Signing back into the Community for the first time? You'll need to reset your password to access your account.  Find out more.

Forum Discussion

esquared's avatar
esquared
Super Contributor
3 years ago

Why are items moved between vaults listed in "Recently Deleted"? Bad security model!

Since well before 1Password 8, items that I move between vaults end up with a copy in recently deleted - this is REALLY confusing when listed with items that were really deleted. The items in the deleted folder seem redundant at best, but I've generally ignored the issue.

However, today I discovered how this is really a potential BIG security hole. For example, if I move an item to a vault I share with others, but I moved the item to to the wrong vault and moved it again to the correct vault, the "deleted" moved items remain accessible to users of the wrong vault. That requires me to take an extra step to empty the trash or permanently delete the specific items.

This same issue could occur if I expand the group membership on some vault, with the intent of moving a small subset of items out to a more secure / limited vault. Again, I have to manually issue "permanently delete" on the moved items.

Why is it that items moved need to be added to recently deleted at all? They were moved - just let them exist only in the destination vault. I don't need to be able to "recover" a copy of the item to the original vault.


1Password Version: 8.7.1
Extension Version: n/a
OS Version: macOS 12.4