Protect what matters ā even after you're gone. Make a plan for your digital legacy today.
Forum Discussion
Former Member
2 years ago1Password Access after Death, Legacy Contacts
I am not planning to die anytime soon, but sometimes things happen.
Beyond securing my 1Password details in an Escrow account, or with a lawyer, or in a bank lockbox, does 1Password offer any means of allowing one or more designated member of the 1Password Families account to access the 1Password account in case of the primary owner's passing?
Apple now offers the ability to add one or more https://support.apple.com/en-us/102631 so that in case of your untimely demise, an Access Key and a Death Certificate allows Apple to grant the holder of both of these to get a new Apple ID that has access to your Apple ID Account.
It may be something 1Password wants to consider, though I realize that reviewing Death Certificates may not be on the high list of priorities for the team!
1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser: Not Provided
134 Replies
- DjerossNew Contributor
I may add, this has been requested for many many many many many... years now.
It's really disappointing and hard to believe that nothing has been done to definitely solve this matter.
I'm even considering to pay for a premium bitwarden account, just to store credentials for my 1P account and take advantage of their "Trusted emergency contacts".
Or maybe I should just pay this premium account to... use it instead of 1P completely ?
Let's see what happens in the next months. - GSKOccasional Contributor
Yes... Completely agree with Djeross. As morbid as it may sound, I have moved everything over to Bitwarden mostly for this reason.
- DjerossNew Contributor
This is one of the most critical features to add. I don't want to store my password anywhere, or entrust anyone.
The bitwarden way of doing things is, for now, the best way I've seen.
Hope this will get implemented soon.
Regards. - 1P_Tommy
Moderator
1Password does not have such an option at this time. Who knows in time we may. It is something I would like to see. Recovery codes are the best suggestion at this time. That's in addition to the account recovery option from the family organizer.
- dragon1Dedicated Contributor
After reading all the posts I'm asking myself what all the answers and the 'recovery code for familiy members' has to do with the topic???
Isn't he asking for something easy Bitwarden is offering for a long time...
A family member dies > I will request to access his data (if he allowed it) > I do get the chance to by waiting an amount of time > if he does not refuse the request (death, serious illness or something else) I do get access.
This is something different than a recovery code you're talking about.
- 1P_Tommy
Moderator
Thanks folks I submitted the feature request. I really hope this is something we can excel at at after all passwords are very much a digital legacy.
- lopincOccasional Contributor
Former Member I understand your point, but I would argue that printing all that information is insecure in its own right, especially if a recovery code now negates the need for the combined 1P password+security key. Any future LP breach can be mitigated by changing the # of rounds of encryption cyphers used to a high and random 6-7 digit number, which I've done, as well as change all of the passwords contained within it (which I would have had to do anyway whether I moved to 1P or not). At this point, my encrypted LP vault is more secure out in the open than all those codes put on paper, and I get the benefit of true emergency access. Pro's and con's and to each their own.
But again, the whole point of this is that all 1P has to do to win my business is to implement a feature that apparently many people are asking for and their competition already has. Their move.
- Former Member
Well my solution is to use LP until 1P implements it. :)
The history of security breaches of LastPass is a knockout criterion for LastPass. Even if it provides some very valuable feature, the service is simply not secure. It cannot be used, if you really value security. If I had been an LP customer, I would have canceled and deleted my account the day their last big breach became public a year and a half ago. No matter their shiny user interface.The two workarounds 1Password provides by either printing emergency kit, password and mfa qr code or printing the recovery code and ensure you're not losing email access by also printing the email password and email mfa QR code of that might seem tedious, but this will work.
The problem is that the password service must distinguish the rightful owner of an account from an attacker who attempts account recovery using stolen information to gain access to the account. Today, common account recovery is performed by still having some secret, while other secrets have been lost or compromised. Legacy access for your heirs is no different. It's required the service distinguishes your heirs from some attacker who gained the same information that's available to your heirs.
- thedeanFrequent Contributor
Yes, you can put your current 2FA seed directly into 1Password and use it the same way you would use any other authenticator app (like Google, LastPass, Microsoft, etc.). I prefer it over other apps, because 1Password will auto-fill both my password and my 2FA code for me --- all hands free. You can find the documentation here: https://support.1password.com/one-time-passwords.
If LastPass works for you, that's great. I dropped LastPass when they got hacked. There is risk in every decision we make. We all have to make our own personal choice about where we land on the risk/reward curve.
Dean
- lopincOccasional Contributor
thedean what do you mean by a "plug-compatible" authenticator? Do you mean you're putting the 2FA seed in the vault?
In the way that LP implements it, you have a pre-defined amount of time to deny the emergency access request (x hours/days/weeks) that you can set before access is granted so that if the request for access isn't legit, you can deny it, so trust isn't an issue.
Well my solution is to use LP until 1P implements it. :)