Post #322373
2026-02-18 04:20 UTC
@dangoodin@infosec.exchange https://1passwordstatic.com/files/security/1password-white-paper.pdf
"At present there’s no practical method for a user to verify the public key they’re encrypting data to belongs to their intended recipient. As a consequence it would be possible for a malicious or compromised 1Password server to provide dishonest public keys to the user, and run a successful attack. Under such an attack, it would be possible for the 1Password server to acquire vault encryption keys with little ability for users to detect or prevent it.” (1/3)
Replies (0)
No replies.