As with any password manager, it relies on AES-256-bit encryption. 1Password uses a two-secret-key security model, meaning two encryption keys are required to unlock your passwords. One key is your master password, which 1Password never sees or stores. The other is a device key generated based on the hardware and software specifications when you add a new device to your account.
Like other tools, 1Password includes a security dashboard, called “Watchtower,” where you can see weak, reused, and old passwords. It also features a section for potentially dangerous websites.
Watchtower has become more responsive. Enable “Check for vulnerable passwords” in the settings and you’ll receive real-time alerts, directly on the login page, if the site in question has suffered an active data breach. This in-page notification prompts you to change your password immediately, rather than waiting for a later report in the dashboard.
Mac users gain a notable simplification: the Safari extension can unlock with Touch ID without requiring the desktop app. Previously, Touch ID required the main app to be installed. Now, the extension can operate autonomously while still syncing with the app if you use it.
Like many password managers, 1Password uses a “zero-knowledge” model, meaning your master password is never stored on their servers. As a result, you cannot reset your master password if you forget it. If that happens, 1Password offers an account recovery option, but it’s not as intuitive as LastPass’s, for example. Everything begins at account creation: you must download an emergency kit. It contains your second secret key, your email address, and a place where you can write your master password. It’s recommended to store this document in a safe vault like… KeePass.
This emergency kit also includes a QR code, which you can scan with the 1Password apps to automatically authenticate your account. It’s an excellent way to recover your account, but remember to keep it in a safe and external storage.