Issues with the password vault storing duplicates, not updating password histories correctly, etc.

I suspect there might be some synchronization issues behind all of these, but I don't know and it's hard to try and figure out as a user.
For background, I've been generally very happy with F-Secure, I was using the old password manager (Key?) since at least 2022 and now have Total. Currently it's installed on 2 Android phones and 2 Windows PCs, but these problems started before I got the newer PC. The phones are basically always on, barring reboots or running out of battery occasionally, and so is one of the PCs. The other PC (the newer one) is turned on usually daily. Even on vacation at least one of the phones is always on.
In short my problem is that the password vault is generating duplicate entries. For example, for my main work password, there are now 12 entries (more on that one later). For another work-related one, which I'll use as an example because I just observed a bug/unintended and unwanted behaviour on it today, there are 3.
This is for an external 3rd party service (so not run by F-Secure or by my employer directly). They require that the password is changed every 3 months but I generally use it more rarely so I usually have to change it whenever I use it. That was also the case today. I noticed there are 3 identical entries, with their anonymized contents (main password and password history) as follows:
Entry
password A
old password B
old password C
old password D
Entry
password A
old password B
old password C
old password D
Entry
password A
old password B
old password C
old password D
I checked that both all the passwords are the same, all the old passwords are the same, and all the old passwords' "Changed" dates are the same (in March 2022, April 2023, and August 2023).
I thought ok, whatever, I'll just edit the top one, generate a new password there, and save it, then later delete the others. I saved the new password (also changing it in the service), after which the first entry was now:
Entry
password X
old password B
old password C
old password D
i.e. the change to the current password was saved, but the password I just changed away ("password A") from was not moved into the password history at all! The other 2 entries remained as above, i.e. showing A as current and B/C/D as old passwords.
I did the above on my personal phone, and just now as I was writing this deleted the extra 2 entries on that phone. I then checked my work phone, and there are still 2 entries for this service there. The new password is saved to the second entry, the top entry still has the same pre-change password. To be fair, I opened the password vault on the work phone only about a minute after deleting them on my personal phone. That could explain why there is still an old entry, but it's a bit weird there is only 1 and not 2, I would assume that both changes would sync at the same time since the deletions were only some seconds apart. It's also weird the order is different. I then deleted the extra one on the work phone too, but I don't have access to check the PCs until the evening.
I can provide more example later, but this is already a fairly long post. Obviously both the duplicates and the password history not saving correctly are moderately large problems for the usability of the app/vault.
Answers
-
Some other examples:
- Another 3rd-party service (not the same provider as the one mentioned above) has 9 duplicated entries. They're split about half and half with one set having password E and the other password F as the current one, but all have only password G in their history.
- I have a total of 8 duplicates for one old credit card entry, so this also affects those, not just passwords.
- The main work password has 12 duplicates. I just did a quick check that 5 of them have password H, 6 have password J, and one has password K. For password history I only checked the most recent one on these, since they have a lot more passwords saved there. The most recent one is from April 2024, and is the same in all of these, so I assume the rest of the password history is also identical. Also, none of H, J or K is my actual current password, and I'm certain that I've saved it in the password vault when I started using it.
And there are more. And more keep appearing: I just numbered the 12 entries for the main work password while on my personal phone, by adding 1 through 12 to the name/title, so I could keep track of them while checking how many of each password is duplicated. Checking my work phone immediately afterwards, it now has 12 unnumbered ones and the 12 numbered ones. And then the unnnumbered ones got copied back to my personal phone. I deleted the unnumbered ones, after which they were gone from both phones. I also saved my current password into one entry, and that got synced to both ok, but the password history in that entry did not get updated, it is still saying that the April 2024 password would be the newest one. -
- I just booted up the new computer mentioned above.
- This also had 2 entries for the first example, the one in the original post, same as the work phone had.
- This also now had both the unnumbered and numbered duplicates, 12 in total, of the main work password. Even though the unnumbered ones were deleted from both phones earlier, and this PC was off for several hours after that.
This PC also had the current actual version of the main work password as an unnumbered entry. Meaning it had at some point been saved directly on this PC, or synced to this one, but was then either not synced or had later disappeared from both phones?!
-
Recording here that I have now deleted most of the duplicates, leaving only a couple of the numbered ones of the main work password to observe them. And I checked they were gone from all 4 devices. The old PC had 3 unnumbered duplicates of the main password even after they had been deleted from all others, but I deleted them and they didn't show up again on the other devices.
This comment is mainly to remind myself what the situation is now, for when this repeats and more duplicates appear. I doubt it's "if" at this point, because I remember doing at least 2 cleanups like this before, months apart. I didn't record exactly when they were, but sometime in the past 1-2 years. -
Hello @JS_
Welcome to the F-Secure Community. Thank you for reporting this issue to us.
To help us better understand the issue, could you please provide the following details?
What are the OS versions of your Windows PCs and Android phones? Are you using the latest version of the F-Secure app on all devices? If possible, please share the installed version numbers on your Windows and Android phones.
When you update a password or delete duplicates, do the changes sync immediately across devices, or does it take time? Have you noticed any patterns when duplicates reappear, such as after rebooting a specific device?
Since the vault automatically locks, do you frequently unlock it on different devices, or do you primarily use one device? Have you tried fully restarting all devices and unlocking the vault again to check if the sync issue persists?
Have you attempted to use the Connect Devices feature again to see if that affects the behavior?
Your insights will help us investigate this further. Looking forward to your response.
Thank you and have a lovely day.
Firmy
Community Manager | F-Secure Community
π Strengthening digital security through knowledge and collaboration
π Explore our User Guides | Knowledge Base for self-help resources
π» Empower yourself with Cybersecurity Insights and protect what matters -
The new PC is Windows 11 Home, exact version is 10.0.26100 Build 26100 if that matters. The old PC is Windows 10 Pro, I'll have to check the exact version in a bit. The personal phone is Android 14 (2025-02-05), and the work phone is Android 14 (2025-02-01 according to the F-Secure app)+ OneUI 6.1.
I can't say for sure that the F-Secure app would have always been identically up to date on all devices (probably likely that it wasn't), but autoupdate should be on in all of them. Currently the F-Secure app version numbers are 25.2.9433529 on both phones, and 19.8 on both PCs.
However, despite the version numbers possibly having been different in the past, when I started writing the posts/comments above, I did make sure to update the app on both phones, so at least from the point where I wrote "I thought ok, whatever, I'll just edit the top oneβ¦" onwards, everything was done with identical app versions in both phones. So while earlier duplicates may theoretically have partially stemmed from differing versions, the new duplicates and errors in saving password history correctly I described as happening yesterday were all with up-to-date software. I have also experienced duplicates/I had duplicates originating from before I had the new PC, or the current work phone.
As far as I could tell, the changes did sync practically immediately across the devices. Mostly I did not have 2 or more vaults open at the same time, but when I was doing the deleting I did do it like that a couple of times, and it only took a few seconds to sync. It basically looked like a loading delay. I haven't noticed other patterns, since until now it was a complete mystery why I was getting duplicates, especially of identical passwords. It was only in the posts above that I observed that old versions of an entry synced back to devices where they had already been removed.
Yes, I have the vault automatically locking on all the devices I think. My usage of the vault varies, on some days I don't use it at all, on some days I use it multiple times and on different devices. But there is usually delay between switching devices, I don't usually use multiple devices simultaneously or within minutes of each other. Instead I might check some password at work on a phone, and then another in the evening on a PC at home.
I haven't tried using the connect devices feature again.