Skip to content
DnsLister Forum

Where domain hunters compare notes

Proton Pass uses DNSSEC, while 1Password does not. How significant is that?

I noticed that Proton Pass’s domains are DNSSEC-signed, while 1Password’s main service domains are not.

Without DNSSEC, a forged DNS response could theoretically redirect a user to another server.

At the same time, my understanding is that DNS spoofing alone should not be enough to compromise a 1Password account because:

– the attacker would still need a valid TLS certificate for the 1Password domain;
– 1Password uses SRP to authenticate the server without transmitting the account password or Secret Key; and
– vault data remains end-to-end encrypted.

So the consequence of a DNS-only attack would more likely be a certificate warning?

Notwithstanding, DNSSEC is a useful defence-in-depth measure. Is there a stronger technical reason why 1Password has not deployed DNSSEC?

submitted by /u/krmkrx to r/1Password
[link] [comments]

Source: r/1Password · by /u/krmkrx

Leave a Reply

Your email address will not be published. Required fields are marked *