Protect what matters β even after you're gone. Make a plan for your digital legacy today.
Forum Discussion
security1010
5 months agoOccasional Contributor
Possible to confirm an unlink action
Hi From what I understand the recommend practice if unauthorised access occurs is change master password, unlink accounts and regenerate a secret key. But if that unauthorised device is offline ...
1P_Dave
Moderator
5 months agoHello security1010β! π
Thank you for the suggestion! Unlinking a device is a great tool to use if a device you donβt recognize has signed in to your 1Password account. Once you unlink a device, it will be unlinked the next time that the app or browser extension on that device is able to connect to the 1Password service.
So for some piece of mind (in that most stressful of moments) in that worse case once unlink is clicked is there way to see if it was successful?
Can you tell me a little more about the threat model that you're seeking to protect against? When you install the 1Password app on a device, that app maintains a local cache of your encrypted items. If someone finds your account password and is able to unlock 1Password on that device, they can just copy that encrypted cache to another machine, keep it offline, and open it there.
Unlinking a device prevents an attacker from accessing your account going forward. But if an attacker already gained access to the 1Password app, it won't prevent them from using the information that they've already found there if they copy it somewhere else before you unlink the app. In those cases, it's recommended that you unlink any unknown devices and then rotate your credentials by changing the passwords for your accounts.
-Dave