Hacker News new | ask | show | jobs
by whymarrh 1630 days ago
1Password's cloud offering architecture has a few important distinctions from other offerings. Namely the use of a password authenticated key exchange (PAKE) and a "Secret Key" that is never transmitted to 1Password servers. [1, 2] If you ultimately trust the app for local vaults, there's a case for extending that trust to the cloud offering.

[1]: https://blog.1password.com/what-the-secret-key-does/

[2]: https://old.reddit.com/r/1Password/comments/rp8t02/security_...