Getting started with 1Password for your growing team, or refining your setup? Our Secured Success quickstart guide is for you.
Forum Discussion
Former Member
5 years agoSecret key in clear text in C:\Users\<username>\AppData\Local\1Password\1password.sqlite
1Password v8 seem to store its local data in C:\Users<user>\AppData\Local\1Password\1password.sqlite.
With any sqlite client, it's dead easy to extract the secret key(s) of your account(s) with an ...
Fooligan
5 years agoDedicated Contributor
That is interesting. I was also able to locate mine in ~/.config/1Password/1password.sqlite (Ubuntu 20.04, perm: 0600). But, I don't think that this is specific to 1P8. I am assuming there might be a technical limitation that the secret key cant be encrypted at rest?
From the docs: https://support.1password.com/secret-key-security/#how-your-secret-key-protects-you
Like your Master Password, your Secret Key is never sent to us. But because you can’t memorize your Secret Key, 1Password stores copies of it for you, so you can:
Unlock 1Password without entering your Secret Key every time. It’s stored in the 1Password apps and browsers you’ve used to sign in to your account on 1Password.com.
Have peace of mind if you lose a device. Encrypted copies of your Secret Key are stored in your device backups and keychains to provide data loss protection. If you have iCloud Keychain turned on and lose your Mac, iPhone, or iPad, you can restore from a backup and unlock 1Password with just your Master Password. It’s the same for Android backups.
I think this is a deliberate trade-off for convenience. But, if your home directory is accessible by others in your workgroup or gets hacked, then it looks like you are only protected by your master password. In that case, you should probably regenerate your secret key.
cc: @jpgoldberg