Multiple Vaults: secondary vault unlocks automatically

Options
2»

Comments

  • JayAreAb
    JayAreAb
    Community Member
    Options

    @Support: As a convert to 1Password I also would like to have the option of having separate passwords for separate vaults, without have to fiddle around or to implement tedious workarounds. Of course, this is just my personal preference. Perhaps you should design the system in a way which gives people the necessary options to customise their 1password experience. Like that everyone would be happy.

  • Megan
    Megan
    1Password Alumni
    Options

    Hi @JayAreAb‌

    Thanks so much for sharing your thoughts here! Unfortunately at this time re-designing the vault structure is no small feat. There's also a fine line between providing people enough customization options to help them make the best use of any program ... and overwhelming them with so many options that they don't know where to start. We're listening to your feedback though, and will take it into consideration! :)

  • peskeguy
    peskeguy
    Community Member
    Options

    I am currently trialling 1Password, and thought I'd add my feedback about this issue, because, although it is possible to workaround, it should not be so hard, and could keep me from switching to 1Password.
    I have been just using the OS X keychain for storing passwords for a long time, and I use "multiple vaults" in this setup as well, storing my less sensitive login passwords in the iCloud keychain allowing them to sync across devices and autofill quickly while browsing. Then my more sensitive passwords are stored in a different keychain file in the OS X keychain (e.g. called "Private"), which would not automatically unlock on login. After updating to yosemite there is an issue that iCloud Keychain will occasionally automatically, without any prompts to me, store the password for a login that I wanted kept separately in the "private" keychain, defeating my whole desire of keeping separate keychains that can be unlocked separately. So I'm in the market for an alternative solution.

    I decided to try out 1Password, thinking "hey, multiple vaults protected by separate passwords! exactly what I need". Then I discovered the issue identified in this thread. So I get that I can switch the order of my primary and secondary vaults, but this should not be required. Multiple vaults are described in your blog (https://blog.agilebits.com/2013/11/13/1password-tip-how-to-create-share-a-vault-with-family-or-coworkers-mac/) as a way to "conveniently use strong, unique passwords to protect all your sites, apps, and devices"
    The fact that encryption keys to secondary vaults are stored in the primary vault is not documented anywhere outside of this discussion board, at least in all the places I have looked (not in the 1Password for Mac user guide or knowledgebase, not mentioned on the agile bits blog). To my mind, that is a dangerous oversight. I am certain that there are users that are unaware that the encryption keys for all secondary vaults are stored in the primary vault and in fact believe that, as I did, and the other users on this thread did, that the two vaults are entirely separate. 1Password promises to "be as open about our data format, implementations, and design as is practical for a non-open-source product."
    But this was a failure to be open in describing the setup of the system. I believed your program operated in a way it does not, and that would have measurably changed the security of my setup. If it documented somewhere else that I am unaware of, it should be moved into one of those more common places.

    I get the reasoning "we are 1Password, not 2 or 3Password". However, I believe the program should absolutely have the option to have each vault be completely separate. I don't see why this should be technically challenging. Don't store the encryption key for secondary keychains in the primary keychain if the user elects that option. Put it in the "advanced" tab of the preferences. Simple.

  • Megan
    Megan
    1Password Alumni
    Options

    Hi @peskeguy‌

    Thanks so much for sharing your feedback here! I'll be sure to mention to our documents team that the organization of secondary vaults is something that we could explain a bit better in our user guides. :)

    As for your suggestion about separating vaults, as I mention above, re-designing the vault structure at this time would not be simple. But I'm happy to pass your thoughts along in any case.

This discussion has been closed.