Getting started with 1Password for your growing team, or refining your setup? Our Secured Success quickstart guide is for you.
Forum Discussion
Former Member
3 years agoIs 1Password Still Safe If iPhone + Passcode Gets Stolen?
Hello!
I am considering getting 1password families but am curious about 1 specific scenario. Saw a scary wall street journal article recently about how your entire digital life can be sent into chaos if someone happens to both steal your phone (lets say from a bar) and they know your iPhone pin code (because they were spying on you in the bar where your phone gets stolen). If a user happens to be able to steal your iPhone + Pin code will that also give them access to your 1Password vault on the iPhone?
https://www.wsj.com/articles/apple-iphone-security-theft-passcode-data-privacya-basic-iphone-feature-helps-criminals-steal-your-digital-life-cbf14b1a
1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser:_ Not Provided
3 Replies
- 1P_Dave
Moderator
Hello @fastrhythm! 👋
Thank you for the question! As danco mentioned, 1Password isn't unlocked by your iPhone's device passcode unless you deliberately turn on passcode code unlock. If passcode unlock is turned off then the 1Password app can only be unlocked using either your account password or Face ID / Touch ID (if you've enabled biometric unlock).
You can have both the 1Password app, and the 1Password for Safari browser extension, lock faster by changing your auto-lock settings:
- How to set 1Password for iOS to lock automatically
- Change how quickly 1Password for Safari requires reauthorization
Regarding the specific attack that you mentioned, the attacker would need both of the following:
- Possession of your iPhone.
- Knowledge of your device passcode.
If you haven't already then I would recommend that you enable biometric unlock for your iPhone so that, when you're in public, you unlock using Touch ID / Face ID rather than typing in your device passcode:
For further advice on how to protect access to your iPhone itself I would reach out to Apple Support. Let me know if you have any questions. 🙂
-Dave
- AMonitorDarklySuper Contributor
A bad actor with your phone and passcode wouldn’t be able to access the 1P app directly but they would have access to the Safari auto fill functionality for anywhere from 15 minutes to 2 weeks depending on your reauthorization settings.
For example, the thief could start visiting major bank websites and see if Safari auto fills any credentials.
- dancoSuper Contributor
No. 1PW has its own password.
Also, consider using a longish alphanumeric passcode for the phone rather than a short numeric one, as that will make it much harder to steal.
Finally, is you turn on ScreenTime, which rquires a four digit passcode, this will prevent the changes that could damage your digital life.