anewuser Posted November 21, 2016 Report Posted November 21, 2016 (edited) When you start typing in a string that matches one of your passwords in the extension popup search bar, the matched login is displayed among the search results. The search bar should be used to filter only logins/emails, and not include password fields. That's a security and privacy issue since the text you are typing is visible on your screen. Firefox 50 Enpass 5.3.3 Edit: the main application has the same problem too. Edited November 21, 2016 by anewuser
Vinod Kumar Posted November 22, 2016 Report Posted November 22, 2016 Hi @anewuser, Thanks for your inputs. Yes, Enpass also searches in password field if search in all fields is enabled. Passwords similar to common search terms like username, email, name etc. are very weak and are not recommended. So, calling it a security issue is a bit overstatement. I bet many customers will complain if we remove this feature as they have their own uses cases for it. We would certainly add more search options in future that will address your concern.
Recommended Posts