1Password Mini - Autofill without entering the masterpassword

Martin Krimp El Bein
Martin Krimp El Bein
Community Member
edited February 2014 in Mac

Hi,
first of all - thanks for such a great product. Everything went fine during installation/configuration.

I only have little question - maybe i haven't find the right configuration. I'm not sure.

I like the autofill feature (CMD+#) to login. But i always have to enter the master password. That's save - but not comfortable.
I know there is a "auto lock" feature in the preferences - but setting this to "off" is also not good - because now everybody can access my data stored at 1password and is able to delete or edit this data. Lock the program every time manually is also not comfortable.

Is the following configuration or behavior possible?

1password mini will never be locked (or it is configurable) - so that i'm always able to use autofill even if 1password is locked (main window).
In this scene - logically - 1password mini could only use to use the "auto fill" feature - nothing more.
If someone want to edit/delete a data, he have to enter the master password and edit/delete the data within the 1password main window.

IMHO this is much more comfortable and also save. So everybody can use the "auto lock after 5 Minutes" (in case you forgot to lock it manually) and is also a lot faster to use the "auto fill" for login because he will never be asked to enter the master password (if its configured)

Is this already possible? If not, do you agree with my opinion and think about it?

I'm sorry - but my english isn't good - hopefully i have described it enough to understand my idea :)

Thanks in advance

Comments

  • Hi Martin,

    If your 1Password database is unlocked and accessible in one place (mini), it can also be accessed in another (main app). Not allowing access from the main app would provide little to no security benefit. In addition, a future update will allow the editing of items within mini.

    To protect yourself from data loss due to unwanted editing of your items, backups are important. And 1Password backs up your data automatically and you can restore an old set of data if you need to.

    In terms of deleting your data, if someone had access to your computer and wanted to delete your 1Password data, it doesn't matter if 1Password is unlocked or not anyway. They could just delete your 1Password database and backups from the ~/Library/Application Support/1Password 4/ folder. To protect yourself in this case, you should have backups on another computer (if you use 1Password on another computer already, you're covered) or a cloud service.

    But in my opinion, the worst security threat is simply someone getting access and looking at my 1Password data. Leaving mini unlocked at all times would leave all my data exposed at all times, therefore would kinda defeat the purpose of 1Password.

  • Martin Krimp El Bein
    Martin Krimp El Bein
    Community Member
    edited February 2014

    Hey Jasper,

    thanks for your reply - i understand you - but all i need is a "hybrid" function of "auto lock" :)

    Do you (and others) a really happy with the actual process? i can't understand it.

    Here a scene:
    You set the "auto lock 1password" to 5 Minutes - so it locks every 5 minutes. so far so good.

    but do you surf to all your "login - pages" within this time? No! definitely not!

    to add it to propel something (hopefully the right translation for "exaggerate") ;)

    Open Facebook - entering Masterpassword - press CMD+# - logged in

    Auto-Lock of 1Password after 5 Minutes

    Open Twitter- entering Masterpassword - press CMD+# - logged in

    Auto-Lock of 1Password after 5 Minutes

    Open discussion.agilebits.com- entering Masterpassword - press CMD+# - logged in

    Auto-Lock of 1Password after 5 Minutes

    Open nfl.com- entering Masterpassword - press CMD+# - logged in

    Auto-Lock of 1Password after 5 Minutes

    Open nba.com- entering Masterpassword - press CMD+# - logged in

    Auto-Lock of 1Password after 5 Minutes

    Open ebay - entering Masterpassword - press CMD+# - logged in

    Auto-Lock of 1Password after 5 Minutes

    Open amazon- entering Masterpassword - press CMD+# - logged in

    Auto-Lock of 1Password after 5 Minutes

    Open logitech- entering Masterpassword - press CMD+# - logged in

    Auto-Lock of 1Password after 5 Minutes

    Open Sony - entering Masterpassword - press CMD+# - logged in

    Auto-Lock of 1Password after 5 Minutes

    Open Apple - entering Masterpassword - press CMD+# - logged in

    Auto-Lock of 1Password after 5 Minutes

    Open HewlettPackard- entering Masterpassword - press CMD+# - logged in
    Auto-Lock of 1Password after 5 Minutes

    and so on and on and on and on ... does this seams for you "comfortable"? Sorry, but thats a farce!

    In this case (and that is the normal behavior of users) you use the doubled time (no benefit) - because your time is killed by entering the Mainpassword each time.

    No one starts his computer - opening ALL websites he might use for the day - and logging in.

    All i want is that i can set up an option to use "auto fill for logins" all the time without entering the mainpassword - BUT ALSO that 1Password data isn't editable oder deletable (with the use of the software - deleting the "storagefile" is always possible (thats normal).

    Conclusion - with this option is it possible to use autofill all the time, but the important functions of 1Password (edit, delete) are still "locked" and could only used by entering the masterpassword.

    Don't misunderstand me - i only want this as an option (for lazy users like me :) ) not as a general behavior of the software.

  • Megan
    Megan
    1Password Alumni

    Hi Martin,

    Thanks so much for providing your feedback here! We're always looking for ways to make 1Password as user-friendly as possible. We do want it to be a comfortable experience for you.

    Unfortunately, the problem with what you suggest is that it leaves your data vulnerable. An attacker doesn't need to be able to edit or delete your Logins or your credit card entries to cause trouble. Think about it this way: with the filling features of Mini enabled, your credit card information can be filled into shopping cart forms, and anyone could log into any of your accounts and change your passwords there or cause other kinds of mischief.

    Now, let's talk a bit about 1Password's existing security settings. The 'Lock after computer is idle for' setting counts time when you are not using the computer. If you continue to browse, or play games, or otherwise use your computer after logging in to a site, 1Password will remain unlocked, even if you don't log in to another site for 10 minutes or more. The timer will only start counting when you stop doing anything with your computer (kind of like to the screensaver). I have set 1Password to lock after 1 minute of computer inactivity and although I certainly don't use 1Password every minute, I rarely have to type my Master Password because I'm almost always doing something on my computer.

    If you are unlocking 1Password every 5 minutes even though you have been using your computer for the whole time, please let me know, as we'll need to do some further investigating!

  • Hi Megan - thanks for your reply and your tipps.

    Maybe i'm a different user because my imac is mounted next to me at the living room wall - so when i sit on my couch, i always got my iMac running beside of me - even when i'm not really using the iMac. When i really want to use him i just dragged him in front of me :)

    From this personal setting i really will have a benefit with the "settings" mentioned above and no security vulnerable because i see everything in my canthus (not sure if this is the right word if smb have always something keep in the eye)
    Maybe you and the coders thing of it as an configurable option - or two different settings. One "locking setting" only for 1Password mini and one only for 1Password Mainapplication independently.

    Till that i'll try your tipps - Thanks and have a nice day.

  • Megan
    Megan
    1Password Alumni

    Hi Martin,

    Thanks so much for writing back - I think I understand a bit better where you are coming from now. If you are not overly concerned about attackers while sitting in your living room (and it certainly is nice to feel safe at home!) you are welcome to adjust the security settings to be a bit more lenient. One way to keep things secure is to keep the 'Lock when main window is closed' option selected and be sure you close 1Password when you are finished using your computer.
    :)

This discussion has been closed.