I would need proof before I admitted it.
I'm on the same page. Ending a snarky comment with "LOL" suggests much younger.
I think one of your positions is that 1Password is no more secure than iCloud keychain, since 1Password keeps the account key in the keychain. I don't draw that conclusion for two reasons.
1 - The Keychain entry for 1Password's account key (secret key) has the comment:
1Password Touch ID and Apple Watch Unlock Key
Your account key is encrypted by the Secure Enclave and then saved in this item. Learn more about the security of using Touch ID or Apple Watch to unlock 1Password:
https://support.1password.com/touch-id-apple-watch-security-mac/
This key is stored in a format that Keychain Access doesn’t understand, so you won’t be able to reveal its password.
This does suggest more security than what is suggested by the simple statement "1Password keeps the account key in Keychain".
2 - 1Password's security hinges on more than just the account key (as
@Mr. Heckles reminded me). I picture myself hanging from a cliff's edge with my three arms.
- my baby arm - That's my confidence that 1Password's enterprise practices adequately safeguard my vault.
- my regular arm - That's the security of my well chosen master password which only exists in my mind.
- my arm on steroids - That's the the account key.
The fact that the account key is in my iCloud Keychain does weaken that third arm, but I really can't say by how much.
On the other hand, iCloud's security is based on AppleID and a password. I believe that if you know those two, you can recover your Keychain. It may be that if you don't have any old devices or access to the recovery email or phone number, it would require a call to Apple. But, that seems comparatively weak thanks to social engineering tricks.
Please correct me if someone knows that it is impossible to recover my iCloud account with JUST my AppleID and password.
So, three arms versus one, while hanging from a cliff's edge. And then there's trust in the software. Apple has proven to me time and again that it writes buggy software. I have no evidence that 1Password does. I trust 1Password's competence and reliability in this arena more than I do Apple's. But, that's just my gut talking.