Getting started with 1Password for your growing team, or refining your setup? Our Secured Success quickstart guide is for you.
Forum Discussion
security1010
2 months agoOccasional Contributor
Game Over Scenarios - What To Do in Breach
Hi, Going through some paranoia I’ve been running through some “what if” scenarios about 1Password and figuring out: How stressed I should be in each case What to actually do if it happens He...
AJCxZ0
2 months agoBronze Expert
Risk assessments are fun and contingency planning can be useful for peace of mind even when threats remain hypothetical. A detailed assessment of each case would be a lot of work, so I'll pick a couple of cases.
The mobile device snatched the very moment that you unlocked the 1Password app or a rubber hose exploit would expose all your secrets, however the chance that the snatch happens during the window in which the app is unlocked is small, and the chance that the snatcher will be in a position (and motivated and able) to exploit the opportunity during the unlock window is even smaller; that is unless the snatch was orchestrated for this purpose, in which case you are probably up against an adversary for which generic advice won't help much.
Wiping the device and changing your 1Password and maybe some critical service credentials from another device would be wise as a precaution, followed by a close watch of evidence of access to valuable accounts.
What to do in the case of a Category 3 scenario probably depends more on the circumstances in which the revelation occurred. A trusted family member finding your Emergency Kit in the filing cabinet is very different from Mr. Robot putting a keylogger on your device(s).