Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This comment is pretty misleading. You're making it sound like they advocated for using the same master password for all accounts, while the post you linked (#2) is about changing 1P (since 8.x) to NOT unlock all accounts with one master password/biometric. (1P<=7.x behavior)

The OP in that thread is complaining that he has to unlock each account separately with its own password. That response is a suggestion to mitigate password fatigue with multiple accounts and restore the same functionality as 1P7.

And as @gmemstr said, each 1Password Account also has a randomized "account key" mixed with your master password, making password stuffing attacks impossible. Your account key is given at signup and manually saved by the user. If you want to add a new device, you need to pull the key from an enrolled device or wherever you wrote it down.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: