5 ms·
You can create a separate user and use a Yubikey to gate access to it, so access would be through your primary 1Password account (where the pass is stored) + Yu
by phphphphp 5y ago
You can create a separate user and use a Yubikey to gate access to it, so access would be through your primary 1Password account (where the pass is stored) + Yubikey. I have multiple accounts to separate things out that shouldn’t cross pollinate.
A 1Password feature for it would be neat but I think you’d end up in a situation where there was always risk that the primary account could be used to gain access to the sub account in some way. I’d argue the best way to tackle this would be to assume 1Password itself is an attack vector and have an encryption key stored on a separate device and so what is stored in 1Password is encrypted (by you) can only be decrypted with your physical key.
Basically, if you can’t trust your digital self, you definitely can’t trust 1Password.
- thebean11 5y ago> have an encryption key stored on a separate device and so what is stored in 1Password is encrypted (by you) can only be decrypted with your physical key. I think this is basically what I want, where my whole account is encrypted using my 1pass master password, and then a subset of it is also protected by my YubiKey. I can definitely do this manually, but it's a pretty huge pain. I wish it was built in to the desktop client. I'm not really worried about 1Password being malicious; I'd believe them if they said the client was doing all this client side and not storing the additional password.