displaying secret key in the clear. why ever do this?
BLUF: You obfuscate it in several places. Why not all? Be consistent.
When initially logging in, the secret key is displayed in full cleartext. Researching why, I have seen some other threads where people have parenthetically complained about this behavior - for several obvious reasons, e.g., uneasy feelings, shoulder surfing, remote control screen sharing, video conferencing, etc... I myself ran into a different one - screen capping the login flow for family members and having to edit the screencap. Which is what frustrated me and prompted me searching out those threads and registering here so I can post this message.
In those other threads, the general responses from 1P staff have been: the SK is our most wonderful differentiating factor re: our competitors and we laugh at them not having one; but it's never seen by us, it's to protect you from us, or something bad happening to us, print out your emergency kit and stick it in your bank's safe deposit box, just be careful sharing your screen, don't really worry about it and oh yeah, you can always change it if you want. Which, of course, would require making a special trip to the bank to replace that copy and necessitate securely disposing of that old copy that presumably had your master password written on it - which oh yeah, was two passwords ago because driving to the bank for this whole safe deposit thing is stupid. And especially stupid when it's so obviously easy to protect it from disclosure with the software in the first place. And isn't that kind of the point?
I get what it does, how it works, what threat model it's designed for. But if it's the big deal that it is, then it needs to be treated that way. So, let me state for the record that having the secret key displayed in cleartext by default is dumb. And the wrong decision. Even given all your above poo-poos of why it doesn't matter. Because it does matter. I know this. And you, 1P, know this. It should be dotted out by default with an eyeball clicker for verification. This isn't a big ask - especially when you control all the fields where it is ever entered.
It's even more incredulous why it hasn't been done when the code to do so is literally a copy and paste from one of the several ways you have already already done exactly this in other places of the UI. Knowing devs, they have already spent more time in your internal bugzilla about whether to fix this than it would take to actually fix this. It probably took me longer to search the few threads about why something so obvious isn't fixed and then type this message out than it would take to fix this. And for y'all to read it and type a reply. And then all the future questions and multiple answers of y'all with the same answers as above.
Or, if you persist in stating that it doesn't matter, then please de-obfuscate it in the several other places where you do. Like in the "you have been auto-logged out due to 10 minutes of activity" screen. And in the details of the 1Password Account login category item. And in the "My profile" screen. And you could also de-blur the QR code wherever it appears since it's just the email and SK.
So, as a new customer, I'm asking: be consistent, not hypocritical.
1Password Version: none yet
Extension Version: 2.5.1
OS Version: Win 10
Browser:_ Firefox
