Do you know what would be amazing? The ability to change all vulnerable passwords, automatically as a group. I know it's very challenging because password change/reset procedures vary widely, but that part of the process is still manual. 1Password already automates logins almost entirely successfully. Perhaps password changing can be automated as well? If it were robustly automated, you cold easily rotate your passwo…
Thanks for the feedback!
Filling into sites and gathering the necessary information for this I think is far easier than determining how a password change takes place. We have an algorithm that we've developed over years that is constantly changing in subtle (and not so subtle) ways to make filling more accurate. Some of the biggest changes in a long time will be coming in the 4.2 version of the browser extension, currently in beta.
But you're right, sites and their password change processes differ greatly. Some require the old password, some require only the new password. Some only require the new password once (admittedly rare).
I think at best though we'd only be able to do this if we went to the password change page for the site and attempted to fill the data in for changing the password. There's no way we could bulk update as that would probably require we hard code each individual site rather than relying on an algorithm for filling data into the site.
It's a tricky thing, but we're always trying to come up with new ideas and ways to accomplish those ideas.
Heartbleed was the first use case for Watchtower, but you're correct in that it'll be available for other situations as well. Now that the foundation is there we can leverage it for other issues in the future.
Thanks again for the wonderful feedback!
Kyle
AgileBits