Skip to main content
prime
June 18, 2023
Question

Passkey and unlocking 1Password with it (biometrics) in iPhones

  • June 18, 2023
  • 22 replies
  • 1796 views

In this blog post, it shows how we can log into 1Password without a password, and using our biometrics/device. Correct me if I am wrong... So the Passkey for my 1Password account is tired to my iPhone (assuming in the passkey area of my iPhone). With the issue of people having their iPhone stolen and they are locked out, is this a bad idea? If someone gets my iPhone, has my passcode for my iPhone, wouldn't the attacker have access to my 1Password then?

I know the work around to protect my iPhone, but not all do this. my iPhone password is also alphanumeric, not just 6 digits.


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser:_ Not Provided

22 replies

prime
primeAuthor
July 30, 2023

Would be prompted for appleid email (assume they know this and enter it)

All the person has to do is open the email app and look for emails sent by Apple.

I’m not as worried, my passcode is over 15 characters long and if Face ID fails and I have to put it in, I do it so no one can see me.

I’m more worried about my parents, in-laws, kids, and others who just use a 6 digit PIN for their iPhone password after I tell them it’s not a good idea.

August 1, 2023

Like @prime, I'm less worried for myself than for others. I'm also less concerned about violent theft, as there's only so much I can expect from Apple. A duress/honeypot passcode would be nice, but would confuse the masses. And Apple doesn't like offering options for advanced users.

That said, just for @steven1, theft rings have surveilled victims. So I'd add to your warnings that you should turn in a circle as you enter the passcode, so they can't catch the entire thing.

It's wild to me that Apple doesn't even confirm on your connected Watch when someone within BT range tries to change your password! This could all easily be fixed, but they choose not to. So I'll use 1Password to store my passkeys and use the old method to access 1Password.