FFS, it hasn’t even been six months since I ditched LastPass to move to 1Password.
1Password detects “suspicious activity” in its internal Okta account | Ars Technica https://arstechnica.com/security/2023/10/1password-detects-suspicious-activity-in-its-internal-okta-account/
@AnnemarieBridy To (perhaps) answer my own question, according to some of the discussion in that article, 1password does indeed implement that model. If so, assuming they did it right, a breach would gain an attacker nothing in the way of customer passwords.
@AnnemarieBridy Yes, I shouldn't sound so absolutist. An unquantifiable number of further compromises are possible once they're inside the firewall; they don't have to have your passwords in cleartext right from the get-go.
@pieist Let's hope that's true. But these stories always seem to start out by saying there's been a breach, but, whew, there's no bad news. Then a week later, there's bad news, followed by very bad news.