Cryptographic Compliance: 1Password Resolves Hardware Token Configuration Disparity
ID: ae8f7fff-0499-51a1-ae72-b19622e004cb
STIX ID: report--ae8f7fff-0499-51a1-ae72-b19622e004cb
Feed Name: securityonline.info
A researcher reported that 1Password's desktop application allowed hardware security tokens (e.g., YubiKey) to be used without enforcing the token PIN during instantiation, which the researcher viewed as a security vulnerability. 1Password considered the behavior a configuration oversight, declined a standard bug bounty, and will implement hardware token PIN verification in the desktop client in a planned July 2026 update, aligning it with the existing browser-extension behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
