Autofill silently fails if no longer signed in
With 1Password 8 on Android you need to enter the password to your vaults once every two weeks. This is fine, except that when it needs you to do it, instead of asking for it, it just fails to fill the password in a website.
Current behavior:
- browse to website like google or paypal or w/e
- go to the login page
- keyboard shows the matching logins from my vault (great)
- tap login on the keyboard suggestion
- grey overlay appears and quickly disappears
- no password has been autofilled
Expected behavior:
- browse to website
- go to the login page
- keyboard shows me matching logins from my vault
- tap login on the keyboard suggestion
- ask me to unlock my vault
- fill the password.
One possible workaround for this would be for 1Password 8 to notify me that my vault(s) have been locked and ask me to unlock them again. This way I won't ever be in the situation in which the vaults are no longer accessible :)
It would also be great if I could "refresh" the duration for all my vaults at once by being prompted for all the accounts that are linked on my phone so that it's just once every two weeks, and not once every week :)
1Password Version: 8.9.3
Extension Version: Not Provided
OS Version: Andoird 12 security patch 5th of july 2022
Browser:_ Firefox mobile
Comments
-
Hi @fhbc, thanks for sharing this with us.
- grey overlay appears and quickly disappears
That definitely would be unexpected behavior. If the set Require password interval has ended that grey overlay should allow you to enter your account password to fill as you mentioned. I've shared this with the team so we can look into reproducing and resolving any issue.
In this situation you should be able to open 1Password for Android directly to "refresh" the Require password interval then return to the site or app to continue filling. If that's not the case, let me know!
I did want to note that with version 8.9.3 and newer, we've included the option to set the Require password interval to 14 days, 30 days or never when Biometric unlock is in use. You can find this setting under Settings > Security.
We have some ongoing discussions internally about how to enhance the available lock options. You've touched on one that we are looking in to. That would be an option to set a Require password interval but have a sign in on any device reset the interval rather than having separate intervals on each device. I don't have any details to share regarding when or if that option will be implemented but I've shared your thoughts with the team. Thanks again!
0 -
Hi @ag_timothy, thanks for getting back to me!
I did want to note that with version 8.9.3 and newer, we've included the option to set the Require password interval to 14 days, 30 days or never when Biometric unlock is in use. You can find this setting under Settings > Security.
Oh, that's good to know, thanks!
That would be an option to set a Require password interval but have a sign in on any device reset the interval rather than having separate intervals on each device.
That sounds like a decent solution, but it might just be easier to set a timed notification to trigger when the interval is set to (almost) expire, that way the user kan keep the interval (and the security of having to re-authenticate periodically) :)
0 -
Hi @fhbc, thanks for following up and expanding on your suggestion. Part of our drive with the lock options has been to balance convenience, security and helping to ensure people don't get locked out of their data by forgetting their password. I've revised my notes to better capture what you shared here for feedback. Thanks again!
0