3 ms·
I actually found that thread concerning. Based on his description, I'm not seeing the "zero-knowledge" mechanism. As described, 1Password (or a hacker on their
by runlevel1 5y ago
I actually found that thread concerning.
Based on his description, I'm not seeing the "zero-knowledge" mechanism. As described, 1Password (or a hacker on their server) would still be able to associate site-to-IP.
The cryptographically generated one-time URLs he mentioned would only prevent a MITM from knowing which what's being requested. The icon server still needs to know which site's icon to send to the requester.
Additionally, it appears 1Password falls back to fetching a site's favicon if they don't have an icon. So it would seem it's only leaking this info to 1Password so that it can fetch higher quality icons.
Unless I've missed something, this sacrifices security for aesthetics.
The thread referenced: https://twitter.com/mitchchn/status/1484225379854426114 https://twitter.com/mitchchn/status/1484225379854426114
EDIT: Yeah, this is not the "zero-knowledge" service implied: https://support.1password.com/rich-icons-privacy/ https://support.1password.com/rich-icons-privacy/