Today, researchers from the Applied Cryptography Group at ETH Zurich published a paper examining how different password managers uphold their “zero-knowledge” architecture when faced with a fully malicious server. We conducted a thorough review of the paper and confirmed that it doesn’t introduce any new attack vectors affecting 1Password beyond the architectural limitations already documented in our Security Design White Paper . We appreciated the opportunity to speak with the team about their research and value the work they’ve contributed to this area.
Zero knowledge vs. a malicious server: A look at ETH Zurich’s research
calendar_today
February 15, 2026
person
info@1password.com (Jacob DePriest and Andrew Hall)
domain
1password