It’s Cybersecurity Awareness Month! Join our interactive training session, or learn about security and AI from 1Password experts.
Forum Discussion
Former Member
3 years agoAfter master password change on other device, able to view vault before reauthenticating on app
First time 1Password user after jumping ship from LastPass. Sorry if this has been posted before but I couldn't find anything and didn't have a lot of time to keep digging so here goes:
Setup 1...
Former Member
3 years ago@TurnerBurn, thanks for getting back to us.
While it might seem odd, we actually do allow for the prompt to be dismissed in our applications. In 1Password for Windows, for example, there is an "x" button to dismiss the prompt. The data is available, but only what is already stored on the device. Not new items will be synced until the authentication with the new account password occurs.
Every device connected to your 1Password account will have a local cache of all vault data that is encrypted with the account password + Secret Key (along with a couple of other things). Here is a similar question from another customer that has several responses from our team that better explain the syncing and the security tradeoffs: https://1password.community/discussion/101453/changed-secret-key-still-able-to-access-vault
For most positive path cases, dismissing the prompt shouldn't be much of a concern, as you're not likely to want to if you're connected to the internet and know your updated password. Since you mentioned what would happen if you lost your device, here are some additional threads and documentation that would assist you with understanding those scenarios:
* https://1password.community/discussion/101453/changed-secret-key-still-able-to-access-vault
* https://support.1password.com/lost-device/#regenerate-your-secret-key-and-deauthorize-the-lost-device