It’s Cybersecurity Awareness Month! Join our interactive training session, or learn about security and AI from 1Password experts.
Forum Discussion
DreClark69
8 months agoNew Contributor
1Password Extension Hijack
I recently watched a video (see link below) where an unassuming Chrome extension could mimic the 1Password extension. It temporarily disabled the extension, changed its appearance to look like 1Passw...
Tom
8 months agoDedicated Contributor
Assuming this would be possible (which I can't think of 'why not' - since there are tons of extensions that are unverified or broken for years) - I would be very concerned with ever being asked for my secret key. Given though, people might indeed just do this, so some kind of user awareness is key.
I'm actually never unlocking via the extension, I always unlock the app (thus unlocking the extensions) but I can see that not being too common.
While I see (and share) your concern I think this is more to do with the browsers than the creators of the extensions, but maybe pushing for some kind of additional verification would be in order (though looking at the play store and all, very unlikely).
Hoping the 1P team has a great insight in this!
Btw, very nice to meet a fellow long-time user :)