Disable (hidden) Facebook Connection when Unlocking | Security/Privacy Issue
Hello.
I checked my DNS logs and see that my 1Password on my iPhone connects to Facebook ...
...when I click on the following button:
I have tested this on several websites and each time Facebook is displayed. - Why is that?
1Password Version: 7.9
Extension Version: Not Provided
OS Version: iOS 15.0.2
Comments
-
Hi @ugafta
Are you able to see what IP address is being connected to? I wonder if this is a case of the same problem we've encountered with Little Snitch and other similar tools where they're doing a reverse DNS lookup on the IP address and showing one of any variety of possible results. You can see an example of where this happened, with CloudFront, here.
1Password itself does not communicate directly with Facebook. Even in the case you had a Login item saved for Facebook and Rich Icons enabled, we use our own intermediary service for those icons rather than connecting directly to the site: https://support.1password.com/rich-icons-privacy/
You can read about the connections 1Password does make, here: https://support.1password.com/ports-domains/
Ben
0 -
Hi @ugafta
Thank you for the additional information. I've asked our security team to look into this further. I hope to have more to report soon. In the meantime could you please also check if this connection is made when you open the 1Password app itself? The button you're tapping above the keyboard is iOS's Password AutoFill feature, which 1Password can provide data to, but isn't actually 1Password itself.
Additionally, can you please check in the Settings app under Passwords > AutoFill Passwords and see if any providers other than 1Password are checked (e.g. iCloud Keychain)?
Thanks!
Ben
0 -
Hi @Ben
When I open the 1Password application itself, I get the following connections: What is in.appcenter.ms?
No other provider is enabled in the app settings under Passwords > Auto-fill passwords.
By the way, I used Chrome and Safari browsers on my iPhone to check the above connections.
Thank you for more information!
0 -
App Center is the service we use for crash reporting.
in.appcenter.ms
Provides crash report management for 1Password for Mac and iOS.(from https://support.1password.com/ports-domains/)
Visual Studio App Center | iOS, Android, Xamarin & React Native
I suspect whatever the original connection in question is, it is coming from Password AutoFill, not 1Password directly. I'd like to ask you to perform one other test though. Could you please try enabling iCloud Keychain in Passwords > AutoFill Passwords and disable 1Password there? Under those conditions does the connection appear when activating Password AutoFill above the keyboard? I've confirmed with our development team that 1Password does not connect to Facebook.
Please let me know. Thank you.
Ben
0