1Password Windows authentication via Windows Hello

Options
mark24332
mark24332
Community Member

Hi there,

First of all, I really the 1PW product. Please keep up the great work, team!

Please see my question/concern below in the context of a Mac user. Privately I am using Mac and iOS/iPhone with Touch ID and Face ID to unlock 1PW. At work, we use Windows so I am using 1PW in the Chrome browsers but would like to use a similar biometric unlock for ease of use so I started looking at Windows Hello. However, there is a few concerns I have with Windows Hello in the context of 1PW. I appreciate 1PW possibly cannot solve it but still would like to view your security expert views to hopefully ease my concerns.

This is the concern/question:
I noticed that when using Windows Hello I am forced to set up a PIN. Not sure whether this is company forced or this is standard for Hello but I find it a concern because I would like to use either fingerprint or camera ID to unlock my laptop and therefore also 1PW Windows. However, the forced use of PIN makes me feel like the security level has lowered significantly because the PIN is much easier to guess/force than the alphanumeric key that is generated as result of my face (face unlock) or fingerprint unlock. I can also use the PIN to just log into the laptop after powering off. I feel this works significantly different from Mac where after power off I always require to enter the full actual password, which is much longer than the PIN.

Is there a way to deal with this?
What are you thought from a security perspective?
Is my concern valid or am I overthinking it too much?

What about an enterprise admin? Would such a person be able to unlock via Window Hello and therefore also be able to access my 1PW?

Thanks in advance. Happy 1PW user.


1Password Version: 8.10.22
Extension Version: 2.18.2
OS Version: Windows 10 Enterprise 19044.3693
Browser: Chrome

Comments