Forum Discussion

LotharSchaberg's avatar
LotharSchaberg
New Contributor
5 months ago

Passkey saving gets interfered with Windows Hello

Hello everybody,

as Passkeys get more and more supported by web services, I tried to save a passkey in 1Password on Windows 11 Pro 24H2, Build 26100.4770 and 1Password Version 8.11.2.

The problem I encounter happens with both browsers on my system: Edge Browser 138.0.3351.109 and Chrome 138.0.7204.184. Both have the latest version of the 1Password browser extension installed.

The website is https://www.huk.de; an insurance company. I can login to the website with my normal credentials and get the opportunity to create a passkey. When I try to save the passkey, the 1Password browser plugin prompts me to create a new entry or update my existing entry. Of course I chose the update entry option.
Then 1Password tells my that it encountered a problem and instantly the Windows hello mechanism pops up and asks me to save the passkey in Windows hello. This is not what i want.

Then I tried the same with my iPad and the passkey gets automatically saved as a new entry in 1Password (its the only option). I am able to login with the passkey, but the URL tied to the passkey is another than the URL for Web login: https://zugang.huk-digitale-services.de

It seems that this login only works when used from my tablet, but I am not able to login under Windows in my browser.

I saw a lot of discussions from other 1Password users who have problems with 1Password and Windows Hello, too. Is there a timeline, when "the normal 1Passaword user" gets a build which works without the need to participate in Windows insider and the use of the MSIX version?

Any helpful answers are appreciated. Kind regards from Germany.

5 Replies

  • Hi Daniel,

    thanks for the detailed explanation. I chose option "b)" and made a post in the corresponding thread.

    Kind regards, Lothar

  • drossner's avatar
    drossner
    New Contributor

    Hi LotharSchaberg​,

    I may add some informal, additional information to your case. As you already discovered, "we" create passkeys to a domain that differs from the origin, as the passkey should work for all brands, like huk24.de and others.

    Having an origin that differs from the relying party is a rather new, Webauthn Level 3 feature (hits CR soon) that is currently supported by Chromium-based browsers and Safari (and on Apple devices in general). The issue is, that 1Password does not support (yet) "Related Origin Requests"; as a personal user of 1Password, I (and others) already raised this concern, e.g. here: https://www.1password.community/discussions/1password/webauthn-support-of-related-origin-requests/42002

    On Edge, 1Passwords fails due to its missing support of ROR, falling back to Windows Hello. On your iPad, 1Password seems to rely on a system implementation that supports ROR (or: 1Password does support ROR on iOS?) and creates the Passkey.

    Currently I would recommend two things:

    a) Create a second Passkey that is stored in Windows Hello, to actually use the feature (if you like)
    b) Raise your voice, that 1Password supports ROR ;)

    Cheers,
    Daniel

  • Hello Dave,

    thanks a lot for looking into my issue.

    Here is the support ticket ID number: BDH-22814-758

    P.S.: 1Password just updated to 8.11.4 - Problem still exists.

    • 1P_Dave's avatar
      1P_Dave
      Icon for Moderator rankModerator

      LotharSchaberg​ 

      Thank you for sending in the diagnostics report! One of my colleagues will send you a reply as soon as possible, please continue the conversation there. 

      -Dave

  • Hello LotharSchaberg​! đź‘‹

    I'm sorry that you ran into issues when saving a passkey for huk.de. Since the website appears to require a phone number in order to register for an account, I'm not able to test the passkey flow myself. So that I can investigate this further, can you reproduce the same issue in Chrome or Edge one more time and then I'd like to ask you to create and share a 1Password diagnostics report from 1Password in your browser:

    Send a diagnostics report (browser extension)

    Attach the diagnostics to an email message addressed to support@1password.com

    With your email please include:

    • A link to this thread: https://www.1password.community/discussions/1password/passkey-saving-gets-interfered-with-windows-hello/160225
    • Your forum username: LotharSchaberg


    You should receive an automated reply from our BitBot assistant with a Support ID number.  Please post that number here.  Thanks very much!

    -Dave