Suggestion for Passkey only access on new device, no existing device access needed
After using the new beta access, I like it but I am concerend that the recovery key not needs storage just like the secret key. It also then needs to be sent to the email address which creates a phishing and access problem
I have two suggestions - the first is for completelness and I am sure it will be thrown out, (academically I'd like to hear the argument why the first wont work but intuition says it wont). The second I am confident will work.
Keep the recovery key stored with every passkey.
If the passkey standard does not allow this then append it to the username or other field that allows it. This might invalidate all existing passkeys should be changed in future (desireable? not sure)Create a recovery key storage server.
These accounts are accessed by passkeys only. This server and accounts are independent from the 1P main accounts. The user can only store recovery keys/credentials there. Crucially recovery account will never store the main account username or email address or anything connected to the main account. The user will be able to nickname multiple recovery keys to help them remember which is which. The user will be discouraged from entering data that identifies the main account. When access to a new device is needed in the absense of an exiting device, the recovery server can be accessed by passkey. I assume that zero knowledge by 1password of the passkeys will not be possible (or this whole problem would not exist) - but this isnt an issue becuase the best 1password could see is the recovery key and not know which account it applies to. There would need to be an audited of logging etc to prevent this connection to main account being made. No email would be sent to the users email therefore meaning no phishing, snooping etc is possible
The second option allows a hardware key to have 100% passkey only access to any vault. It needs a passkey for the main vault and a passkey for new device recovery vault. The user would only need to remember their email address during the recovery process so the recovery can be applied to the correct account. (although maybe some clever programming could even take an email address from the other passkey?). Other than for connecting the recovery account to the main account (during recovery only) the email address otherwise not used
PS - the way a new device is currently implmented this looks amazing. I'd suggest using this for the current secret keys too as it makes more sense for those. Also generating random codes that are longer but not mix of caps/non caps would be easier to type inn. Apha numeric (and longer) are much quicker in my mind
1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser: Not Provided
