Getting started with 1Password for your growing team, or refining your setup? Our Secured Success quickstart guide is for you.
Forum Discussion
wavesound
4 years agoDedicated Contributor
1Password 8 Password Multiple Password Vault Unlock
So in 1PW7, I was able to unlock all my accounts with one password. However, it looks like in 1PW8, I need to unlock each account separately. We have quite a few vaults that we share with clients and...
wavesound
4 years agoDedicated Contributor
Jack_P_1P I appreciate the response, but it just focuses on policy rather than addressing real and practical threats to the password manager.
Windows Hello, Touch ID, Face ID, and Apple Watch unlock will continue to unlock each 1Password account that has been unlocked with an account password, even if they're different. If you'd prefer to use different account passwords, unlocking them each once, and then using the biometry options available on that specific version of 1Password 8 would be your best bet.
This is the crux of the issue. It seems clear that 1Password has not been following the legal and practical developments around biometrics. Biometrics access can be compelled whereas revealing passwords cannot under recent US case law.
https://www.nacdl.org/Content/Compelled-Decryption-Primer
https://news.bloomberglaw.com/us-law-week/compelled-biometric-access-legal-under-4th-5th-amendments
https://arstechnica.com/tech-policy/2019/11/police-cant-force-child-porn-suspect-to-reveal-his-password-court-rules/
https://www.techdirt.com/2022/07/21/fbi-successfully-forced-a-criminal-suspect-to-unlock-his-wickr-account-with-his-face/
https://www.biometricupdate.com/201912/federal-state-court-rulings-on-whether-biometrics-protected-by-fifth-amendment-get-murky
We can't use biometrics with several of our customers since biometric components can never be changed/modified since they are physically traits of the user that can always unlock all accounts over a period of up to two weeks when users could be legally compelled.
Aside from the legal issues, thieves that mug users on the street are frequently forcing users to look at or use their fingerprint to unlock devices.
https://www.thetimes.co.uk/article/mugged-for-my-phone-then-locked-out-of-my-life-92kpv50x7
https://abc7chicago.com/chicago-robbery-south-loop-downtown-cellphone/1506428/
https://goalz.online/thieves-forcing-victims-to-unlock-phones-before-transferring-thousands-of-pounds-in-digital-currency/
https://bobsullivan.net/gotchas/forced-to-venmo-at-gunpoint-smartphone-crime-gets-more-violent-more-tech-y/
A quick access PIN/Token would give your customers options to address both of these issues and was previously implemented in 1Password 7 for iOS with a single failure lockout.
If an intrinsic unchangeable physical trait is acceptable, then I can't see why a single-attempt/single failure lockout PIN as implemented in 1Password 7 for iOS would not also be acceptable to unlock all vaults over the two week period that you specified.