惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
Netflix TechBlog - Medium
I
InfoQ
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
Recent Announcements
Recent Announcements
T
The Blog of Author Tim Ferriss
P
Proofpoint News Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
D
Docker
Microsoft Security Blog
Microsoft Security Blog
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
GbyAI
GbyAI
博客园 - Franky
博客园 - 聂微东
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
B
Blog RSS Feed
WordPress大学
WordPress大学
MyScale Blog
MyScale Blog
月光博客
月光博客
罗磊的独立博客

Blog on 1Password Blog

Why secure-by-design is an incentives problem, with Bob Lord | 1Password NIST and AI agents: 1Password’s approach to agent identity | 1Password Go beyond device health with External Checks in 1Password Device Trust | 1Password Natoma and 1Password help enterprises scale AI securely with governed agent access | 1Password New integrations between 1Password SaaS Manager and EPM | 1Password RSA 2026: Leading the way to secure agentic AI | 1Password How 1Password is Building a Culture of AI Fluency Through AI Champions | 1Password 1Password vs. Keeper Security: A comparison | 1Password 1Password vs. LastPass: Which is right for you? | 1Password Secure MCP credentials with 1Password and Runlayer | 1Password The next layer of AI security | 1Password Building the next chapter of Go-to-Market in EMEA | 1Password Automating SOC workflows with 1Password Enterprise Password Manager | 1Password Automated Provisioning hosted by 1Password: A Simpler, Smarter Way to Manage Access | 1Password Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents | 1Password Next-generation automated provisioning, without compromising zero-knowledge security | 1Password Bitwarden vs. 1Password: Which password manager is right for you? | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password How to wrangle SaaS contract renewals | 1Password Stop trusting consumer browsers with work credentials | 1Password IAM stops at sign-in. Your credentials do not. | 1Password Your digital pit crew: a 10-minute pre-race security checklist | 1Password 1Password Device Trust is coming to EMEA | 1Password The identity transformation: Analyst and CIO insights | 1Password Why now is the moment to join 1Password Go-To-Market | 1Password Identity and Accountability in the Age of AI Agents | 1Password How 1Password secures agent architectures | 1Password 1Password becomes the first global partner to transact through Express Private Offers in AWS Marketplace | 1Password Start Learning on 1Password Academy | 1Password Expanding Programmatic Access to 1Password | 1Password
A first step toward post-quantum security | 1Password
info@1password.com (Daryl Martin) · 2026-03-31 · via Blog on 1Password Blog

At 1Password, our mission is simple: to protect people’s most critical information, their credentials. At the time of writing this post, I personally have 291 items in my vault, so the long-term confidentiality of this data is critical to myself and every 1Password user. We are thrilled to announce the first major milestone in our post-quantum cryptography (PQC) journey, the successful deployment of PQC on 1Password’s web application. If you’re using a PQC-capable browser, such as Chrome or Firefox, your data is protected today with no action required. 

The threat of a large-scale quantum computer, sometimes referred to as a cryptographically relevant quantum computer (CRQC), is its potential to break the public-key cryptographic algorithms. These algorithms are used in most communication protocols and digital signature schemes. While it's unclear that a quantum computer powerful enough to break the public key cryptography will ever exist, we are not waiting for one before taking action to protect your data. 

“Harvest now, decrypt later” attacks are a practical concern where adversaries intercept and store encrypted traffic today with the intention of decrypting it in the future, once quantum computers become powerful enough. We are putting protections in place now to ensure the long-term confidentiality of our customers’ data well into the future.

This is the first step in our long-term plan to protect customer data and withstand harvest-now, decrypt-later attacks. We will provide updates in the future as we migrate other parts of our infrastructure to support PQC, as we firmly believe that cryptographic designs should be done in the public. 

What we delivered 

We began our PQC rollout where it matters most for long-term confidentiality: internet-facing traffic. When a browser connects to 1Password, it establishes a TLS session using public-key cryptography to negotiate encryption keys. Historically, that key exchange relied solely on classical algorithms like elliptic curve cryptography. While secure against today’s computers, those algorithms may be vulnerable to sufficiently powerful quantum computers.

With this launch, 1Password now supports hybrid post-quantum key exchange (X25519MLKEM768) for all 1Password web application connections. When a compatible browser connects, it negotiates a TLS handshake that combines classical cryptography with a quantum-resistant algorithm (such as ML-KEM). This hybrid approach preserves compatibility while adding protection against future quantum adversaries. This all happens automatically; there are no configuration changes or performance penalties.

How to verify PQC in your browser

If you’re using a modern browser, such as Chrome, you can verify this yourself.

  1. Open your browser and navigate to your 1Password account (for example, https://my.1password.com).

  2. Under settings, navigate to More Tools -> Developer Tools.

  3. Select the Privacy and Security tab.

  4. View the Security Overview and note the connection uses X25519MLKEM768

How to verify PQC in your browser

If PQC is being used, you’ll see a hybrid key exchange (X25519MLKEM768).  PQC depends on browser support, so results may vary depending on version and configuration. If you do not see PQC being negotiated, please update your browser and double-check other test websites such as https://pq.cloudflareresearch.com/ 

Conclusion

This milestone represents the first phase of a broader post-quantum roadmap at 1Password. We are focusing on the parts of our architecture that are most at risk of HNDL attacks to preserve long-term confidentiality. We will provide future updates and more technical details as we expand our PQC coverage across our products.  

At 1Password, our responsibility is to protect your data, not just against today’s threats but tomorrow’s as well.