Not prompted for 2FA when login from browser
I set up 2FA with hardware keys (Yubikeys) many moons ago, as well as with an Authenticator app, and these have worked previously when logging into the 1Password app either on my Macbook or iPhone. In other words, I have previously been prompted, upon login, to present a 2FA. However, today I logged into my 1Password account via browser and was asked for the password only with no prompt for the 2FA of any kind. I just entered my password and was in. Logging out from that same browser session did not make a difference; upon the next attempt to log in, I was again NOT prompted for 2FA.
I went into Manage Two-Factor Authentication screen and indeed all four of the expected 2nd factors are listed. Additionally, for all but one of the clients/sessions listed under 'Linked to your account', I am given the option to 'Require 2FA on next sign-in' , but not for the web browser session in question (which is the one currently logged in).
What step needs to be taken to ensure that 2FA is required when logging in via web browser, every time?
FWIW, the browser is Brave. https://brave.com/latest/
Thank you.
Thanks for the reply. 1Password is only designed to be used on a device that you trust and that is free of malware. The second-factor is used to authenticate your account on that device when you first sign into the account but after that the device is considered trusted and linked to your account. If you choose to sign in to your 1Password account on a device then an attacker with access to that device, and who knows your account password, will be able to access both your items as well as account management tools.
The concern is, now that 1Password has deemed the hardware second factor is no longer needed because it has chosen its own locally stored copy of encrypted 1Password data to be the only 2nd factor required for login
The locally stored data isn't a second factor, it's an stored session that you've authenticated using your account credentials along with your second factor. It sounds like you might be look for the following option:
If you click this option then you'll be prompted for your account information, along with 2FA, each time that you access your data on 1Password.com.Alternatively, you might wish to take a look at our passkey unlock beta. You can store the passkey used to unlock 1Password on a physical security key and use that to unlock 1Password each time: Add additional passkeys or security keys (Note: passkey unlock for 1Password is currently only available in beta and requires creating a new test account.)
-Dave