Hacker News new | ask | show | jobs
by julian37 1146 days ago
Surely the UI code is what responds to clicking "reveal" and therefore, if compromised, could fetch the secret even without a click?
1 comments

Good point. I don’t know what 1Password could do to prevent the telemetry from issuing control commands to the rest of the app outside of trying to prevent malicious code from being checked in and deployed.