app that write a javascript/dhtml app with your encoded passwords into a Safari bookmark. Nothing's sent over the net. Very clever.
Exactly correct!

All your information is encrypted into a bookmarklet, and stored in Safari on your Mac. When you sync your iPhone in iTunes, the bookmarklet is synced just like all your other bookmarks.

The data is then decrypted in Safari on your iPhone once you provide the correct password.

No external web servers. And No hacks!

Quote:
Originally Posted by Mr. Zorg View Post
Now, that said, I do have two concerns (I have not tried it yet):

1) Previously when I was using bookmarklets, it made starting Safari very sluggish (on both my mac and my iphone). Presumably this is because if the size of the bookmarklets I had. I'm sure the bookmarks system was never optimized to carry such large amounts of data. Hopefully this generates a very small amount... Don't know.
This can be true, but for us the only delay was in the initial load (see below).

Quote:
Originally Posted by Mr. Zorg View Post
2) According to their site it uses some pretty strong cryptography (448 bit blowfish). While blowfish is a very fast cipher, I wonder just how fast it would run in javascript on the (relatively limited) horsepower of the iphone...
Blowfish is amazingly fast. We actually started with AES encryption, but it was just too much overhead for the iPhone. Blowfish was over 10 times faster and it decrypts your individual entries almost instantly.

The only performance bottleneck is the initial loading of the page. Since *everything* is stored inside the bookmarklet, it can get pretty big. On our personal datasets of 800 items, it is 600KB, which takes Safari a while to load (mine takes 9 seconds to load). Thankfully most users have less than 200 entries, which load in just a few seconds.

Quote:
Originally Posted by Mr. Zorg View Post
I guess one way to find out is to try it.
What are you waiting for??
__________________
Cheers!
Dave Teare
Co-author of 1Password Password Manager
dteare is offline   Reply With Quote
Old Oct 10, 2007, 10:58 AM   #7
traderx1
macrumors member
 
Join Date: Mar 2007
dteare...

seeing that you are involved with the software company of 1password, i had a suggestions for future implementation. The software works wonderfully with my iphone, but my one request is the ability to put in other things other than web password. I see a option Credit Cards which is great and what I needed, but also put in other non-internet related info such has financial information, drivers license, car info, health insurance/info. the list could go on...but that would be a great start. Even the ability to have blank fields and add various private info would be awesome.
thanks
traderx1 is offline   Reply With Quote
Old Oct 9, 2007, 06:51 PM   #8
roustk
macrumors newbie
 
Join Date: Jul 2006
Quote:
Originally Posted by ozziegn View Post
a web applet application that allows me to store all of my important passwords? sure, where do I sign up?

NOT!
AFAIK, this is the most secure way to carry your passwords and other confidential information on iPhone.

To address your concerns:

1. All information and the javascript code to access it is stored locally inside the Safari bookmarklet. Internet access is NOT required to use it.

2. The passwords are encrypted with 448 Blowfish encryption using CBC (Cipher Block Chaining) and a randomized salt. The access code is needed to decrypt individual entries.

3. The JavaScript code automatically locks the application after 5 minutes of inactivity.
roustk is offline   Reply With Quote
Old Oct 19, 2007, 10:52 AM   #9
SC68Cal
macrumors 68000
 
Join Date: Feb 2006
Quote:
Originally Posted by ozziegn View Post
a web applet application that allows me to store all of my important passwords? sure, where do I sign up?

NOT!
Quoted for Truth.

Also, storing the passwords locally on the iPhone is a terrible idea as well, when you are using a TIFF exploit to unlock the phone. Who says the same TIFF exploit can't be used to take those passwords?

Granted, you're using Blowfish, but still if the password database is able to be lifted from the phone then the game is up. Plus, just because you have encryption doesn't mean you're secure because you can have the encryption key being generated with a dictionary word.
SC68Cal is offline   Reply With Quote
Old Oct 19, 2007, 11:14 PM   #10
dteare
macrumors newbie
 
Join Date: Jun 2006
Quote:
Originally Posted by SC68Cal View Post
storing the passwords locally on the iPhone is a terrible idea as well, when you are using a TIFF exploit to unlock the phone. Who says the same TIFF exploit can't be used to take those passwords?
Nothing is perfect (as Bruce Schneier used to say) but 1Password for iPhone is the safest solution, next to not using a computer at all. Certainly it is much safer than reusing the same password all over again or trying to keep them on a piece of paper. If you need to access your accounts while on the road, you need a strong solution like 1Password's Sync to iPhone.

The TIFF exploit used on iPhone is simply one example of taking control of a device. Safari and other apps are frequently patched to prevent buffer overflows that allow "arbitrary code execution", so your Mac is vulnerable just like the iPhone (albeit, the iPhone is particularly bad because everything runs as root, but I digress). This is why keeping your software up-to-date is part of any good Defense-In-Depth plan.

Since 1Password's Sync to iPhone does not use any hacks, you are allowed to upgrade to the latest firmware which will fix these exploits, and you won't need to worry about bricking your iPhone

Quote:
Originally Posted by SC68Cal View Post
Granted, you're using Blowfish, but still if the password database is able to be lifted from the phone then the game is up. Plus, just because you have encryption doesn't mean you're secure because you can have the encryption key being generated with a dictionary word.
The strength of the Blowfish encryption is directly proportional to the strength of your password (in terms of brute force attacks). Using a dictionary word for your master password is a terrible idea as specially designed applications can easily guess them. You must choose a good strong password! Otherwise, there is no sense in using encryption at all.

The beauty of 1Password is that you will only need to remember one password, so you are able to make it a strong password and since there is only one you will be able to commit it to memory.
__________________
Cheers!
Dave Teare
Co-author of 1Password Password Manager

Last edited by dteare : Oct 19, 2007 at 11:21 PM.
dteare is offline   Reply With Quote
Old Oct 9, 2007, 02:08 PM   #11
deep
macrumors newbie
 
Join Date: May 2007
Excellent!

I've been using the desktop app for a couple of weeks now, and I have to say I'm pretty impressed. I have over a 150 sites in my keychain and remembering all the different usernames and passwords is becoming impossible. So far, this app has done a great job of getting things organized, and as it also synchs across multiple computers through .mac, it's saves me a lot of time and grief. One thing I wished it would do was work on an iPhone or Touch. Looks like the developers are thinking along the same line.

Ever try typing a long username and password on an iPhone or Touch? What a pain the ass! I'd definitely give this a shot if they can make it autofill on the iPhone. Also needs to store things other than just website logins, like multiple form fill profiles and text.

Last edited by deep : Oct 9, 2007 at 02:15 PM.
deep is offline   Reply With Quote
Old Oct 9, 2007, 02:32 PM   #12
Danicus
macrumors newbie
 
Join Date: Sep 2006
Location: ny ny
this has bad idea all over it
Danicus is offline   Reply With Quote
Old Oct 9, 2007, 04:49 PM   #13
Aetles
macrumors newbie
 
Join Date: Nov 2002
Location: Umeå, Sweden
Quote:
Originally Posted by Macrumors View Post
The new version adds a "Sync to iPhone" feature which exports all your stored passwords into an encrypted Safari Bookmarklet. The Bookmarklet is accessible from the iPhone's Safari bookmark list and protected by a password.
It seems a lot like the already announced PasswordWallet for iPhone.
Aetles is offline   Reply With Quote
Old Oct 9, 2007, 05:46 PM   #14
kugino
macrumors 6502a
 
kugino's Avatar
 
Join Date: Jul 2003
everyone's fears and apprehensions are totally understandable. were i not using the desktop version of 1Password i'd be equally dubious.

but it's really an amazing app by a good company. though i don't have an iphone (yet) i will most definitely look into this implementation when i pick up an iphone in january.

just FYI, the TWIT macbreak guys really like 1Password, too, and they highly recommend it...and that's how i learned about this app. saves me a ton of time with a lot of password-protected sites my job forces me to engage with...and i feel very confident about the security measures implemented in this app. hopefully people will take a serious look at this app before judging it. if it's not for you, fine.
__________________
2.4GHz MBP
32GB white iPhone 3GS
first-gen 20" intel iMac
Air Extreme, Air Express, Al BT keyboard
kugino is offline   Reply With Quote
Old Oct 9, 2007, 07:40 PM   #15
NightOne
macrumors newbie
 
Join Date: Dec 2006
Location: TN
Quote:
Originally Posted by Aetles View Post
It seems a lot like the already announced PasswordWallet for iPhone.
Ironically, it was someone from Sweden who posted pretty much the same thing on the TUAW post.

Do you work for PasswordWallet or something?
NightOne is offline   Reply With Quote

Reply

Mac Forums > iPhone and iPod Touch Forums > iPhone News Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 09:19 PM.

Mac News | Mac Rumors | iPhone Game Reviews | iPhone Apps

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright 2002-2009, MacRumors.com, LLC