Forum Discussion

security1010's avatar
security1010
Occasional Contributor
5 months ago

Possible to confirm an unlink action

Hi

From what I understand the recommend practice if unauthorised access occurs is change master password, unlink accounts and regenerate a secret key. 

But if that unauthorised device is offline none of the above would make a difference right?

So for some piece of mind (in that most stressful of moments) in that worse case once unlink is clicked is there way to see if it was successful?

3 Replies

  • security1010's avatar
    security1010
    Occasional Contributor

    Thanks1P_Dave​ 

    I guess I’m likely overthinking and trying to play through through too many scenarios.

    but it feels like unlinking provides value in notification about where it’s in use rather than being able to actually unlink (as you mentioned it needs to see 1Password services to the trigger to unlock).

  • Hello security1010​! 👋

    Thank you for the suggestion! Unlinking a device is a great tool to use if a device you don’t recognize has signed in to your 1Password account. Once you unlink a device, it will be unlinked the next time that the app or browser extension on that device is able to connect to the 1Password service. 

    So for some piece of mind (in that most stressful of moments) in that worse case once unlink is clicked is there way to see if it was successful?

    Can you tell me a little more about the threat model that you're seeking to protect against? When you install the 1Password app on a device, that app maintains a local cache of your encrypted items. If someone finds your account password and is able to unlock 1Password on that device, they can just copy that encrypted cache to another machine, keep it offline, and open it there. 

    Unlinking a device prevents an attacker from accessing your account going forward. But if an attacker already gained access to the 1Password app, it won't prevent them from using the information that they've already found there if they copy it somewhere else before you unlink the app. In those cases, it's recommended that you unlink any unknown devices and then rotate your credentials by changing the passwords for your accounts. 

    -Dave