I registered a Yubikey 5c on my Macbook MacOS 10.15.3 and have 1Password 7.4.4. The key is showing

Options
gardoggie
gardoggie
Community Member

I registered a Yubikey 5c on my Macbook MacOS 10.15.3 in 1Password 7.4.4. The key is showing as registered. When I log out of 1Password and try to log back in, I plug the Yubikey in and touch it. The Master password field fills up with a bunch of dots and then it says the password is wrong and won't log me in.

I tried several times, even deregistering and started over. Same problem each time. I even tried the app version from the toolbar and had the same issue.

What am I doing wrong?

Thanks!


1Password Version: 7.4.4
Extension Version: Not Provided
OS Version: 10.15.3
Sync Type: Not Provided
Referrer: forum-search:Yubikey

Comments

  • plttn
    plttn
    Community Member
    Options

    To clarify, you registered the Yubikey as 2FA on the website? Last I checked, the desktop programs didn't have U2F support. What you're doing is just typing the YubiOTP code into the master password box and then it presses enter (which is not your master password).

  • Ben
    Options

    Hi @gardoggie

    @plttn is correct; the Yubikey is not a replacement for the Master Password. You still need to type your Master Password. :) Additionally 1Password for Mac does not support U2F, so you'll need to use TOTP for 2FA with that application when prompted (but again this does not affect/replace your Master Password).

    Ben

  • gardoggie
    gardoggie
    Community Member
    Options

    So, what does the Yubikey offer with 1Password. What functionality is available to use when I insert the Yubikey into the USB-C port when using 1Password. If it doesn't replace the Master password, what does it do? Thanks

  • plttn
    plttn
    Community Member
    Options

    The Yubikey offers U2F two factor for the webapp and the Android/iOS app. 2FA cannot handle safely decrypting, as it only can function as authentication (thus the name 2fa).

    The only way for a 2FA factor to allow for unlocking would be for 1Password to have the ability to unlock your vault by you just saying you should have access, which is completely insecure compared to only being able to unlock with the cryptographic material needed.

This discussion has been closed.