FFS, it hasn’t even been six months since I ditched LastPass to move to 1Password.
1Password detects “suspicious activity” in its internal Okta account | Ars Technica https://arstechnica.com/security/2023/10/1password-detects-suspicious-activity-in-its-internal-okta-account/
@AnnemarieBridy Do none of these services have a zero trust model? It's perfectly straightforward to build an authentication system where they can't reveal your information because they don't have it. Damned if I know why they don't implement one.
@AnnemarieBridy To (perhaps) answer my own question, according to some of the discussion in that article, 1password does indeed implement that model. If so, assuming they did it right, a breach would gain an attacker nothing in the way of customer passwords.
@AnnemarieBridy Yes, I shouldn't sound so absolutist. An unquantifiable number of further compromises are possible once they're inside the firewall; they don't have to have your passwords in cleartext right from the get-go.