Web interface automatically copies passwords to clipboard without notice/warning

Options

In 1Password's web interface, viewing an item will show buttons that make it a conscious choice to view or copy a password. However, when in edit mode for new or existing items, clicking the key icon to open the password generator automatically copies the existing password to the clipboard, and the Regenerate link/button does the same for each new password. There is no indication that this has occurred, and it's an insecure default because you literally cannot create a random password without putting it on the clipboard. Cancelling out of editing the item still leaves credentials on the clipboard, too. Even if one isn't concerned with it going to the clipboard, the next paste to any other program will potentially have unexpected sensitive data, not the what was last consciously copied. I don't see how it can be reliably cleared from the clipboard like the apps can, either.

This should be opt-in per device at the least, or removed in favour of a deliberate copy button, and should always indicate when a copy has occurred. It's not even essential to copy in that situation because after setting a new password, it's right there saved in the item for copying, etc.


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser:_ Not Provided
Referrer: forum-search:clipboard new

Comments

  • Hi @roy_orbison:

    Thanks for letting us know about this! I was able to replicate it, and I've brought it up with the team to see if we can take a closer look at this.

    Jack

    ref: dev/b5/b5#17293

This discussion has been closed.