2 ms·
Can't believe that 1password doesn't enforce multi-factor by default for the online account. They have a secret key which more or less acts a 2nd factor but it
by sam345 2y ago
Can't believe that 1password doesn't enforce multi-factor by default for the online account. They have a secret key which more or less acts a 2nd factor but it looks like in this case they stole the victim's web session which held the key. Could have happened if they had stole the multi-factor session too I guess.
- toomuchtodo 2y agoThey have conditional access capabilities. https://support.1password.com/firewall-rules/ https://support.1password.com/firewall-rules/ (have implemented to attempt to mitigate this vulnerability, but if there is malware active on the device, it will eventually have access to the clipboard or otherwise unencrypted secret)