I just setup a new computer and was surprised to find out that I didn't need to authenticate 1Password with an existing device/Secret Key because I also signed in to iCloud on the new computer. I am guessing that 1Password Family accounts are storing account-specific information in iCloud instead of device-specific. Is this the case? I was initially not a fan of the subscription/cloud-based direction that 1Password went years ago, but was assured that a new device could not gain access to my 1Password data unless I confirmed it with my Secret Key.
Now that I know an attacker could gain access on a new device with ONLY a compromised iCloud account password, I am a bit weary.
1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser:_ Not Provided
Comments
Team Member
Hi @CGDaveMac,
Do you currently have any Standalone vaults synced with iCloud/Dropbox? A subscription account cannot be accessed on a new device without your Secret Key/Setup Code.
No I do not. I setup a new MacBook and was able to access all subscription account information without the key which is why I posted this.
Team Member
@CGDaveMac thanks for letting me know. Not sure what's happening, but we'll have someone from our team look into this. Please send an email to [email protected] with a brief description of the issue, and be sure to include the following:
You should receive an automated reply from our BitBot assistant with a Support ID number (eg. ABC-12345-123).
Thanks so much. :)