They also discuss 1Password. no authentication of public keys, vulnerable to vault substitution attack (it does not authenticate vault keys) and KDF Parameter Downgrade (a malicious server can reduce the iteration count from the default 650,000 iterations to a minimal value of 10,000 iterations.)
gnabgib•1h ago