3 ms·
I thought I remembered 1Password using SRP (https://blog.agilebits.com/2015/11/11/how-1password-for-teams-protects-your-secrets/ https://blog.agilebits.com/2015
by motive 9y ago
I thought I remembered 1Password using SRP (https://blog.agilebits.com/2015/11/11/how-1password-for-teams-protects-your-secrets/ https://blog.agilebits.com/2015/11/11/how-1password-for-team...).
I admittedly don't know enough about the underlying cryptography to have an educated opinion, but it seems like they put some due diligence into determining it still provided value.
- tprynn 9y ago1Password uses TLS, and SRP inside TLS. If TLS is broken as in Cloudbleed, SRP hopefully still protects the channel - at least against non-active attacks such as Cloudbleed. The security still ultimately relies on TLS. Having not read the document fully, I think those would be against initial registration or in an active MITM allowing password-guessing. I'm looking at page 52 of https://1password.com/teams/white-paper/1Password%20for%20Teams%20White%20Paper.pdf https://1password.com/teams/white-paper/1Password%20for%20Te....