Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That feature only exists on family/team accounts, and in that case the account that is allowed to perform recoveries has an escrow of the vault passwords of other team members.

1Password themselves don't hold these keys.



But it's possible to authorize a new account to perform recoveries of vaults created before. So there must be a way of distributing the escrow.

My point is not so much to throw 1Password under the bus (I'm a happy user), but I'd be curious to see a description of how this works.


The user who currently holds escrow can distribute those recovery keys to other accounts in that family/team/enterprise. This is why 1Password SaaS forces you to have at least one account admin (aka the user with recovery keys). If you somehow have 0 account admins, creating a recovery key -- without full decryption access to a vault, aka, user still knows their password & account key -- is impossible.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: