Skip to main content
prime
June 18, 2023
Question

Passkey and unlocking 1Password with it (biometrics) in iPhones

  • June 18, 2023
  • 22 replies
  • 1796 views

In this blog post, it shows how we can log into 1Password without a password, and using our biometrics/device. Correct me if I am wrong... So the Passkey for my 1Password account is tired to my iPhone (assuming in the passkey area of my iPhone). With the issue of people having their iPhone stolen and they are locked out, is this a bad idea? If someone gets my iPhone, has my passcode for my iPhone, wouldn't the attacker have access to my 1Password then?

I know the work around to protect my iPhone, but not all do this. my iPhone password is also alphanumeric, not just 6 digits.


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser:_ Not Provided

22 replies

prime
primeAuthor
June 28, 2023

@1P_David you have any words of wisdom about this?

1P_Dave
1Password Employee
July 5, 2023

Hello @prime! 👋

I'm sorry for missing your post and I'm happy to respond to some of your concerns.

Folks will soon be able to unlock their 1Password account with a passkey instead of a Secret Key and account password – this removes the need to remember a strong and unique password. Customers can add trusted devices to sign in to their account using the same passkey. As with account passwords, inside 1Password isn’t a good place to keep the passkey for 1Password. Instead, we’ll rely on solutions – such as iCloud Keychain – provided by platform vendors, to sync and sign in to 1Password itself with passkeys.

We're bringing forward this innovation as a way to better protect your data. Unlike passwords, you can’t create a weak passkey. Passkeys are generated by your device using a public-private key pair, which makes them strong and unique by default. Passkeys can’t be phished like a traditional password – this makes them resistant to social engineering scams.

The attack that you mentioned would require that a malicious actor has access to both your physical device as well as that device's passcode. To help guard against such an attack I recommend that you:

  1. Use Face ID or Touch ID to unlock your device when in public so that eavesdroppers can't spy on you entering your device passcode.
  2. Set a strong passcode, you don't need to use a simple PIN but can choose a strong custom alphanumeric code: Set a passcode on iPhone - Apple Support (CA)

When passkey unlock is introduced for 1Password accounts, it will be an option and not the only way to use 1Password. If your personal threat model requires that you stick with an account password and Secret Key to unlock 1Password then you'll be able to do so.

I hope that helps! 🙂

-Dave

[edit: Spelling and grammar]

prime
primeAuthor
July 8, 2023

@1P_Dave

The attack that you mentioned would require that a malicious actor has access to both your physical device as well as that device's passcode.

That’s my concern. Let’s say I had a 6 digit pin and someone saw me put that in, and then took my phone. The attacker had my phone, my 6 digit PIN, so wouldn’t he have access to my passkey that unlocks 1Password and able to get into my 1Password? I feel like my iPhones password is now weak link in this new set up.

I have a long alphanumeric password, but then again, in the new passkey set up, that’s protecting my 1Password.

XIII
July 8, 2023

Will I be able to use both a passkey and a (physical) security key (back up) to unlock my 1Password account?

1P_Dave
1Password Employee
July 10, 2023

@XIII

Passkeys can provide the same level of security as password + two-factor authentication, with a lot less friction. It isn’t necessary to use a separate multi-factor authentication solution on top of a passkey. Passkeys cannot be remotely phished, socially engineered, or leaked. Those are the threats that two-factor authentication was designed to protect against.

If you'd like to continue using an account password, Secret Key, and your security key then you'll be able to continue to do so rather than using a passkey to unlock 1Password.

-Dave

July 20, 2023

If I do the following:

  1. Lock my phone while 1password is unlocked and running in the background.
  2. Block my face and unlock my phone using the passcode.
  3. Reset Face ID using the passcode.
  4. Set up Face ID.
  5. Bring 1password to the foreground

1password is still unlocked.

Do I have something configured incorrectly or is there a way to force 1password to lock when I unlock the phone using the passcode?

OK, I think I figured out how to make this work.

It looks like 1password "Auto-lock on Exit" needs to be set to Immediately.

@1P_Dave Does this sound correct?

July 20, 2023

To answer the way above question.
Does anyone know whether a hardware key with apple 2FA prevents reseting Apple ID with just a trusted device?
I know this is off topic, but to answer your question.
If you lose both keys–or they’re stolen, broken, or destroyed–you can still rely on trusted devices to regain account access or remove keys and enroll new ones. However, if you can’t use your security keys and lose access to all trusted devices, your Apple ID account will likely be unavailable forever.

July 21, 2023

I think that it is very concerning that Apple's implementation of passkeys authentication in iOS falls back to Passcode after a few failed attempts using FaceID / TouchID.

While having a complex Passcode and using these biometrics to unlock the iPhone reduces the risk of being a victim through shoulder surfing, it doesn't help when muggers coerce a person to hand over their iPhone and to reveal their Passcode at knifepoint.
This is happening nowadays, where muggers use the Passcode to log the victim out of other Apple devices they might have and change their Apple ID password.

And now with Passkeys, they can also authenticate into any services which the victim has configured to sign into using Apple passkeys.

For that reason, I consider very risky to configure 1Password to be unlocked using Passkeys on iOS. I know this it not mandatory as you wrote, @1P_Dave, but I think that most iOS users are probably not aware of this risk, and 1Password could probably highlight it.

Also, Apple really should, in my opinion, give iPhone users the option to specify that they don't want to allow the Passcode to be used to authenticate Passkeys (and also not to allow it to be used to change the Apple ID password).

Any thoughts on this, @1P_Dave?

XIII
July 21, 2023

@1P_Dave No need to convince me about passkeys; I’m going to use them everywhere I can (and stored in 1Password).

With possibly 1 exception: my 1Password account, since that passkey will have to reside in iCloud Keychain. While the chance is small that I lose my iPhone, iPad, and MacBook in the same event, it is not zero. A passkey would still be my preferred way of logging in to 1Password, but I would like to have an analog backup (like the current Rescue Kit).

prime
primeAuthor
July 22, 2023

@XIII

my 1Password account, since that passkey will have to reside in iCloud Keychain

And that’s my original point. If it’s in iCloud and someone, somehow saw my iPhone password to get into it, they will have access to my 1Password if they take my iPhone (like in the links in my original post).