Skip to main content
AMonitorDarkly
September 21, 2021
Question

Safari Extension Authentication

  • September 21, 2021
  • 11 replies
  • 737 views

The authentication process for the new Safari extension seems a bit clunky. It involves extra steps that are annoying and unintuitive. So you’re left with the choice of either wasting time doing these extra steps frequently or setting the extension to require authentication less often thus sacrificing security.

I don’t understand why it doesn’t just automatically authenticate with each use as it did with the old auto fill system.

11 replies

1P_Dave
1Password Employee
1Password Employee
September 21, 2021

Hello @AMonitorDarkly! 👋

1Password for Safari takes advantage of Safari's ability to support extensions on iOS 15 and is subject to different technical opportunities and limitations than iOS Password AutoFill. Specifically we're using a web standard called WebAuthn in order to manage authentication, it's a great way for Safari extensions to make use of Touch ID or Face ID however it does require that the user first allows the authentication to take place.

The default amount of time before 1Password for Safari needs authorization again is 24 hours but you can indeed lower this to as low as 15 minutes. Or you can manually lock 1Password for Safari between uses:

  1. Open Safari on your iPad.
  2. Tap on the puzzle piece in the address bar.
  3. Tap on 1Password.
  4. Tap on the colourful ring icon.
  5. Tap on Lock 1Password.

The next time that you use 1Password you'll be prompted to authenticate. Let me know if that helps. :)

AMonitorDarkly
September 21, 2021

I’m hoping a smoother extension authentication process can be implemented in the future. As of right now, it’s cumbersome and a distinct step backward from the previous auto-fill system. A user in another thread mentioned that authenticating the extension is 5 extra steps.

As I mentioned, the extension is currently forcing users to choose between sacrificing time or security.

1P_Dave
1Password Employee
1Password Employee
September 23, 2021

Hopefully we can improve this in the future as Safari Web Extensions on iOS and iPadOS continue to mature. At the moment because of the technical limitations of WebAuthn and Safari Web Extensions 1Password for Safari isn't able to immediately authenticate using Face ID / Touch ID.

In recent years Apple has done a great job having users set a PIN code or use Face ID / Touch ID to lock their iPhones when not in use. If your iPhone is locked when you're not using it then 1Password for Safari won't be available either until you unlock your iPhone.

Michael_Shingledecker
September 24, 2021

I agree with the clunky comment. I’m not going to continually type a complex password on an iPhone keyboard just to use this extension. I’m turning off the extension and going back to the previous method.

September 24, 2021

Understood @Michael_Shingledecker, we appreciate the feedback :+1:

October 1, 2021

Unfortunately you can’t go back to the previous method, because they disabled it. Why did they disable it? No one has given an answer that isn’t convoluted and confusing. Something about not wanting to support two different functionalities because that’s too hard/expensive, and something about the browser extension being so much better that they just tossed the share sheet method (that’s the previous method). What I don’t understand is, when was that decision made inside the company, and didn’t at least one person speak up and say “Hey, if you do that you’re killing the app for like thousands (they don’t know the actual number of people with local accounts, so it could be tens or hundreds of thousands for all I know) of costumers who’ve forked over hundreds of dollars in license purchases? Or why didn’t at least one person say hey, the extension method requires users to input a (newly lengthened) 10 character password periodically into the tiny iPhone keyboard which has to be typed perfectly because you can’t autocorrect a password, and the old share sheet method only used biometrics - I wonder if anyone is going to dislike this? And also, if my 1Password app always uses biometrics, why on earth does it make sense to have to manually type in the password to the “mini 1Password” extension periodically? Also, why do they keep closing discussions here about the iOS15 local account thing?

Sandgirl
October 1, 2021

You make some very good points.

I hope management listens to its users before they end up losing many previously loyal customers. It is a shame to find that the app is no longer the brilliant one it has been for many years.

AMonitorDarkly
October 2, 2021

I’m on a subscription so the trashing of the share sheet hasn’t technically affected me. However, if I’m being honest, the fact that 1Password has effectively kicked so many old, loyal users to the curb along with the developers’ tone deaf response has really rubbed me the wrong way.

If I’m being brutally honest, this whole situation has made me reconsider whether or not I want to continue my membership. When subscriptions first came about I explicitly recall the developers stating that what has transpired here would never happen. How long will it be until my user story no longer aligns with 1Password’s bottom line?

October 2, 2021

I’m currently not a fan of the new Safari extension. I prefer having Face ID authentication each time 1P is accessed on my phone. The new extension also displays items from all my vaults even when I exclude certain vaults from “All Vaults”. Also, as most are saying, it’s clunky and takes too many steps to manually lock/unlock each time.

Please bring back the share sheet extension. I can still kind of use the old method since it prompts the login integrated with the keyboard, but I can’t seem to initiate credit card fill this way.

October 5, 2021

+1 for the previous comments