Oh, 1Password stores user profile pictures on their servers without authentication. Anyone who has the long URL, which also contains the account identifier, can access the picture. It's not a big deal, but a password manager should definitely be more careful.

#privacy #infoSec

This is a test account we created to test the new feature that 1Password just announced about unlocking the app with the Mac password, as it relates to our recent work. Here's the link that was shown in the screenshot:

https://a.1passwordusercontent.com/VL4OMT3IFZDB3LIJRC67R3ECLU/f2v3kcoxrnemzaf4hrl7vtpw6m.png

@mysk 1Password does have an update for you... https://a.1passwordusercontent.com/VL4OMT3IFZDB3LIJRC67R3ECLU/f2v3kcoxrnemzaf4hrl7vtpw6m.png

Such a shitty service. Looks like the .png is still there and they just blocked requests because of your popularity. #1password #privacy #passwordmanager

@case2tv No worries. I still have other examples that I also deleted last November:

https://a.1passwordusercontent.com/N6BR47U6UBD6VHEQI2WP6QFQUM/2gsposdalbajjo76scqudg4vl4.png

@mysk Such a good move showing that 1Password is more shitty than expected! I cannot believe that this is true... But it is!
@zak @blake @1password any comments?
CC: @jik
#1password #passwordmanager #privacy