Posts

Tips & Tricks: 1Password 5.1 for iOS

1Pi iOS 7 icon 1521Password 5.1 for iOS is now up in the App Store, and it sports some great new stuff based on your feedback. In fact, there’s enough for a bulleted list not much unlike this:

  • Touch ID now has 42% more touch, 27% more ID – We simplified our Auto-Lock settings for your Master Password and Touch ID to be clearer. Give Settings > Security a look.
  • Tags go mobile – Need more than folders? Folders just not your thing? Now you can add tags to items on iOS. Sub-tip: they’re comma separated.
  • iPhone 6- and 6-Plus-ified – Better graphics, even richer icons, and other tweaks for iPhone 6 and 6 Plus owners.
  • Custom keyboard control – Third-party keyboards are a big thing in iOS 8, but they don’t need to be in your 1Password (in short, some of them can transmit what you type to servers for, ideally, useful text-in-the-cloud stuff). We disable them by default, but you can turn them on in Settings > Advanced.

We hope you enjoy! If you get a minute, please spread some of your review magic in the App Store. They really do help!

Touching on security and convenience

I remember watching Craig Federighi introduce the Touch ID API at WWDC this year. I remember thinking he was speaking directly to me, that Touch ID was clearly meant for 1Password. The next day, I ran out to buy an iPhone 5S, downloaded the new Xcode and iOS 8 betas, and added Touch ID to 1Password that night.

I remember how excited I felt the first time I was able to successfully unlock 1Password with Touch ID. Unlocking 1Password would never be the same.

Security and Convenience

A password manager is a combination of two occasionally conflicting concepts: Security & Convenience. First and foremost, a password manager must keep your data secure. But it also needs to give you quick, convenient access to your data.

The addition of Touch ID allowed us to take a huge step forward in convenience without sacrificing security.

Touch ID does not replace your Master Password. After unlocking with your Master Password, you can enable Touch ID. Once enabled, 1Password will present the Touch ID prompt instead of asking for the Master Password, allowing you to unlock using your fingerprint. Your data is always encrypted with your Master Password.

Thanks to Touch ID, you can now have the security of a strong, complicated Master Password with the convenience of unlocking with a fingerprint.

Turning on Touch ID

1P 5.0 iOS security settingsTurning on Touch ID in 1Password 5.0 is as simple as tapping Settings > Security and flipping the Touch ID switch.

When enabled, you can specify a “Request Fingerprint After” timeout, also known as an Auto-Lock timeout. This timeout sets how long 1Password is inactive before locking.

Those with sharp eyes may also notice a second timeout for the Master Password as well. Read on further to see how we are simplifying this for 1Password 5.1.

Now let’s take a quick look at how Touch ID was added to 1Password and what’s happening underneath the hood.

Adding Touch ID to 1Password

1P iOS Touch ID promptAdding Touch ID to 1Password started out as quite a simple task. The challenge was determining how to use Touch ID to access your 1Password data.

Apple’s Local Authentication framework made it easy to authorize a fingerprint, but the result is a simple success or fail. 1Password, however, needs your Master Password to decrypt your data after a successful authorization. To make this possible, 1Password stores your Master Password in the iOS Keychain when Touch ID is enabled.

Your Master Password is the most important password you have, and we take many precautions to keep it secure.

The iOS Keychain provides a way to store your Master Password in a secure place that only 1Password can access. The iOS Keychain item that contains your Master Password is never synced to other devices or backed up to iTunes or iCloud. It is also aggressively removed from the keychain whenever Touch ID authorization fails or if Touch ID or the device Passcode are disabled.

I hope this helps explain how Touch ID and your Master Password work in tandem to provide convenient, secure access to your data. Now, let’s talk about why adding Touch ID to 1Password turned out to be not quite so simple after all.

Improving Touch ID

1P 5.1 iOS Security settingsI had an awesome time adding Touch ID to 1Password and was overwhelmed by the hugely positive feedback that we received (no really, there was a ton of it). But it turns out that, instead of Touch ID, many people were seeing Master Password prompts far too often.

First, there was an issue in my code that caused the Master Password to be required at times instead of Touch ID. I’m happy to say this has been fixed in 1Password 5.1, which is strolling through App Store review and should be out soon.

In many cases though, the Master Password prompt was showing up in 5.0 exactly when it should, at least according to our confusing settings—we had Auto-Lock inactivity timeouts for both the Master Password and Touch ID.

In fact, even I had trouble explaining how the “Request After” and “Request Fingerprint After” settings worked together. After explaining (unsuccessfully) to so many people, I knew something had to change.

Starting in 1Password 5.1, there will be a single Auto-Lock timeout that works for both.

Auto-Lock specifies how long 1Password will wait before it locks automatically. To unlock 1Password again, you can use your fingerprint if Touch ID is enabled, otherwise enter your Master Password. Your Master Password will be required after a device restart or when Touch ID authentication fails.

Combined with Lock on Exit, this gives you a great deal of control over when, and how, 1Password locks.

Until Next Time

Touch ID has made a big difference in how I use 1Password and my phone in general. I hope it has for you as well, and yes—I can’t wait until Touch ID enabled iPads are available!

I do worry that Touch ID will make things so convenient that people will forget their Master Password. I’m tossing around the idea of requiring your Master Password once every 14 days or so. I’d love to hear your thoughts in the comments.

On iOS 8, App Extensions, OS X Yosemite, and 1Password

iOS 8 App Extensions iconHonestly, we’d like to exclaim from atop Yosemite’s cliffs about our excitement for the other Yosemite, iOS 8, and all the incredible things Apple announced during WWDC 2014’s opening keynote.

But the great news is we’re actually here, in San Francisco, to learn first-hand about all this amazing new stuff straight from Apple (though the not-so-great news is we’ll have to hold off on the road trip)! If you’re in the area and see us around, we love to meet fellow developers and our amazing customers—be sure to say hi!

iOS 8 App Extensions, Touch ID opening up, and what this all could mean for 1Password

By now you may have heard about App Extensions, one of the many, many new features Apple announced is coming to iOS 8 in the fall. In short, App Extensions allow third-party apps to plug into other apps, including Apple’s own.

iOS extensions

Combine that with Apple’s announcement that Touch ID is also opening up to third-party developers, and you can see why we were doing Snoopy dances in our keynote seats. Then pile on other great new stuff like user-installable keyboards, OS-wide support for third-party cloud storage, Spotlight improvements, and… well, you can see we have a lot of dancing to do. Then, we have a lot of research and testing to do.

This all is incredibly exciting, and we are looking into the delectable possibilities these features might be able to unlock for 1Password. Might.

Right now, we have nothing to announce since we learned of all this awesomeness at the same time as you. We still need to explore the actual capabilities of these features and whether we can even use them.

As soon as we can say more about whether iOS 8’s HomeKit features will let 1Password turn off your lights and lock your front door along with your vault, we’ll exclaim it from atop our blog here, Twitter, Facebook, and our newsletter!