If you’re not familiar with 1Password, you need your secret key (generated by 1Password upon account setup) and your master password (generated by you) to setup 1Password on a new device. So if I gave you my master password, you still couldn’t access my data on your device without the secret key.
Why would 1Password store the secret key in the vault by default? If my computer was ever compromised, I’m thinking the thief’s could easily take my secret key and have free reign over my account on another device.
If you use 1Password, do you recommend removing the secret key from the vault, or is it somehow not necessary because I’m missing something?
[link] [comments]