Comment on 1Password discloses security incident linked to Okta breach
anoxydre@jlai.lu 1 year agoExactly. Accounts are locked with both password and encryption key. The latter is not known by 1Password.
Comment on 1Password discloses security incident linked to Okta breach
anoxydre@jlai.lu 1 year agoExactly. Accounts are locked with both password and encryption key. The latter is not known by 1Password.
tippl@lemmy.world 1 year ago
To be accurate, they don’t know either. A login key and a decryption key are derived from password and secret key client-side.