Remove 1Password

I feel the reason is convenience. Also the last time it was defaulted they had push back:

"Security and usability are a balance, one that we are always making tradeoffs back and forth to find the right solution. Sometimes there is no perfect solution, only the solution that works best for the most users. As I mentioned previously, it is only with user feedback that we chose to remove the prompt for the PII items that would prevent clickjacking from occurring. A change that we’ve documented in the support article under the “Identity alerts” section.”
https://socket.dev/blog/password-manager-clickjacking#:~:text=Security%20and%20usability,Identity%20alerts”%20section.

I believe their plan now is to inform their customers as quoted here:

“Since there is no comprehensive technical fix for this kind of vulnerability, our focus is on giving customers more control and ensuring they are clearly informed when autofill is happening.”
DOM-based extension clickjacking | 1Password Support .

This here below is not entirety true:

As, they have been transparent:

“At time of publication, only 1Password responded.”
https://socket.dev/blog/password-manager-clickjacking#:~:text=At%20time%20of%20publication%2C%20only%201Password%20responded.

You as a consumer don’t know what they were doing behind the scenes to figure out how to deal with this issue, the best approach to take and how to educate their consumers on why in their words there was “no comprehensive technical fix for this kind of vulnerability”.

You have every right to be as you as a customer did not get the answer you were looking for in the way you wanted or in the timely fashion you were looking for.

But that doesn’t mean everyone shares your sentiment in how 1Password handled the situation.

But that is a good thing as people who may not still fully understand can benefit from the more disgruntled customers. Who voice their concerns to help the others who are lost with this certain vulnerability. As, it make 1Password sit and think on how to approach this situation in a more informed clear manner to help teach nontechnical people the implications of the situation and to provide a optional solution.

2 Likes