Skip to main content
May 19, 2022
Question

1Password 8 Password Multiple Password Vault Unlock

  • May 19, 2022
  • 13 replies
  • 556 views

So in 1PW7, I was able to unlock all my accounts with one password. However, it looks like in 1PW8, I need to unlock each account separately. We have quite a few vaults that we share with clients and unlocking each one is hassle. Can we get the 1PW7 behavior back so that we don't need to enter dozens of passwords to unlock all of our accounts?


1Password Version: 1Password for Mac 8.7.0
Extension Version: Not Provided
OS Version: macOS 12.4

13 replies

1Password Employee
May 24, 2022

However, the fact that I periodically get logged out on one account and not the other is annoying. There are times when I am trying to fill a login prompt and it says there are no passwords for that site. That is when I have to launch the full 1 Password to find that one of my accounts is logged out.

I have not had that happen while using the same account password for all accounts, or using Touch ID, Windows Hello, etc. Since you're planning on making that change, I don't anticipate this will continue. If it does, please start a new thread (or email us at support@1password.com) so we can troubleshoot.

Ben

August 10, 2022

@Jack_P_1P I appreciate the response, but it just focuses on policy rather than addressing real and practical threats to the password manager.

Windows Hello, Touch ID, Face ID, and Apple Watch unlock will continue to unlock each 1Password account that has been unlocked with an account password, even if they're different. If you'd prefer to use different account passwords, unlocking them each once, and then using the biometry options available on that specific version of 1Password 8 would be your best bet.

This is the crux of the issue. It seems clear that 1Password has not been following the legal and practical developments around biometrics. Biometrics access can be compelled whereas revealing passwords cannot under recent US case law.

https://www.nacdl.org/Content/Compelled-Decryption-Primer
https://news.bloomberglaw.com/us-law-week/compelled-biometric-access-legal-under-4th-5th-amendments
https://arstechnica.com/tech-policy/2019/11/police-cant-force-child-porn-suspect-to-reveal-his-password-court-rules/
https://www.techdirt.com/2022/07/21/fbi-successfully-forced-a-criminal-suspect-to-unlock-his-wickr-account-with-his-face/
https://www.biometricupdate.com/201912/federal-state-court-rulings-on-whether-biometrics-protected-by-fifth-amendment-get-murky

We can't use biometrics with several of our customers since biometric components can never be changed/modified since they are physically traits of the user that can always unlock all accounts over a period of up to two weeks when users could be legally compelled.

Aside from the legal issues, thieves that mug users on the street are frequently forcing users to look at or use their fingerprint to unlock devices.

https://www.thetimes.co.uk/article/mugged-for-my-phone-then-locked-out-of-my-life-92kpv50x7
https://abc7chicago.com/chicago-robbery-south-loop-downtown-cellphone/1506428/
https://goalz.online/thieves-forcing-victims-to-unlock-phones-before-transferring-thousands-of-pounds-in-digital-currency/
https://bobsullivan.net/gotchas/forced-to-venmo-at-gunpoint-smartphone-crime-gets-more-violent-more-tech-y/

A quick access PIN/Token would give your customers options to address both of these issues and was previously implemented in 1Password 7 for iOS with a single failure lockout.

If an intrinsic unchangeable physical trait is acceptable, then I can't see why a single-attempt/single failure lockout PIN as implemented in 1Password 7 for iOS would not also be acceptable to unlock all vaults over the two week period that you specified.

August 10, 2022

@Jack_P_1P

It looks like you deleted my last reply in this thread. Could you elaborate why?