Security: 1Password App Doesn’t Prompt For Master Password Re-Entry After Face ID Change
After resetting Face ID, 1Password correctly says that it detected a change (a new face setup via iOS settings), but then it unlocked without any further verification of Master Password.
Here’s the technical details of what happened: I changed my Face ID; I went into an app that uses Face ID; it prompted me to re-enter password, so I opened 1Password using the built-in iOS auto-fill feature; 1Password showed an alert about the Face ID change; I cancelled everything and went back to Home Screen to open 1Password fully (because if I enter my Master Password in the pop up screen first, it doesn’t “save” that I entered it once already); and then it immediately did a Face ID scan and let me in.
1Password Version: 7.8-BETA-8
Extension Version: Not Provided
OS Version: iOS 15.1 Public Beta