1Password adds pop-pup warnings for suspected phishing sites
嗯,用户让我总结一篇文章的内容,控制在一百个字以内,而且不需要特定的开头。首先,我需要仔细阅读文章内容,理解其主要信息。 文章讲的是1Password这个数字保险库和密码管理器新增了内置的反钓鱼URL保护功能。这个功能帮助用户识别恶意页面,防止他们泄露账户凭证给威胁行为者。此外,文章提到1Password在企业环境中被广泛使用,并且Windows最近增加了对原生密钥管理的支持。不过,仅仅依靠URL匹配来保护是不够的,因为用户可能会误入拼写相似的钓鱼网站。因此,1Password新增了一个弹出警告,提醒用户注意潜在的钓鱼风险。这个功能对个人和家庭用户自动启用,企业用户则需要管理员手动激活。 总结的时候,我需要涵盖这些关键点:新增反钓鱼功能、保护用户识别恶意页面、防止泄露凭证、以及弹出警告的机制和适用范围。同时要控制在一百字以内。 现在组织语言:1Password新增反钓鱼功能,通过弹出警告提醒用户潜在风险,并自动填充与存储URL匹配的数据。个人和家庭用户默认启用,企业用户需管理员激活。这样既简洁又涵盖了主要信息。 </think> 1Password新增反钓鱼功能,通过弹出警告提醒用户潜在风险,并自动填充与存储URL匹配的数据。个人和家庭用户默认启用该功能,企业用户需管理员手动激活以增强安全性。 2026-1-25 15:30:26 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

1Password adds pop-pp warnings for suspected phishing sites

The 1Password digital vault and password manager has added built-in protection against phishing URLs to help users identify malicious pages and prevent them from sharing account credentials with threat actors.

The subscription-based password management service is widely used in the enterprise environment by many well-known organizations. Recently, Windows added support for native passkey management via 1Password.

Like all tools of this kind, 1Password will not fill in a user’s login data when visiting a website with a URL that does not match the one stored in their vault.

Wiz

While this provides intrinsic protection against phishing attempts, some users may still fail to recognize that something is wrong and attempt to enter account credentials on dangerous pages.

As 1Password admits, relying on this protective layer alone is incomplete from a security perspective because users may still fall for typosquatted domains, where the threat actor registers a misspelled or similar-looking domain name.

Users may still think they landed on the correct site, but their password manager glitched out, or that their vault is still locked, and proceed to enter the credentials manually.

To address this security gap, 1Password users will benefit from an extra layer of protection in the form of a pop-up alerting them of potential phishing risk.

"It's easy for a user to miss that extra 'o' in the URL, especially if the rest of the page looks convincing," the vendor explains under a Facebook domain typosquatting example.

1Password alert to user
1Password alert popup
Source: 1Password

The vendor says that "the pop-up reminds [users] to slow down and look more closely before proceeding."

The new feature will be enabled automatically for ‘individual’ and ‘family plan’ users, while Admins may activate it manually for company employees through the Authentication Policies in the 1Password admin console.

In its announcement, the password management company highlights that the phishing threat has increased with the proliferation of AI tools that help attackers perpetrate more convincing scams at a higher volume.

A 2000-person survey conducted by 1Password in the U.S. showed that 61% had been successfully phished and that 75% do not check URLs before clicking links.

In corporate environments, where a single account compromise is enough to allow external actors to move laterally across networks and systems, 1Password found that a third of the employees reuse passwords on work accounts, with nearly half of them having fallen victim to phishing attacks.

Almost half of the survey participants responded that phishing protection is the responsibility of the IT department, not theirs, and 72% admitted they had clicked suspicious links.

Finally, more than 50% of the respondents said that it is more convenient to just delete suspicious messages than report them.

Wiz

Secrets Security Cheat Sheet: From Sprawl to Control

Whether you're cleaning up old keys or setting guardrails for AI-generated code, this guide helps your team build securely from the start.

Get the cheat sheet and take the guesswork out of secrets management.


文章来源: https://www.bleepingcomputer.com/news/security/1password-adds-pop-pup-warnings-for-suspected-phishing-sites/
如有侵权请联系:admin#unsafe.sh