It’s Cybersecurity Awareness Month! Join our interactive training session, or learn about security and AI from 1Password experts.
Forum Discussion
Former Member
4 years ago2FA - General question
I am a new 1Password user and so far very satisfied.
However, I have one question. Do I understand correctly that I only have to enter the 2FA code once per device?
But I would like to use a 2F...
Former Member
4 years agoAsking for 2fa while there is a cached copy of your vault on the device doesn't increase security, so it isn't used.
There is a long comprehensive reading about this somewhere on the 1Password website.
The short answer is this:
2fa in general protects remote web logins.
If you login first time on a new device, you provide 2fa on the website and your encrypted vaults are copied (cached) from the cloud to the device.
It isn't possible to protect local data with 2fa, because 2fa only generates the information: "authentication succeeded" or "authentication failed". If you directly access the data files without the 1Password app, you're always allowed to access the data - in encrypted form.
So if an attacker wants to steal your data, he just can take the cached copy as file from your device, without 2fa, and try to hack it anyway. The master password protects that data, because it is used directly as key to decode the data.