This is a staging forum for AgileBits, not an official support forum. Visit http://discussions.agilebits.com instead.

Credit Card names are shown when 1P is locked in Safari

Vano
Vano Junior Member
edited December 1969 in Mac
Hello,



When 1P is locked, the Safari Plugin still shows all Credit Cards as can be seen in the following attachment. Once a credit card is selected, it asks for the master password, but even still, I don't think it should be showing the names of the credit cards when 1P is locked.



[attachment=62:1P issue.png]



Can you please let me know whether this is normal and a work around to fix this?



Thanks

Comments

  • Nik
    Nik
    edited December 1969
    Welcome to the forums, Vano! This is normal behavior as item titles are not encrypted:

    [url]http://help.agile.ws/1Password3/agile_keychain_design.html[/url]



    I hope that helps.
  • Vano
    Vano Junior Member
    edited December 1969
    Thanks for the prompt reply.



    However the behavior doesn't seem consistent with say the Go & Fill Login option. When 1P is locked, the fields in that submenu are not shown (only search... is shown which pops up the master password dialog) contrary to the Credit Cards submenu. Furthermore without the master password (or unlocking of 1P) the user cannot access any other item titles from within the Safari plugin or the 1P program, with the exception of the Credit Card titles in the Safari Plugin. It certainly is not something to be expected.



    Is there anyway to disable the Credit Card submenu short of disabling the Safari plugin altogether?



    Thanks
  • [Deleted User]
    edited December 1969
    Hi Vano,



    At the moment it's not possible to hide credit card items from the 1Password browser menu. The reason for the change in Go & Fill behaviour is that a number of users felt that showing all the login titles, which often included their user name (although this is not the default behaviour and not something we recommend). I'll pass this along to our developers, but the biggest tip I can give you is to make sure that your credit cards aren't named in a way that would reveal any of their information, of course only the title is stored unencrypted and none of your credit card information is available without your Master Password.



    Hope that helps,
  • Vano
    Vano Junior Member
    edited December 1969
    Thanks for the reply.



    I would suggest to the devs that the Credit Card submenu should not be shown if 1P is locked.



    I understand that from a security point of view the title names are not encrypted in the key chain, and thus are not secure, but even so, having this info within a single click of a button within the browser, which is arguable the most used program and is guaranteed to be always running, is not a great idea.



    Thanks.
  • MartyS
    MartyS AgileBits Customer Care (retired)
    edited December 1969
    Thank you for your followup.