Skip to main content
May 6, 2022
Question

Security with "Use the Trusted Platform Module with Windows Hello"

  • May 6, 2022
  • 27 replies
  • 6676 views

When using "Use the Trusted Platform Module with Windows Hello", 1Password prompts with a security warning.

- How can another app gain access to 1Password with this setting?
- Is there a way to retrieve the applications which have access to Windows Hello?

Thanks


1Password Version: 8.7.0
Extension Version: 2.2.3
OS Version: Windows 10 21H2

27 replies

ag_mike_d
1Password Employee
1Password Employee
May 12, 2022

Hello @kapsiR, I'm sorry for the delay in response. I'm happy to help with your questions.

We have an article on our support page that discusses Windows Hello security in 1Password for Windows. This same article goes on to discuss more information if you are using the Trusted Platform Module with Windows Hello.

Is there a way to retrieve the applications which have access to Windows Hello?

I'm unsure if it possible to retrieve a list of applications specific to your device that have access Windows Hello. If this is an area of concern, it would be worth reaching out to Microsoft support for help or to see if this is possible.

I hope this helps!

kapsiRAuthor
May 12, 2022

Thanks for the response, my concerns are especially about that sentence:

A malicious application could prompt you to unlock 1Password to access your information.

So why is this possible? Do you have resources about that?

ag_mike_d
1Password Employee
1Password Employee
May 12, 2022

Hello again @kapsiR, thanks for getting back to us.

With regard to this warning when you enable TPM support, 1Password loses control over what can prompt you to access the key 1Password creates on the TPM. As noted in the article I provided, "1Password delegates the responsibility of authentication to Windows Hello."

Without the TPM option enabled, Windows Hello stays within our process so any phishing attempts by a malicious process wouldn’t work. However with Enhanced Windows Hello, a malicious process can potentially trick you into accepting a context-less prompt in order to decrypt your data. We've included the above prompt to have the user confirm that they know the risks and that you trust other apps on your system which generate their own Windows Hello prompts. The key itself is safe in the actual TPM, its just a concern when logged into Windows.

As far as I understand, we'll have some additional resources about this in the future, but it’s not ready just yet.

kapsiRAuthor
May 12, 2022

Thanks for the detailed explanation - it's much clearer now.

So the secret is stored on the TPM - anyone with a Windows Hello prompt authenticates against the whole TPM?
And I assume there is no way to have an additional entropy when prompting via Windows Hello to make this a little harder for attackers? 😄

1P_PeterG
Community Manager
Community Manager
May 19, 2022

Hi @kapsiR, thanks for these questions.

There is no way to have additional secret entropy added in, since Windows doesn’t provide a secure place to store data that only our app can fetch (akin to the macOS keychain, for example).

Assuming you haven't downloaded any malicious apps (which are the chief threat for this scenario), and you only accept TPM-backed Hello prompts (i.e. the ambiguous one where it doesn't specify the app unlocking it) when you expect there to be one, there's no substantial risk.

To add a bit more detail: NCrypt / Windows Hello wrap and control all access to the underlying Hello device. So therefore any userland software can make the same requests as another app. We provide the message you mentioned in order to notify the user that control is shifting to the TPM / Hello in a different way than it does when just using Hello with 1Password alone, and that you should trust the apps on your device if you want to enable this feature.

kapsiRAuthor
May 19, 2022

Thanks very much! I appreciate the detailed explanation!

Jack_P_1P
1Password Employee
1Password Employee
May 19, 2022

Hi @kapsiR:

On behalf of Peter, you're very welcome!

Jack

October 14, 2022

Hello!

I recently installed Windows 11 by using a method to bypass requirements for a supported CPU and a TPM module.

After installing 1Password on the new installation, I discovered that using Windows Hello PIN would be a really convenient method to unlock 1Password.

However, I have concerns about the security of this, since my computer doesn't have a TPM module at all (not even v1).

Am I still safe to use Windows Hello with 1Password? How is the security ensured in this case?

Thanks, I love 1Password very much.

ag_mike_d
1Password Employee
1Password Employee
October 17, 2022

Hello @ForgottenPasswords,

Thanks for your reaching out with your question about Windows Hello and 1Password. I've included a link to a related articles about Windows Hello security in 1Password for Windows.

If you'd like to enable Windows Hello, you can follow this guide: Use Windows Hello to unlock 1Password on your Windows PC

We appreciate your kind words about 1Password! 💙

October 17, 2022

If your computer doesn't have a TPM, Windows emulates some of its functionality in software. With a hardware TPM, things like the secret to unlock 1Password survives a reboot, so you can unlock 1Password after a reboot with just your Hello pin. With the software emulation, such stuff is kept in protected CPU memory only, so you need to enter your 1Password master password once to unlock after a reboot. Additional unlocks are with PIN, since the secret to unlock is kept in memory - until next reboot. What survives a reboot even with the software emulation is the ability to login to Windows itself.