Forum Discussion
I was about to email mailto:passwordless@1password.com about this. Glad prime brought it up. I've been following 1Password's passkeys blog/emails since last year, and throughout that time, this issue was not clear to me. I concur with @luisneto's suggestion to 1P_Dave that 1Password should highlight this shortcoming in Apple's security envelope, as it related to securing our vaults.
1P_Dave, is there no way for 1Password to serve as the "hardware" on Apple devices, rather than simply the storage for the passkey? I trust 1Password any day over Apple's "masses over security" approach.
I've been telling people to refrain from using passkeys until there's clarification on this, so it's good to know. Apple's glib responses to WSJ articles have been concerning. Their most recent security additions show where their focus lies (with careless rather than responsible users):
- "Recovery Key," like passwords, can also be changed (and enabled) with the passcode and makes it nearly impossible for theft victims to access their accounts.
- "Account Recovery Contact," helps people who forget their password and passcode, by allowing them to request a code from a trusted contact.
If this is at all unclear to us, the beta-using technophiles on your forums, I think it's unlikely that everyday users will spare 1Password blame when Apple's poor policies get them locked out of their account, and suddenly they lose everything in their 1Password vault also.