Skip to main content
September 12, 2022
Question

Safari Biometrics disabled? [SOLVED]

  • September 12, 2022
  • 63 replies
  • 5151 views



https://1password.community/discussion/comment/662952/#Comment_662952

.

Why does the latest update disable biometrics in Safari?


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser:_ Not Provided

63 replies

September 14, 2022

@alovchin91 yup. They want everyone to have the same experience. Yes they actually said that. 😂

Jack_P_1P
1Password Employee
September 14, 2022

Hi folks:

I sincerely appreciate your concerns here. I've been a huge user of 1Password for Safari since it released, and I'm having to adjust my workflow here as well.

How and why were these changes just found out recently when iOS 16 has been available for beta testing for months? I can't imagine Apple suddenly made this change in the RC release a week ago.

We noted the issue here in late August, and we've been working on the best solution since then. As it stands, removing Touch ID and Face ID unlock from 1Pasword for Safari is the best path until / unless things change.

you've had months to get this sorted out

As it currently stands, there is no acceptable way to implement Touch ID / Face ID in 1Password for Safari. While the behavior of WebAuthn appears similar between iOS 15 and iOS 16, there are differences, and while we are still actively pursuing a solution, it's also possible we may need help from our friends at Apple to bring this back.

Jack

AMonitorDarkly
September 14, 2022

it's also possible we may need help from our >friends at Apple to bring this back.

I think that’s the biggest concern for myself and others. If 1P ends up having to rely on Apple for a solution then it’s not going to happen. I guarantee Apple doesn’t care about this. As someone else mentioned, they’re going to be more worried about pushing people onto Keychain/Passkeys.

hegguardo
September 16, 2022

This is a huge regression in functionality. I really hope a solution is found ASAP. I would hope it is a high priority.

September 25, 2022

This makes 1password unusable. I love your product and and your company, and have used it forever. And I understand it may be beyond your control, but that doesn’t change the fact that it makes 1password unusable. Is this the beginning of the end?

Is there a reason I had to find this in your community rather than direct in the articles about enabling Face ID? You sure wasted a lot of my time troubleshooting. You need to update the Face ID and extension documentation.

September 26, 2022

The "disabling" is inconsistent I have 2 phones, 1 an iphoneXR, 1 an iPhone 13 Pro. Both running ios 16.02. The FaceID works on the XR but not on the 13 Pro. I also notice that the FaceID does authenticate on the 13 Pro but isn't unlocking 1Password. Further, my sons iPhone 14 Pro also works to unlock FaceID. Why all the inconsistency? Frustrating.

SyberCorp
September 28, 2022

Just my input about some of the people commenting that 1Password/AgileBits should have accounted for this while iOS 16 was still in beta, etc., and how they don't have the users' backs.

If the API they use was modified to have lowered security than what AgileBits was comfortable with their app/users using (because it would potentially put user data at risk), unless Apple changed the API again to appease AgileBits, I don't get what you expect AgileBits to do about it short of lowering their standards and agreeing to put user data at risk, or magically create their own API that somehow becomes a part of iOS 16. So, from my perspective, they absolutely DO have the collective backs of the users by refusing to use an inferior API from a security standpoint.

That all being said, I too am upset about the lack of the biometrics in the Safari extension because of the other things it took away in removing it.

AMonitorDarkly
September 28, 2022

@SyberCorp For me, this is more a matter of how this was handled. This is a significant enough regression that, while necessary for security, warrants a public statement. AB did nothing to inform users of this other than a small blurb in the release notes which AB knows the vast majority of users aren’t going to see. As a result, many people came to the forums thinking this was a bug only to find out that AB, once again, broke critical functionality without telling anyone.

I’m glad AB was putting security first here but as usual their execution was pretty poor.

September 28, 2022

I had to switch to Keeper because of this. Hopefully they will get it figured out at some point. Unfortunately they lose this customer because of it.

SyberCorp
September 28, 2022

@AMonitorDarkly I suppose that’s fair, that they could have made users aware of the upcoming issue/regression by sending something to all users outside of just release notes.