惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
J
Java Code Geeks
V
V2EX
Blog — PlanetScale
Blog — PlanetScale
博客园 - 司徒正美
Hugging Face - Blog
Hugging Face - Blog
F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
B
Blog
A
About on SuperTechFans
有赞技术团队
有赞技术团队
月光博客
月光博客
Microsoft Azure Blog
Microsoft Azure Blog
阮一峰的网络日志
阮一峰的网络日志
腾讯CDC
美团技术团队
大猫的无限游戏
大猫的无限游戏
爱范儿
爱范儿
N
Netflix TechBlog - Medium
C
Check Point Blog
Recent Announcements
Recent Announcements
博客园 - Franky
博客园 - 叶小钗
T
Tailwind CSS Blog

Blog on 1Password Blog

NIST and AI agents: 1Password’s approach to agent identity | 1Password Go beyond device health with External Checks in 1Password Device Trust | 1Password Natoma and 1Password help enterprises scale AI securely with governed agent access | 1Password New integrations between 1Password SaaS Manager and EPM | 1Password A first step toward post-quantum security | 1Password RSA 2026: Leading the way to secure agentic AI | 1Password How 1Password is Building a Culture of AI Fluency Through AI Champions | 1Password 1Password vs. Keeper Security: A comparison | 1Password 1Password vs. LastPass: Which is right for you? | 1Password Secure MCP credentials with 1Password and Runlayer | 1Password The next layer of AI security | 1Password Building the next chapter of Go-to-Market in EMEA | 1Password Automating SOC workflows with 1Password Enterprise Password Manager | 1Password Automated Provisioning hosted by 1Password: A Simpler, Smarter Way to Manage Access | 1Password Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents | 1Password Next-generation automated provisioning, without compromising zero-knowledge security | 1Password Bitwarden vs. 1Password: Which password manager is right for you? | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password How to wrangle SaaS contract renewals | 1Password Stop trusting consumer browsers with work credentials | 1Password IAM stops at sign-in. Your credentials do not. | 1Password Your digital pit crew: a 10-minute pre-race security checklist | 1Password 1Password Device Trust is coming to EMEA | 1Password The identity transformation: Analyst and CIO insights | 1Password Why now is the moment to join 1Password Go-To-Market | 1Password Identity and Accountability in the Age of AI Agents | 1Password How 1Password secures agent architectures | 1Password 1Password becomes the first global partner to transact through Express Private Offers in AWS Marketplace | 1Password Start Learning on 1Password Academy | 1Password Expanding Programmatic Access to 1Password | 1Password
Password Manager for Families, Enterprise & Business | 1P...
info@1passwo · 2026-06-16 · via Blog on 1Password Blog

At 1Password, we regularly invite outside experts to challenge our assumptions and strengthen our security.  We encourage security researchers to participate in our bug bounty programs, and have spent years building a collaborative research environment. We also believe in the benefit of open source software and standards, which raise the bar for the industry as a whole, while ultimately benefiting our 1Password customers.

That’s why we funded an independent security assessment of the open source library Snow, worked closely with the maintainer on remediation, and are making the results publicly available for anyone to review.

Where to read the report

The results of the independent security assessment are available now for anyone who wants to learn more.

Why we invested in Snow 

Snow is a Rust implementation of the Noise Protocol Framework, a system for building secure channels using customizable cryptographic handshake patterns based on Diffie-Hellman key exchange. We rely on Noise-protected channels in parts of 1Password. Since Snow gives Rust developers an implementation of that framework, that makes it, for us,  part of the security foundation we care about getting right. Funding validation on Snow allows us to improve something we care deeply about while giving back to the open source community that helps make 1Password possible. 

We are active contributors to Snow. The pull requests we’ve opened and the independent security assessment we funded reflect our commitment to helping strengthen the project. 

What Trail of Bits found

Trail of Bits reviewed Snow through a combination of manual review and automated testing over four engineer-weeks. Their report identified 10 findings in total: one medium-severity issue, one low-severity issue, and eight informational findings. The most important issue discovered was a nonce-handling bug that could let an attacker permanently disrupt an encrypted channel without knowing any cryptographic secrets. Another finding showed that invalid PSK indices could trigger a panic, creating a denial-of-service condition. 

For more details on the engagement, including the informational findings, please read the published security assessment.

We then worked with Jake McGinty, the Snow maintainer, to remediate the issues, and with Trail of Bits to validate the fix. To date, 8 of the 10 findings are resolved, including the medium-severity nonce-handling flaw, the invalid-PSK panic, message-length enforcement. Two longer-horizon informational items remain and we believe neither impact the security of the Snow library.

What’s next?

Thank you

We want to say thank you to Trail of Bits, and especially Joe Doyle and Tjaden Hess, for the assessment and review. We’re also grateful to Jake McGinty, the Snow maintainer, for partnering on remediation, providing real-time assistance during the testing, and helping turn the report into concrete improvements.

Open source security work is most valuable when it doesn’t stop at identifying problems. Funding an audit with transparent results matters, but working with maintainers to responsibly land fixes matters even more. That is how we help raise the security bar not just for one company, but for the larger community that depend on the same foundational building blocks. 

If you’re building in Rust and need the Noise Protocol Framework, take a look at Snow. Read the audit, review the code, and try it in your own projects. Open source becomes stronger when more developers use it, test it, and invest back into it. We’re excited to see what you build.

Want to learn more about building securely with 1Password?