It’s Cybersecurity Awareness Month! Join our interactive training session, or learn about security and AI from 1Password experts.
Forum Discussion
esquared
4 years agoSuper Contributor
Why are items moved between vaults listed in "Recently Deleted"? Bad security model!
Since well before 1Password 8, items that I move between vaults end up with a copy in recently deleted - this is REALLY confusing when listed with items that were really deleted. The items in the de...
esquared
4 years agoSuper Contributor
Thus far this has not been identified as a high impact situation.
That is a sad statement. We have clearly outlined situations in which this could lead the information leakage. In the most obvious case, someone who is the member of multiple accounts, e.g. an MSP situation, could inadvertently leave "moved" copies of credentials in the deleted folder of the wrong customer.
I will also claim that blaming the user is not an option here. The tool is simply doing something that most users will simply not expect. Heck, poll your own staff at ABits and I'll bet you a beer that half don't know this mis-feature exists in a product they work on and presumably use daily.
I urge you to think harder about the ramifications of this choice and how the reputation of the company could be adversely impacted if not addressed.