To protect your privacy: email us with billing or account questions instead of posting here.

Feature Request: Opt out of Account Recovery

Options
poorfuse7
poorfuse7
Community Member
edited November 2019 in Memberships

Account Recovery is a dangerous feature if you want to team collaborate without trusting the administrator.

If the administrator is centrally managing emails, the administrator can initiate the recovery himself and view the master password reset emails that are sent to the user. Even if the administrator is not malicious, the same situation can occur due to threats, fraud, and email system attacks.

To prevent this, I propose an Account Recovery opt-out feature.

When opting out, access from 1Password employees, law enforcement agencies, etc. must be prevented.

The Dashlane implementation is a good reference.

https://support.dashlane.com/hc/en-us/articles/115005111905-Zero-Knowledge-Account-Recovery-for-Dashlane-Business

It is also a good mechanism to allow recovery requests and recovery only from the device, not email.

Please improve according to this.

Thank you.

Comments

  • Ben
    Options

    Hi @poorfuse7

    Thanks for the suggestion. :+1: We don't currently have any plans to change this, but I'll pass the feedback along to our development team for their consideration. We do discuss the risks associated with the design of recovery in the "recovery risks" section (pg. 40) of our 1Password Security Design White Paper, along with some recommendations on mitigating those risks.

    Ben

  • poorfuse7
    poorfuse7
    Community Member
    Options

    Thank you for your sincere reply.

    The current best practice seems to be to set up each mail service that users trust.

    I will wait patiently.

  • ag_ana
    ag_ana
    1Password Alumni
    Options

    @poorfuse7, on behalf of Ben, you are very welcome!

    Have a wonderful day :)

This discussion has been closed.