This is all about how password managers deal with unencrypted data in memory. On disk the encryption is all fine, but when running, they should minimize the attack surface. I was expected better outcomes for 1Password, my preferred password manager. Note though that these all require access to a computer and unlocked memory state, so the real risk is low. Nonetheless, I’d like to see this improved.

Posted on February 21, 2019

