This is a staging forum for AgileBits, not an official support forum. Visit http://discussions.agilebits.com instead.

Locking again with numerical password

Hi guys!



After using the new version a little while I have to say that I hate typing my over 10 letter password every time I want to use 1password.



You should at least leave the option the choose between the original master password or the good old 4 number password.



I loved in the last version that I "only" had a 4 letter password and [b]then[/b] an other password to view the actual password details.



Now with a 10 letters pw I make a mistake every time I try to get my password <img src='http://forum.agilebits.com/public/style_emoticons/<#EMO_DIR#>/skype_worried.png' class='bbc_emoticon' alt=':S' />



thanksè <img src='http://forum.agilebits.com/public/style_emoticons/<#EMO_DIR#>/biggrin.png' class='bbc_emoticon' alt=':D' />

Comments

  • jhollington
    jhollington Junior Member
    edited 2012 28
    If you go into your Security settings, you can set a "Quick Unlock Code" that will be used in place of the Master Password as long as the app remains resident in the background and you haven't locked it manually. Currently, the "Auto-Lock" timeout seems to re-enforce the master password, but I've been in another thread ([url="http://forum.agilebits.com/index.php?/topic/11172-lock-settings-and-quick-unlock-code/"]http://forum.agilebi...ck-unlock-code/[/url]) that this is a bug that should be fixed in a future version. In the meantime, you can simply leave the "Auto-Lock" off and use "Lock on Exit" instead along with a Quick Unlock Code.



    Note that if iOS terminates 1Password in the background for whatever reason (usually because it needs more memory for something else), then it will go back to requesting the Master Password instead. In most cases, however, I've found this to be pretty rare if you use 1Password even a couple of times a day, at least on my iPhone 5. Your mileage may vary on older devices as they have less RAM.



    Oh, and for whatever it's worth, I have a [b]40[/b]-character alphanumeric Master Password, so I definitely understand where you're coming from. The Quick Unlock Code, however, seems to have been serving me well so far. I am entering the Master Password a bit more often than I'd like, but that's only because I'm installing new updates so often during the beta cycle <img src='http://forum.agilebits.com/public/style_emoticons/<#EMO_DIR#>/smile.png' class='bbc_emoticon' alt=':)' />
  • MikeT
    MikeT Agile Samurai
    Hi Bertrand,



    @Jhollington got it right, he has a lot of experience with this lately. <img src='http://forum.agilebits.com/public/style_emoticons/<#EMO_DIR#>/smile.png' class='bbc_emoticon' alt=':)' />



    The problem with the dual security levels (4-digit/Master Password) is that any items protected with 4-digit is just not secure enough for anybody who uses it.



    For that reason, we've gotten rid of the low security level completely, reduce the complexity with these (you don't have to decide security levels anymore) and ensuring only the master password is required to get into the data file first before you can start using the quick unlock code, so all of your items are protected by the same strong encryption technologies.



    Yes, 1Password 4 may ask for the master password more often but this is needed to make sure your data is protected at all times. Now, even with the quick unlock code, only one incorrect attempt is allowed before the app changes it to ask for the master password instead.



    One more thing, now with 1Password 4, if you change your master password, the encryption keys will sync with the rest of the devices, so they will also have the same master password as well.



    Please let me know if you have more questions.



    Thanks!
  • Question, is this master password the same as the desktop master password? If I change my master password on my iOS device, will this change be reflected on the Mac side?
  • jhollington
    jhollington Junior Member
    edited 2012 28
    The short answer is yes.



    Instead of entering the "real" Master Password only when initially setting up sync (and then having it actually [i]stored[/i] on the device -- see [url="http://forum.agilebits.com/index.php?/topic/10412-storage-of-master-password-on-ios-devices/"]http://forum.agilebi...on-ios-devices/[/url]), 1Password 4 just has you [i]use[/i] the "real" Master Password.



    Keep in mind that in many ways the "Master Password" used to get into 1Password 3.x for iOS was a misnomer. The [i]actual[/i] Master Password (used in both the desktop app and in 1Password 4 now) is what is used to actually [i]encrypt[/i] your data file (indirectly, but part of the key process nonetheless). The "Master Password" on iOS protected the data on your device after a fashion (combined with the low-security PIN), but was ultimately less secure of a solution for various reasons, not the least of which included the risk of lower-security passwords being used as well as the real Master Password being stored in a less-than-secure manner, obfuscated within the iOS Keychain but not really [i]encrypted[/i] unless iOS Data Protection is being used.



    None of this was an issue for users who have properly-secured iOS devices, but the reality is that 1Password understandably needs to provide a secure solution for the lowest common denominator, which includes the user who has NO passcode on their iPhone or iPad and therefore is not taking advantage of Data Protection for the iOS keychain.



    Personally, I still have some concerns that the use of the Master Password on iOS devices may encourage users to choose shorter and therefore less secure options for their very critical Master Passwords, but I suppose one could make the argument that if a user is going to do that, they're just as likely to do so on the desktop. However, the Quick Unlock Code seems to be working quite well for me thus far and I haven't found the requirement for a Master Password to be onerous at all, even with my extremely long one.
  • MikeT
    MikeT Agile Samurai
    @Henry, yes, changing it on your iOS device will sync the encryption keys to your desktops and other iOS devices. It is actually exactly the same one as on the desktop, so you're actually using [i]1Password[/i] now.



    If you need an official answer from us, what Jhollington just wrote is pretty much accurate.



    Let us know if you have more questions.
  • What does Lock on Exit do, and why does it have an asterisk next to it in the settings?
  • MikeT
    MikeT Agile Samurai
    Hi Henry,



    In [b]Settings > Security[/b], you'll see an asterisk next to [i]Auto-Lock[/i], it just means that [i]Lock on Exit[/i] is enabled.



    If it was disabled, the asterisk would not show up next to [i]Auto-lock[/i].



    [b]Lock on Exit[/b] means to auto-lock the app each time you leave 1Password. So if you leave 1Password to the home screen or to another app, and come back, 1Password will be locked.