Forum Discussion

jeffkirkley's avatar
jeffkirkley
New Contributor
19 days ago
Solved

Unlocked Vault - entries viewable to other sites?

Hello All: 

  If I have my Vault open and unlocked, can an Internet site that I visit view/see/obtain any credentials in my Vault.  OR, is it the case of when I visit a site, and then click on an entry for that site that contains stored credentials and then populates those store credentials into the site's form -- can they only then see that credential info?

My current paranoia involves me locking and unlocking my Vault numerous times a day and I want to know if this is really necessary?  Is it safe to leave the Vault open and unlocked all day?  My computer is only used by me, so local security is not part of this discussion.

Thanks.

 

  • Hello jeffkirkley! 👋

    Thanks for the question! As Tom mentioned, 1Password will only fill your login credentials for a specific website if you deliberately choose to have 1Password fill those credentials by clicking on a suggestion from 1Password. Your other login credentials are not shared with the website and the website can't see the other information that you have stored in 1Password. 

    So, to answer your question: websites cannot view your information in 1Password unless you deliberately choose to fill some specific information (like login credentials) into the website. You can read more here: 


    -Dave

5 Replies

  • jeffkirkley's avatar
    jeffkirkley
    New Contributor

    Hi @1P_Dave1P_Dave 

    Thanks so much for the confirmation on this matter and the info page you provided.  Definitely reassures my security concerns in the daily use of a great product!

    Jeff

     

  • Hello jeffkirkley! 👋

    Thanks for the question! As Tom mentioned, 1Password will only fill your login credentials for a specific website if you deliberately choose to have 1Password fill those credentials by clicking on a suggestion from 1Password. Your other login credentials are not shared with the website and the website can't see the other information that you have stored in 1Password. 

    So, to answer your question: websites cannot view your information in 1Password unless you deliberately choose to fill some specific information (like login credentials) into the website. You can read more here: 


    -Dave

  • jeffkirkley's avatar
    jeffkirkley
    New Contributor

    Hi Tom, Thanks so much for your reply.  I understand about the pop-up when I click on a site's username and password, but my question is more about the overall security of the contents of the Vault itself.  In other words, are all of my Vault entries available and viewable by an external site (if the Vault is unlocked) or do the other Vault entries remain encrypted and non-viewable if they are not for the site I am visiting at the time?

    • Tom's avatar
      Tom
      Dedicated Contributor

      I meant to say nothing is visible to the site unless you click on it - though if creative enough you can get the pop-up to display any data, but websites themselves should never be able to 'reach out' - i.e. the 1password extension creatively tries to determine from site contents (url, form-field-labels, etc.) which things to display from any applicable (unlocked) vault in your pop-up but sites shouldn't be able to reach into your 1password data at any point (disclaimer, not sure about the passkey shizzle).

      1P_SimonHcan you add your thoughts?

  • Tom's avatar
    Tom
    Dedicated Contributor

    They only see whatever entry you clicked on to start auto-filling it that is what you ask? Unless you start filling (e.g. tap/click on something to fill) nothing will happen (the 'pop-up' is just local)