1password 6 Catalina



1Password works best on the latest version of macOS.

  • 1Password 7 requires macOS High Sierra 10.13 or later.
  • 1Password 6 requires OS X Yosemite 10.10 or later.
  • 1Password 4 requires OS X Mountain Lion 10.8 or later.

Feature-specific requirements:

CleanMyMac X 4.6.9 1Password 7 v7.6 Parallels Desktop Business Edition v15.1.4 (47270) Luminar 4.3.0 (7031)!!!! Do not update these applications to avoid losing their functionality. MacOS Catalina 10.15.6 (19G73) Mac App Store Installer Release year: July 15, 2020 Version: 10.15.6 (19G73) Platform: Intel only.

  • There is an incompatibility between 1Password 7.4 and Royal TSX v.4.2. We have already identified the issue and have created a fix for it. This fix is already included in the latest beta version which was released yesterday!
  • I would need to purchase 2 new licenses, one for me and one for my wife. We both share the same 1Password vault, using Dropbox, on 2 different computers. 1Password 6 still works great even on Catalina and iOS 14.
FeatureRequirements
1Password accounts1Password 6.6 or later
Touch ID1Password 6.5.1 or later
MacBook Pro with Touch Bar or MacBook Air 2018 or newer
macOS 10.13 or later
Unlock using Apple Watch1Password 7.7 or later
Apple Watch with watchOS 6 or later
A Mac with a Secure Enclave
macOS 10.15 or later
Two-factor authentication1Password 6.8 or later
Duo multi-factor authentication1Password 7 or later
Markdown formatting1Password 7 or later

1Password works best on the latest version of iOS.

  • 1Password 7 requires iOS 12.2 or later.
  • 1Password 6 requires iOS 9.3 or later.
  • 1Password 5 requires iOS 8 or later.
  • 1Password 4 requires iOS 6 or later.

Feature-specific requirements:

FeatureRequirements
1Password accounts1Password 7 or later
AutoFill1Password 7.2 or later
1Password extension1Password 5 or later
Touch ID1Password 5 or later
Touch ID-enabled device
Face ID1Password 7 or later
iPhone or iPad Pro
Two-factor authentication
Duo multi-factor authentication
1Password 7.0.6 or later
YubiKey1Password 7.6.2 or later
A device compatible with YubiKey 5 NFC, YubiKey 5C NFC, or YubiKey 5Ci
Apple WatchwatchOS 4 or later

1Password works best on the latest version of Windows.

1Password requires Windows 10 or later and Microsoft .NET 4.7.2 or later.

Feature-specific requirements:

FeatureRequirements
1Password accounts1Password 7 or later
Two-factor authentication
Duo multi-factor authentication
1Password 7 or later

1Password works best on the latest version of Android.

1Password requires Android 5 (Lollipop) or later.

1password 6 Macos Catalina

Feature-specific requirements:

FeatureRequirements
1Password accounts1Password 6.5 or later
Filling in apps and browsersAndroid 5 or later
Biometric UnlockFingerprint: Android 6 or later
Face or eyes: Android 10 or later
Security key1Password 7.4 or later
Android 7 or later
Split-screen modeAndroid 7 or later
Two-factor authentication
Duo multi-factor authentication
1Password 7 or later

I recommend regularly that people use some sort of password-management system that lets them set hard-to-crack passwords (whether short and complicated or long and easy to remember) uniquely for every site and service, and also lets them fill in those passwords everywhere they need to.

Lowell Nelson emailed me a few weeks ago wondering why I’m so hot on third-party options, like 1Password, Dashlane, and LastPass, when Apple has a robust, multiplatform solution of its own that includes synchronization: Keychain. (Keychain more specifically describes the OS X part, while iCloud Keychain allows synchronization across devices and use with iOS.)

It’s a terrific question, and I prefer not telling people to buy into a paid service (whether a one-time fee or a subscription) unless the utility of that utility is so high that it outweighs the cost.

Let’s look through the details. Since I have tested and studied 1Password and LastPass extensively, I use them as the basis of comparison. You should be able to find answers to each of the points below in the FAQs or feature descriptions for any sufficiently robust alternative.

While Apple’s Keychain, 1Password, and LastPass can all store other sorts of data securely, passwords are the most reliable element that can used across a whole ecosystem and across platforms.

How secure is your data?

A password “safe” needs to keep the passwords, well, safe, in three major areas:

  • Data at rest on a device. Passwords should be secure on a device against anyone but the owner gaining access.

  • Data stored on servers. It should be difficult or impossible for an attacker to access and decrypt cloud-stored passwords.

  • Data in transit while being synchronized or to and from Web-based access. Strong encryption should prevent a snooper from unscrambling new entries, retrievals, and updates, as well as interactive sessions.

Keychain and iCloud Keychain are pretty dang robust in these regards. OS X and iOS have to be unlocked to fill Keychain entries, and OS X’s Keychain Access app requires an administrative or user password to unlock and view passwords. With Touch ID or a passcode in iOS and FileVault 2 in OS X, passwords are highly secure as well when you’re shut down (OS X) or locked (iOS). iCloud Keychain uses device-based encryption which prevents Apple from being able to (or being compelled to) decrypt your passwords.

1Password and LastPass use an “expensive” passphrase encryption method for your locally stored databases, so that even if someone gets ahold of them, a cracker can only brute-force password attempts at a very, very slow rate. LastPass tested this unintentionally after a hack: no reports emerged of any password vaults being unlocked.

LastPass syncs everything through its servers, but encrypts with keys known only to users. 1Password syncs via Dropbox and other cloud-based services (relying on their security and encryption-at-rest methods) as well as through its add-on subscriptions for sharing with family or team members, but it locks everything with user-owned keys.

LastPass and the team or family options for 1Password also give you access via a Web browser, and use browser-based decryption instead of native client software; the companies don’t possess your keys. However, there is a weakness in relying on the browser. Malware and other browser-based exploits make browsers much more vulnerable relative to the level of security available through native apps and cloud sync. Safari flaws in iOS and OS X are discovered regularly (though very few are seen in the wild), and you might be tempted to access your passwords from an unfamiliar machine running another OS.

How easy is the system to use?

A password system has to be easily invokable. If it’s not, you won’t use it consistently, because that’s human nature. Worse, if you’re installing it for someone else to improve their security, they may be unlikely to use it at all if it’s not a constant reminder and superbly straightforward.

Keychain is used largely by Apple as a way to remember passwords for specific fields on webpages, and to store passwords for an automatic retrieval and bypass in its software (like AirPort Admin in OS) or with third-party software that uses Apple’s Keychain hooks. In mobile and desktop Safari, Keychain works very well, from suggesting a strong password, to storing it, to making it possible to pull it back up or use other stored alternatives.

1password 6 Catalina Version

But while it’s broadly useful in OS X, as more developers have adopted it and there’s Keychain Access for direct lookups and retrieval, in iOS you have to drill down to Settings > Safari > Passwords to view, edit, or (swipe all the way to the bottom) add passwords. Further, you can’t invoke Keychain in Apple’s non-Web login dialogs, making it useless for common purposes. And while you can make up a password when you need one, it’s awkward to get to and can only be retrieved easily on a corresponding Web page.

Apple’s addition of extensions starting in iOS 8 allows 1Password, LastPass, and other tools to be invoked in Safari and other apps. Many iOS apps I use are tied directly into 1Password’s API that allows direct invocation. In the worst case, I can switch to LastPass or 1Password to find the password, copy it, and then switch back to the app and paste it in.

You can also use the app to create strong passwords that are retained on creation, synced automatically, and copied to the clipboard to use in other apps.

Catalina

The cross-platform situation is much worse. Apple doesn’t make iCloud Keychain available outside its own operating systems. 1Password and LastPass (and other apps) are available across a broad variety of major platforms, plus they have browser-based access (by default with LastPass and as a subscription option with 1Password).

1password 6 Pc

iCloud Keychain has no mechanism of sharing with other people—part of the ongoing narrative I’ve been discussing for years about how Apple doesn’t designs its systems from the ground up to recognize that people work in groups and as families. (Let’s not get started on the issues with Family Sharing.)

1password 6 Download Mac

Most password systems have some mechanism to share secrets with others who have accounts. 1Password allows direct transmission without a subscription or, more recently, selectively shared access among members of business and family groups. LastPass, because items are centrally stored, has offered this for years.

Choosing between them

If you’re almost entirely using passwords only on websites, only using iOS and OS X, and don’t mind memorizing and typing in passwords demanded by Apple for its services, Keychain with iCloud Keychain fits the bill. If not all those conditions match, a password-management system is worth the investment.

1password 6 Safari Catalina

Update: An earlier version of this story said iOS didn’t provide access to stored passwords or a way to create new ones. It does; it’s just buried in Settings.