How 1Password is designed to keep your data safe, even in the event of a breach
blog.1password.com
blog.1password.com
This was good support for 1PW's 2-key solution, since one of the keys is randomly generated with a true 128 bits of entropy, no matter what password the user chooses, a compromise of the service's data store alone will mean the user's vault encryption key is uncrackable.
[1]: https://neilmadden.blog/2023/01/09/on-pbkdf2-iterations/
Disclaimer: I'm an employee of 1Password.
I know your linked article talks about it a bit like this, but I think it's wrong to think about PBKDF2 as "increasing the entropy" of a password. The number of PBKDF2 rounds just increases the cost of each guess an attacker makes, but doesn't fundamentally change the number of guesses an attacker needs to make. To me it's basically the constant multiplier term with respect to Big-O notation - that is, while some process make take 1000N time or 10N, it's all still just O(n).
So, that said, I 100% agree that 1Password's approach of using a truly random 128 bit string as part of the key is fundamentally an uncrackable approach while LastPass's was not.
Curious if you've had a chance to try the Setup Code? It's not as slick as iCloud since we don't own the OS, but it enables you to scan the code and get all the account details on your new device. That way all you need to do is type your password.
On that note we recently had a hackathon around this to make things even simpler and we had some success there. I'm hoping we can make this real and share it in an update later this year.
Security is always at odds with convenience. - Steve Gibson
The obvious benefit of a secret key is its high entropy. But I also like how the secret key discourages me from logging into 1Password on anything but my own, trusted, devices. In my view, password managers should not be accessed from other people's computers or internet kiosks.