Hacker News new | ask | show | jobs
by conception 532 days ago
Using 1Password requires me to use one of my devices to add a device to my account.

If someone has my password and my device how will a separate app help me in this case?

Honest question as the 1password model seems to be “something you know and something you have”.

1 comments

If someone hacks 1Password, they will get access to all your accounts. Whereas if you moved TOTP off 1Password, that hacker would no longer be able to access your accounts.
If someone hacks 1Password, they get an encrypted vault. 1Password has no access to my passwords. There is no recovery mechanism without the encryption keys or a device on the account.