It’s Cybersecurity Awareness Month! Join our interactive training session, or learn about security and AI from 1Password experts.
Forum Discussion
prime
3 years agoDedicated Contributor
Passkey and unlocking 1Password with it (biometrics) in iPhones
In this blog post, it shows how we can log into 1Password without a password, and using our biometrics/device. Correct me if I am wrong... So the Passkey for my 1Password account is tired to my iPhon...
Former Member
3 years agoI think that it is very concerning that Apple's implementation of passkeys authentication in iOS falls back to Passcode after a few failed attempts using FaceID / TouchID.
While having a complex Passcode and using these biometrics to unlock the iPhone reduces the risk of being a victim through shoulder surfing, it doesn't help when muggers coerce a person to hand over their iPhone and to reveal their Passcode at knifepoint.
This is happening nowadays, where muggers use the Passcode to log the victim out of other Apple devices they might have and change their Apple ID password.
And now with Passkeys, they can also authenticate into any services which the victim has configured to sign into using Apple passkeys.
For that reason, I consider very risky to configure 1Password to be unlocked using Passkeys on iOS. I know this it not mandatory as you wrote, 1P_Dave, but I think that most iOS users are probably not aware of this risk, and 1Password could probably highlight it.
Also, Apple really should, in my opinion, give iPhone users the option to specify that they don't want to allow the Passcode to be used to authenticate Passkeys (and also not to allow it to be used to change the Apple ID password).
Any thoughts on this, 1P_Dave?