Vulnerability in 1Password

For those of us who don’t know code, could you give an ELI5 summary of what exactly the vulnerability is? Explain it to someone who knows how to sign up for an app and what E2EE is but doesn’t know what an IDE or CLI is.

To simplify this, the vulnerability is that you don’t need to enter your password everytime when you access the password manager.

So for example you access your password manager and type your password in and it gets unlocked, now you can access it until X-minutes and than it relocks again. The vulnerability says that it should insta lock, so that you need to enter your password everytime.

Just not for the desktop app or browser extension rather than the CLI (command line) tool.

3 Likes