I noticed that Proton Pass’s domains are DNSSEC-signed, while 1Password’s main service domains are not.
Without DNSSEC, a forged DNS response could theoretically redirect a user to another server.
At the same time, my understanding is that DNS spoofing alone should not be enough to compromise a 1Password account because:
– the attacker would still need a valid TLS certificate for the 1Password domain;
– 1Password uses SRP to authenticate the server without transmitting the account password or Secret Key; and
– vault data remains end-to-end encrypted.
So the consequence of a DNS-only attack would more likely be a certificate warning?
Notwithstanding, DNSSEC is a useful defence-in-depth measure. Is there a stronger technical reason why 1Password has not deployed DNSSEC?
submitted by /u/krmkrx to r/1Password
[link] [comments]
Source: r/1Password · by /u/krmkrx