Forum Discussion

Former Member's avatar
Former Member
3 years ago

feature request

1password is great. use it on my iphone. would be nice to have a way to add extra layer of security (seconday pin maybe) so when i access HBO, Netflix, .... that works with face id, but when i access Bank of America, that requires a pin or extra step.


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser:_ Not Provided

13 Replies

  • clarino's avatar
    clarino
    Frequent Contributor

    1passquest, Wouldn't it be simpler to enable 2FA on your bank? (And don't use 1P for your 2nd factor but something like authy or a hardware token.)

  • Former Member's avatar
    Former Member

    great information. i understand the issue better now.

    so i may not be able to give the best threat model, but when i am at a busy crowded overpacked airport, and i want to open netflix, i feel better if i am not also able open my banking info without an extra step

  • Hello @1passquest! 👋

    Thank you for the suggestion! At the moment 1Password doesn't include an option to require a PIN in order to open certain items or reveal certain passwords. It's certainly an interesting idea and I'm happy to pass it along to the team. Can you tell me a little more about the particular threat model that you're trying to protect against?

    When you unlock 1Password (using your account password or biometric unlock) your data is decrypted so a determined and well-equipped attacker with access to your Mac would be able to access your information since your vault data is already unlocked and decrypted. To require a PIN after your data is already unlocked would potentially, in this case, be an example of "security theatre" where a feature claims to offer more security on a surface level but in reality doesn't actually offer more protection.

    What I personally do on my device is set the auto-lock time to a short duration so that 1Password locks after a short period of inactivity. I also have biometric unlock enabled so that I can quickly unlock 1Password without having to enter my account password. You can find guides on how to configure both auto-lock and biometric unlock here:

    -Dave