[Feature Request] Freeze Private Vault on Deletion from Family Account instead of full deletion
I just discovered that if the family organizer deletes a member of their family, that family member immediately loses everything in their private vault. I can see a lot of posts in the forum here on this topic dating back to 2016, but as I'm kinda in shock at this I wanted to make another one to emphasise that this needs to change.
There are two major ways this creates security and safety issues:
Many family accounts are run by tech-savvy people who give 1Password to their not-as-tech-savvy family members. It's recommended that you have at least 2 family organizers in a family, for obvious recovery reasons. However, if one of those people is not-as-tech-savvy, and doesn't quite have the same operational security as their partner, it creates a giant hole in the system if malware gets into their device/device is stolen/heck, even person clicking around accidentally has happened before.
Weaponizing the account deletion in case of divorce/break-up. It's very easy to see a controlling partner hitting that delete button in revenge during a family separation. We know partners have done worse things. The loss of literally your entire life with one click because your partner is mad is a really big and uncomfortable security risk. This also disproportionally affects women and at-risk minorities (this could also affect kids in family accounts - plenty of posts around the internet of kids finding themselves locked out of their devices because their parents are controlling for whatever reason).
I worked for a business that used 1Password Business, and I had the "free family account" while I worked there. When I left, as advertised, the account became "frozen but vaguely accessible and exportable" until I paid for my own subscription. The technology is already there! Why can't it be applied to family account user deletions? Simply freeze the private vault and say "you've been kicked out of the family, pay or export", just like Business!
Even after typing all this I'm still really surprised that this is how that deletion button works. I'm now terrified of even looking at the users in my Family account, and also kinda scared about my partner's family organizer permissions. +1 to the long-standing feature request, please!
1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser: Not Provided
Comments
-
I've filed your feedback verbatim for the teams review. Thank you for sharing. I would like to see this for my own needs where I could spin my kids account off to their own.
ref: 40644700
0