Protect what matters – even after you're gone. Make a plan for your digital legacy today.
Forum Discussion
AlmoEnd
3 years agoDedicated Contributor
Continuous reprompt Windows Hello
They prompt reads: "You need to enter your account password before you can use Windows hello" but it seems to me that this shouldn't pop up every single time I launch the last pass excuse me one pass...
Former Member
3 years agoThat is, it bespeaks something like: "if anybody else can use Hello on your computer to log in as you, then they will have full access to your Vault" which makes (to me) zero sense.
The warning that comes with the TPM was that a malicious app could gain access to 1Password information.
You always have to weight risk against convenience. 1Password as vendor must warn about every possibility, no matter the probability, that exists to break in. They don't write: "times this happened in the past is one for 100000 users", thus probability 0.00001% for each user. Unfortunately, it's difficult to rate such warnings: is some warning significant for my own user profile? How significant?
For example, as single person with the occasional visit of a friend in my household with a stationary desktop computer and a mobile I have a completely different risk profile than a family whose children often brings friends into the house, and whose members carry laptops with them all the time to every place they visit. And additionally, I am an IT person who can assess software better and sense malware, while the children of said family might install everything that pops up on some webpage.
So you always need to take warnings with some grain and assess your personal use case.
For example, I opened my desktop computer and 1Password very much for convenience. 1Password will not lock automatically, and neither my computer. I disabled timeouts and automatic locking. However, if I leave the house, I lock my computer manually. Or if I have guests I don't completely trust, I lock 1Password and/or the computer manually. Or just switch off the computer. This requires discipline, of course, to not forget to lock. However, I was trained to manually lock devices by my company (it's policy that no PC must be accessible if there is no person in front of it) to lock whenever I stand up from my chair. It's just WIN-L to press, very easy. So if someone foreign enters the household and I am about to leave the room, WIN-L.
A laptop I carry gets a different configuration, of course. That would definitely get a timeout, because out of house it can be lost or stolen any moment without me able to press WIN-L.