Watchtower issues

Hello

I have some issues with the Watchtower.

First, numbers are different between desktop app and web vault.

Web vault

Desktop app

Second, after deleting an item in Watchtower, it goes back to all login items, instead of Watchtower page. For example, when I delete a login item from Weak Passwords tab, I expect it to stay there but instead it goes to my vault page.

Third, some Watchtower reports are missing in desktop app, like missing 2FA, Compromised sites, Expiring, Vulnerable Passwords.

Fourth, it shows password strength of my logins but it doesn't show which is which. Just seeing numbers doesn't mean anything, e.g. 242 very good passwords, 13 fair passwords, what are those? Which item has fair password, what is the criteria for password strength?


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Sync Type: Not Provided

Comments

  • Hi @Naxterra,

    Thanks for taking the time to report this.

    At the moment, 1Password 8 uses a newer implementation of Watchtower algorithms that the web app hasn't yet been updated to. We will continue to refine this and move all of our apps to reuse the same algorithms.

    Second, after deleting an item in Watchtower, it goes back to all login items, instead of Watchtower page. For example, when I delete a login item from Weak Passwords tab, I expect it to stay there but instead it goes to my vault page.

    This is a bug, we'll get this fixed.

    ref: dev/core/core#6872

    Third, some Watchtower reports are missing in desktop app, like missing 2FA, Compromised sites, Expiring, Vulnerable Passwords.

    Can you confirm they're enabled in 1Password's settings > Privacy? They have to be enabled for it to show up.

    If you did enable it, try pressing Control + F5 on the Watchtower Dashboard to refresh it.

    We do plan to figure out a way to explain why they don't show up such as mentioning they're disabled and you can enable it directly from the dashboard.

    Fourth, it shows password strength of my logins but it doesn't show which is which. Just seeing numbers doesn't mean anything, e.g. 242 very good passwords, 13 fair passwords, what are those? Which item has fair password, what is the criteria for password strength?

    There are at least three separate challenges here:

    1. For the security dashboard, the desire is to focus on the items that you should work on, and in this case, the items with the weak passwords; fair usually means that it is not important to change it right now. The biggest security risk is password reuse and very weak passwords. That's what the security dashboard is meant to showcase.
    2. If you select Weak Passwords link on the dashboard, you're taken to the Watchtower item list and you can see the sections of each password strength from terrible to weak.
    3. We do not yet have an advanced search UI implemented to let you narrow down the list item to find certain password strength. This is something we plan to expand on over time. We could also link that search filters to the security dashboard, so clicking fair would take you to the item list of all items with fair passwords.
  • Blake
    edited June 2021

    Hmm. That's still not quite right.

    Could you go ahead and exit the app completely (if you haven't already) restart it, unlock, and check again?

    If nothing changes, let's go ahead grab the logs from the 1Password desktop app, so I can see what's going on behind-the-scenes. To generate and send a diagnostics report:

    1. Open up 1Password 8 for Windows, click the three horizontal bars top-left corner of the app, click File and then Settings from the dropdown menu.
    2. Switch to the Advanced page, and click Send Diagnostics.
    3. Click Reveal to show the diagnostics report in the filesystem. Copy that file, and attach it in an email to [email protected]

  • Thanks a bunch for sending that Diagnostic Report in @Naxterra! 🤗

    We will continue the conversation with you there, via email, so we're not running the risk of missing anything.

This discussion has been closed.