PSA: 1Password uses “1Password.co” for email links — instead of their usual “1Password.com” domain. Craig isn’t an idiot; it 100% feels like phishing. If you ask me, tracking link clicks and opens in emails is simply not worth the potential freak-out when you think you’ve been phished, please tell the marketing team to pound sand (respectfully)

From: @chockenberry
https://mastodon.social/@chockenberry/112049988291729734

@cabel @chockenberry I sincerely hope someone at 1Password has escalated and set about solving this blurring of what needs to be absolute trust (between a user and a password managing org). This sort of thing is an awful choice on your part (1Password) and you must address it or risk becoming less than trustworthy in users eyes. Marketing pressure MUST NOT usurp security or client confidence.