6 ms·
This. 1Password comes with limitations but by far it’s the best password manager for teams due to the built in 2fa support. I wish it was possible to share a c
by webo 7y ago
This. 1Password comes with limitations but by far it’s the best password manager for teams due to the built in 2fa support.
I wish it was possible to share a credential with specific people without a need to create a dedicated vault.
- ac2u 7y agoI love 1password but I don't understand why you'd use it for 2fa. Surely if someone gains access to your 1password account you're just giving them the "something you have" aspect of 2fa for free ?
- davismwfl 7y agoI understand what you are saying but part of security is making it easy enough that people will use it, but hard enough it isn't easy to break for bad actors. People are lazy in general, if you tell 25 engineers at a startup they have to use two different tools just too handle credentials, the compliance rate of using 2fa will drop to nil, making accounts easier to hack. Don't get me wrong, it isn't like 2fa is so secure, it has been shown to be hackable for sure, especially when using SMS devices; but if done properly it can add a level of extra effort for a bad guy and if that extra effort is easy for engineers to use they'll do it. 1Password makes it this way. From a corporate standpoint, I don't want people using their personal devices for SMS OTP (2fa) because then if they leave, are disgruntled or get tragically hit by a bus I am locked out of a potentially important service/account. I had this happen on three accounts in the past year where one took me 3 days to recover the ability to access it, another I never could recover and we had to work around it and a third that was absolutely critical but took close to two weeks all said (lots of waiting). That is insane, and all because people used their own personal devices (or similar) for SMS 2fa. There are other devices you can use, and some enterprises do use hardware keys in addition to the password which works well and the more sensitive the system the more inconvenience people will tolerate and understand. For me it boils down to 1Password works good for a reasonable price which helps startups and small companies. I also don't think using 1Password is just a tool and you still need a good password refresh cycle and to stop reuse etc. This way if a backup at 1Password was somehow compromised or stored improperly at your company or at 1Password at least you'd be insulated better. It definitely does provide a single point of access that if compromised in a way which bypasses all their security a lot of companies will be hurting.
- e_proxus 7y agoIn addition to the arguments outlined above, it protects against some attack vectors. If the service gets hacked and the password leaked or they discover the password in some other way, they still don't have the 2FA token and so can't login.
- snuxoll 7y agoIf somebody breaks into a specific service and is able to dump hashed passwords it’s very likely they also had access to TOTP keys. Since you’re already using a password manager you should be protected from password reuse. Ultimately in this case you are protected from MITM attacks and basic forms of keylogging.
- tialaramex 7y agoNot relevant to scenarios where you stash TOTP long term secrets in a password store, but note that WebAuthn / FIDO doesn't have this problem - the data you're keeping per user to authenticate with WebAuthn isn't a secret, it's not even personally identifiable, a bad guy could add their own credentials if they have write access, but they can't learn anything by examining yours.
- tzs 7y ago> From a corporate standpoint, I don't want people using their personal devices for SMS OTP (2fa) because then if they leave, are disgruntled or get tragically hit by a bus I am locked out of a potentially important service/account. I had this happen on three accounts in the past year where one took me 3 days to recover the ability to access it, another I never could recover and we had to work around it and a third that was absolutely critical but took close to two weeks all said (lots of waiting) Wait...I've seen two ways for services to handle multiple users from a client using the same account. 1. A company using the service gets a single user login for their account. That login is shared by all of the employees who use the service. 2. A company using the service starts out with a single user login for the account. That login is meant to only be used to administer the account. The administrator can create more user logins for the account, usually with reduced privileges. Each employee is given a separate login of their own, with just the privileges needed to do their job. I don't think I've seen a #1 that uses 2FA. I assumed that was because it could then easily run into the problem you describe. With #2 there is no problem using 2FA, or with each user using their own device for 2FA. The only account you have make sure won't be lost if someone gets hit by a bus is the administrator account. Did you run into a service using approach #1 but that used SMS OTP?
- Ductapemaster 7y agoThe argument I've seen provided for this is that an attacker would both need your password and physical access to a device with 1password already set up on it. To use 1password on a new device, you need a "secret key" that is provided to you when you create your account which serves as a basic form of 2FA for your whole account. Not a perfect system, but it is not as simple as just getting your password and having access to everything.
- dclusin 7y ago1password is a cloud service. So they'd either need a device like you said or your login/password + authentication key that is only used in the initial setup flow of a new device. So still pretty hard like you said. Never considered how the extra key during new device setup could be helpful until now.
- flamtap 7y agoYou can also set up 1PW to use a OTP itself. I use 1PW for OTP generation and for passwords (naturally), but my 1Password account itself is protected by my password + secret key, as well as an authenticator/OTP app that is not 1PW.
- FateOfNations 7y agoThe "secret key" is of sufficient length to not to be able to qualify as "something you know". It's either a quite lengthy string you have to type in, or a QR code.
- rolltiide 7y agoI just stopped called it 2fa, and just otp for “one time password”, the URI standard calls it otp:// as well see problem solved, no need to debate how single or two factor a thing is and you can just focus on the attack vectors it actually still solves for, objectively yes the password vault is a single point of failure if someone knows your vault password or key logs it.
- urda 7y agoIf an attacker has gained access to your vault you have much, much more to worry about than if 2FA codes are there or not.
- ac2u 7y agoIt's certainly a panic but if everything is 2FA'd with tokens that the attacker doesn't have access to, then you've done a lot to mitigate the splash damage and have a path to regain control.
- flamtap 7y agoI don't use 1PW for teams, but I do use it personally and use it to store all my OTPs except my OTP credential to access 1Password itself. I use a different authenticator app for that (happens to be Microsoft, but that doesn't matter really). So, while I think it storing storing your passwords beside your OTP generator isn't great, if both are locked behind another factor of authentication, you have mitigated that risk significantly.
- Justsignedup 7y agoThere are still good reasons: 1password requires more than just a password to access. You need the encryption key. It acts nicely for that purpose. 2fa is unnecessary if you're generating 20 character passwords uniquely for every site. The best security is like the best camera. There is no better camera than the one you actually use. This is why cell phone cameras are the best. This is why 1password is the best, because it is security you always use and always keep safe.
- webo 7y agoIt’s not very trivial to gain access to a 1password account: 1. Attacker needs access to the physical device of the account holder if they know the credentials. 2. Otherwise, they need to know credentials + secret key on a new device. 3. You can set up Google Auth to access the account in the first place, which can have its own separate 2fa (this is what we do)
- developer2 7y agoI have to spam another comment here to suggest that Bitwarden also has built-in two-factor auth. $10/year (not per month) for personal use, and I believe it's included for $3/month/user in the enterprise version. Cheaper than 1Password, and a better overall app imo.
- satysin 7y agoI am a Bitwarden user (three years paying for premium) and while I like it the desktop app isn't as feature rich or as smooth to use as 1Password imho. It lacks biometrics support for one which is something I wish they would add but I believe as it is an Electron app they cannot do so, at least not on macOS. The iOS and Android apps are decent enough though. They support Touch/FaceID and the Android equivalents. With the exception that the iOS app has "Live Sync" (i.e. push notifications to sync the vault when a change is made elsewhere) but they never work. I recently made a post about this on the Bitwarden support reddit [0] but had no response from the developer there or on Twitter which is a shame. Live Sync works fine on Android though so it is clearly an iOS issue only. If 1Password were cheaper, or if my needs were more complex, I would switch away from Bitwarden but as a home user it is "good enough". [0] https://old.reddit.com/r/Bitwarden/comments/f1besd/has_live_sync_ever_worked_for_anyone_on_ios/ https://old.reddit.com/r/Bitwarden/comments/f1besd/has_live_...
- frozen_memory 7y agoI don't agree. When compared to other offerings (LastPass, BitWarden) 1password consistently comes up short in enterprise features. 1password doesn't even have an API. Three of the biggest issues I have with 1password: 1. If a user fails (or skips) 2FA, they still retain complete access to any passwords/vaults they previously locally synced... they just can't sync new/updated entries. This seems like a really flawed design - a 2FA failure should prevent access. When I asked the 1password team whether they'd consider invalidating local cache on 2FA failure, they did not seem interested. 2. You can't create links to passwords, which would allow management of an entry from a single location. If you want to share a password across multiple teams/vaults, you need to know about and maintain those entries for the same account, which means you also have to have access to all those vaults to manage that entry. This discourages password rotation, and increases the likelihood of orphaned passwords in other vaults. 3. Lack of granular permissions structure. You can't, for example, allow a user to initiate vault resets without giving them full admin access to the entire thing. Again, other password managers allow more fine-grained control. To me, 1password feels like a small-time solution that tried to bolt on some enterprise features to retain customers. I don't think it should be considered enterprise software.
- notlukesky 7y agoWhat do you exactly mean by share a credential without a vault? Share access without sharing the password etc?? If so SAASPASS has a sharing center for both password-based, 2FA protected email-based and Authenticator code-based sharing of access. https://m.youtube.com/watch?v=i31RMUMuX2U https://m.youtube.com/watch?v=i31RMUMuX2U