Is my vault vulnerable to remote attack/malware if i leave it unlocked in whilst at the computer?

hardtofin
hardtofin
Community Member

I understand about locking my vault when i step away from the computer, but if i am at my computer for an entire work day, unlock the vault in the morning so all my passwords can be easily entered throughout the day without having to re-enter my master password (i.e the vault is left unlocked in the background), are my passwords more at risk than if i locked the vault after every single time i entered a password?

Thanks


1Password Version: 7.9.1
Extension Version: Not Provided
OS Version: MacOs 12

Comments

  • ag_ana
    ag_ana
    1Password Alumni

    Hi @hardtofin!

    It is riskier, yes (that is why 1Password has auto-lock settings) since your data is decrypted when 1Password is unlocked, but you need to balance the timeout I think. Locking 1Password every single time you use it would make your experience quite painful in my opinion. It depends on how at risk your computer is, but I would leave at least some minutes before auto-lock becomes enabled.

  • hardtofin
    hardtofin
    Community Member
    edited November 2021

    Thank you. The problem is i am at the computer for sometimes 10 hours straight.
    As far as I can see there is no option for the vault to autolock in this circumstance. It will only lock if the computer actually becomes idle. Is there an autolock after 5 mins even if i am still using the computer option or something?

    Also, a couple more questions whilst you are here please.

    1). Is it possible to make a new vault with it's own master password so that someone gaining access to my vault wouldn't be able to open the second vault?

    2). Is it safe to store my master password in another family members vault in case of something happening to me?

    3) Is my secret key redundant if i have a family member who is able to restore my account via the 1password site?

  • ag_ana
    ag_ana
    1Password Alumni

    @hardtofin:

    As far as I can see there is no option for the vault to autolock in this circumstance. It will only lock if the computer actually becomes idle. Is there an autolock after 5 mins even if i am still using the computer option or something?

    The closes setting would be Lock when the main window is closed under 1Password for Mac > Preferences > Security tab, but I am not aware of a setting to automatically lock while you are still using the computer at this moment.

    1). Is it possible to make a new vault with it's own master password so that someone gaining access to my vault wouldn't be able to open the second vault?

    Not a new vault, this would only be possible with a separate 1Password account, with its own Master Password:

    How to use multiple accounts

    2). Is it safe to store my master password in another family members vault in case of something happening to me?

    Yes, we do something similar by adding the Emergency Kit document directly in a Shared vault, so other family members also have access to the Secret Key if necessary :+1:

  • hardtofin
    hardtofin
    Community Member

    Is my secret key redundant if i have a family member who is able to restore my account via the 1password site?

  • ag_ana
    ag_ana
    1Password Alumni

    @hardtofin:

    The Secret Key is useful so you don't have to recover your account in the first place. But if another family member can recover your account, they wouldn't need the Master Password either, only access to your email address to receive the email message to begin the recovery.

  • hardtofin
    hardtofin
    Community Member

    Thank you ever so much for your help ag_ana!

  • ag_ana
    ag_ana
    1Password Alumni

    You are very much @hardtofin! If you have any other questions, please feel free to reach out anytime.

    Have a wonderful day :)

This discussion has been closed.