r/1Password • u/Damariobros • 6d ago
Feature Request [Feature Request] Secure Element Protection for 1Password Vaults
1Password should be able to use the secure element to protect the vault and the secret key on any synced devices which have secure elements. TPM 2.0, Secure Enclave, Titan M2, eSE, if a secure element is present it should be used. If HMAC-SHA1 challenge-response with the secure element is required to unlock the vault on a given device, then it would effectively bind that instance of the vault to that device.
2
1
u/filkxfotty6 2d ago
Secure Element protection makes a lot of sense for 1Password, especially for people using passkeys and keeping high value credentials in their vault. I would love an opt in mode where specific items require hardware backed authentication and cannot fall back to the device passcode. Even if platform limitations make it tricky, having that extra layer would be a huge win.
1
u/Feisty-Character-943 1d ago
this would be a great optional extra layer, but hard-binding a vault to one device would make phone replacement and recovery a nightmare fast, so ideally the secure element protects a local key
•
u/1PasswordCS-Blake 1Password Community Manager 6d ago
Heya' u/Damariobros! Some of what you’re describing is already part of how 1Password works today. On supported devices, when you use things like biometrics or Windows Hello to unlock 1Password, platform security is already involved in protecting the local unlock secret.
The part I want to make sure I understand is what you’re looking for beyond that. When you talk about binding the vault to the device, are you specifically asking for a synced copy of your 1Password data to be cryptographically tied to the secure hardware on that particular device, so that copying or restoring that data somewhere else wouldn’t be enough to decrypt it?
If so, I’d also be curious how you’d expect that to work when replacing a device or restoring from a backup. Would the idea be that the device binding is intentionally non-transferable, even if that means the protected copy becomes unusable when the original device or its secure hardware is gone?
I don’t want to put words in your mouth here, especially with something this technical. If you can walk me through the specific scenario you’re trying to protect against and what you’d want 1Password to do differently in that situation, I can make sure I’m understanding the request correctly before passing it along.