Forum Discussion

paulvbk's avatar
paulvbk
Occasional Contributor
2 hours ago

You should prevent users to register a passkey for 1Password account with the 1Password app

My friend is using Bitwarden and we were talking about securing our password managers account with a passkey. I learned from him that Bitwarden prevent their users to register a passkey for their Bitwarden account (so when your are on the bitwarden website I guess) and I tried it on the 1Password website.

As you can see I successfully registered both a TOTP and a passkey for my 1Password account and was able to easily (maybe too easily ??) store them in my 1Password vault.

If your using 1Password as your main TOTP authenticator app for all your accounts, I guess having the 1Password TOTP inside 1Password is useful for quick access when you want to Set up a 2nd or 3rd device when you still have access to the 1st one. But it feels to me like this is dangerous and can lead to users being blocked out of their vault, and even more dangerous when doing this with a passkey.

Am I wrong ?

Thanks in advance for any insights in this !

 

No RepliesBe the first to reply