@AnnemarieBridy Do none of these services have a zero trust model? It's perfectly straightforward to build an authentication system where they can't reveal your information because they don't have it. Damned if I know why they don't implement one.
@pieist Let's hope that's true. But these stories always seem to start out by saying there's been a breach, but, whew, there's no bad news. Then a week later, there's bad news, followed by very bad news.
@AnnemarieBridy Yes, I shouldn't sound so absolutist. An unquantifiable number of further compromises are possible once they're inside the firewall; they don't have to have your passwords in cleartext right from the get-go.
@AnnemarieBridy To (perhaps) answer my own question, according to some of the discussion in that article, 1password does indeed implement that model. If so, assuming they did it right, a breach would gain an attacker nothing in the way of customer passwords.