FFS, it hasn’t even been six months since I ditched LastPass to move to 1Password.

1Password detects “suspicious activity” in its internal Okta account | Ars Technica arstechnica.com/security/2023/

@AnnemarieBridy Do none of these services have a zero trust model? It's perfectly straightforward to build an authentication system where they can't reveal your information because they don't have it. Damned if I know why they don't implement one.

@AnnemarieBridy To (perhaps) answer my own question, according to some of the discussion in that article, 1password does indeed implement that model. If so, assuming they did it right, a breach would gain an attacker nothing in the way of customer passwords.

@pieist Let's hope that's true. But these stories always seem to start out by saying there's been a breach, but, whew, there's no bad news. Then a week later, there's bad news, followed by very bad news.

Follow

@AnnemarieBridy Yes, I shouldn't sound so absolutist. An unquantifiable number of further compromises are possible once they're inside the firewall; they don't have to have your passwords in cleartext right from the get-go.

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.