1P 8's uncontrollable auto-fill just gave away my private data
My wife made some family travel plans and shared the travel company's trip with me. I clicked the link in their email message, which took me to the site and requested I log in. I hit cmd-\ to bring up 1P, which filled and submitted the form. Unfortunately, while I thought I already had an account, I actually did not -- but there is an account in one of my work vaults. Since there was only one cred in the database, 1P found it, filled it in, and automatically submitted it. And, the travel company share was a one-click affair, meaning as soon as I was logged in, all the details of my family trip were linked to the work account and shared with lots of people in my company. This includes things like scheduling details, personal details about everyone in my family, and how much I paid.
As has already been pointed out, auto-submit is absolutely a security risk, for two reasons:
Machine error (i.e., 1P misidentifies what fields it should fill) causes 1P to fill in information the user did not want filled or even to submit the wrong form entirely. People have posted in these forums plenty of examples of this.
Human error leads 1P to fill in the wrong credential, triggering whatever consequences are linked to that. This post is about one example of this.
Both cases are high-probability, which is why both have been discussed on these forums. It's actually very similar to removing the anti-phishing feature where 1P will only auto-fill if the domain matches.
I get that some people like the feature. And I'll admit that, when it does the right thing, with the right data, it's a wonderful experience. The problem is, there are just too many variables at play for you guys to ensure it does the right thing, with the right data, with an acceptible level of reliability. And in some cases, it's not even possible. This rightfully led you guys to kill the feature years ago, and you even blogged about the fundamental problems at the time. You say you've fixed all that now, and yet, people keep pointing out the very same problems and you keep fixing bugs related to it. Clearly, the fundamental problems are still present. The only way I can think that happens is that the people who made the decision are gone and the new people have egos telling them they can do it better.
Please give us back the ability to turn off this feature. If some people have narrow enough use-cases that it works well enough for them to keep it enabled, great. (Though, you should warn them as they turn it on that it carries risks.) But don't make everyone for whom it does not and cannot work that well suffer bad UX and potentially embarrassing or costly consequences when things inevitably go wrong. This is terrible for your users and a fairly big liability risk for you guys.
1Password Version: 8.8.0
Extension Version: 2.3.6
OS Version: macOS 12.4
Browser:_ Safari 15.5
