Is the security of my vault weakened if I change my master password?

Options
pdnd93
pdnd93
Community Member

There used to be guidance on the 1Password site (a couple of years ago, though I can no longer find it) that changing your master password could potentially weaken your vault's encryption... Is this still true with the addition of the encryption key? Does it matter if you have a primary vault used in the app (synced to Mac via WAN) along with several other shared vaults in a family account? I just want to understand whether I am compromising my vault by changing my master password.


1Password Version: 6.8.6 on Mac and 7.0.5 on iPhone
Extension Version: yes
OS Version: iOS and macOS High Sierra
Sync Type: WAN
Referrer: forum-search:Is the security of my vault weakened if I change my master password?

Comments

  • Lars
    Lars
    1Password Alumni
    Options

    @pdnd93 There's a few things to unpack in your question.

    First off, your local installation of 1Password for Mac will use as its Master Password the first vault you create or sync to when the app is newly installed. If you've been using 1Password for a while on your Mac, your first vault would likely have been a local (standalone) vault called Primary. If you later add a 1password.com account, 1Password for Mac will still use the Master Password for the Primary vault for unlocking. You can change this, but this is the way it works if you have a Primary vault and then add one or more 1password.com accounts.

    Is this still true with the addition of the encryption key?

    I think you might have meant the Secret Key? All 1Password vaults have always had an encryption key; that's what allows the AES256 algorithm to transform your data back and forth from unreadable ciphertext into your human-and-machine-readable 1Password data. With the launching of 1password.com accounts the Secret Key is new, and it definitely strengthens a user's overall encryption because it's a string of random alphanumeric characters equal to at least 128 bits of entropy.

    Changing your Master Password won't by itself weaken your security unless either your old Master Password or your new one is particularly weak on its own. We've got a great guide for choosing a good Master Password if you'd like to review that before you change. Are you worried your existing Master Password has been compromised? If that's the case, then I'd recommend some more-involved steps to secure your data.

  • pdnd93
    pdnd93
    Community Member
    Options

    Thanks for your reply. I just have a couple of follow-ups... Can I email 1Password directly for a more private discussion even if it may be a little slower?

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    @pdnd93: Sure thing! Shoot us an email at support@1password.com and post the Support ID you receive here if you'd like to continue the conversation via email instead. :)

  • pdnd93
    pdnd93
    Community Member
    Options

    OK, will do. Thanks!

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    :) :+1:

  • Lars
    Lars
    1Password Alumni
    Options

    @pdnd93 - Just received your email; one of us will be with you shortly.

    ref: NQZ-59257-452

  • pdnd93
    pdnd93
    Community Member
    Options

    Great! THANKS!

  • Ben
    Options

    :+1: :)

    Ben

This discussion has been closed.