EXTREME HEADS UP

I just go phished on my 1Password account from an email talking about unconfirmed users. Clicked a link to:

httpx://mkt-lnk.1password.co/n/

And it's on a Family Account that's managed by my wife who's currently in Kuwait.

FUCK!

/cc @1password

Thanks FedEx, This is Why we Keep Getting Phished

I've been getting a lot of those "your parcel couldn't be delivered" phishing attacks lately and if you're a human with a phone, you probably have been too. Just as a brief reminder, they look like this: These get through all the technical controls that exist at my telco and

Troy Hunt

So the “phishing link" with the .co domain was a valid link and documented as such:

https://support.1password.com/email-domains/

But I still find it inexcusable.

That link caused 30 minutes of complete panic. I know enough about how phishing works to know how absolutely fucked I'd be if that link hadn’t just been to track my click in the email.

I am just now starting to recover from the episode.

1Password email and marketing domains

Learn which domains 1Password uses to send emails and what links are used for marketing, so you can validate messages you receive and make sure they're not marked as spam.

1Password

Which brings up another question: why is a company I pay to protect my private information using tracking links in the emails it sends me?

Privacy should be a part of all operations at 1Password.

When one of the leading products that protects your passwords encourages you to use a phish-like link, it's pretty much game over.

FedEx has legacy systems, arcane government regulations, and a bunch of weird infrastructure. Their phish-like links are understandable, at least.

1Password using a phish-like link just so they can track my fucking click makes no sense at all.

And the irony here?

I got this email about unconfirmed users, but can't do anything about it because I'm not the family organizer.

After 30 minutes of panic, I got nothing to show for it.

And thanks to all the folks who let me know about the .co link being legit.

If you've ever been phished, you know how much relief I felt by seeing these messages.

@chockenberry Sorry about the scare! I pinged our team to get this fixed.

FWIW, I purchased as many 1password and 1password-like domains as I could find to make the phishing attacks more difficult.

Not sure if we bought 1password.xxx though 🤔

@roustem @chockenberry SEXY SINGLE-USE TOTP CODES IN YOUR AREA
@harpaa01 @roustem @chockenberry 1Password is SO HOT! (because switching to Electron is so inefficient)
@chockenberry IconFactory should totally write an amazing front end to Apple Keychain!
@chockenberry I got this email as well, and the worst part is that I don't have any "unconfirmed users”, and for some reason they sent me the email twice. Why not send it only to the accounts that actually have unconfirmed users? 😓
@_inside exactly the same here. Lazy and disruptive.
@_inside @chockenberry same! We manage some clients with 1Password and got several iterations of this email. Not one of the accounts that got the email had unconfirmed users so I don't know why we got it. I only checked them because (perhaps foolishly) I presumed the only people getting the message were the ones that needed it.
@Verso @_inside @chockenberry same here, I checked all my family members in the admin panel and have no unconfirmed so to me this email should only go out to anyone that actually has some
@Verso @_inside @chockenberry same, I got several copies. I logged in manually and all seemed confirmed.
@steveriggins @Verso @_inside I was sent the email and since I'm not the family manager, I wasn't even able to navigate to the setting mentioned in the email.
@chockenberry @Verso @_inside what a mess every which way but loose
@chockenberry related: there are no unconfirmed users on my account, yet they keep emailing me like I‘m overlooking something. Also somewhat stressful, not quite on your level…

@chockenberry sometimes I consider 1Password because it looks like the experience is nicer, but then I remember the corporate-owned, closed nature of it probably means stuff like this that I won't see from Bitwarden.

There's no good excuse for this from a password manager!

@chockenberry so much enshittification since they started taking VC money. 😭

@caseyliss @chockenberry As someone that doesn’t just use  platforms, 1Password has improved massively on Windows/Android since launching v8. Obviously YMMV, but just to point out that there have been real benefits for some users.

All that said, this email tracking is obviously complete fucking bullshit 🤬.

Set up iCloud Passwords on your Windows computer

Set up iCloud Passwords in iCloud for Windows so you can manage and autofill your passwords on your PC.

Apple Support
@ravi @caseyliss @chockenberry 1Password 7 was a bad Windows citizen for sure, but instead of improving that they decided to make 1Password 8 a bad citizen on every platform to level the playing field. Hugely disappointing.
@caseyliss @chockenberry Also another reason why they shouldn't be forcing people to use hosted 1Password accounts if they'd prefer the old-style Dropbox- or iCloud-synced vaults…
@caseyliss @chockenberry Isn't it somewhat amazing how the VC $$$ --> enshittification cycle plays out everywhere, every time, as if it's some natural law?
@caseyliss @chockenberry Yes, I dumped 1Password because they sold their soul for a wad of cash. I now prefer @bitwarden for Password Management; if I didn’t use BitWarden, I’d just use iCloud KeyChain.
@chockenberry This, and similar questionable behavior, is why I’ve stopped using 1Password. Moved into Keychain about a year ago and, since I’m not cross platform, it does everything I need.
@chockenberry how does having this separate domain help track email clicks? Why isn’t this something they could do with their main domain?
@chockenberry because they’re after business / VC money and end-user consumers are no longer their primary customer. See also: DropBox.

@goldenbough Phishing is even more of a concern in a corporate environment.

Getting a foothold inside a firewall exposes a lot more people and information to danger.

@chockenberry sounds like they need the CHOCK BLOCK ✋🏻😤🤚🏻
@chockenberry 1Password is not what it used to be. Unfortunately it’s still the best password manager on  platforms, I think. So while I agree completely that they shouldn’t use these practices, I’m not surprised that they do.
@chockenberry I think that went out the window as soon as 1Password was bought out and pivoted to enterprise from consumer.
@chockenberry BUT SOMEONE THINK OF THE VC FUNDERS!
@chockenberry I dropped 1Password once they got rid of the native app and forced people into their cloud. I’d rather use a solution that lets me choose how I want to sync.
@chockenberry billion dollar evaluation doesn't care about nonprofits like “privacy".
@chockenberry It’s not just emails. telemetry.1passwordservices.com is constantly blocked through PiHole coming from the app