Invalid weak password warning.

cresswellc
cresswellc
Community Member

I'm receiving a weak password warning. The password concerned was generated by 1P, is 31 characters long, and contains a mixture of uppercase, lowercase, numbers, and special characters. I don't believe the warning for this password is valid. I'm obviously not going to post it, but I'm looking at the password and it isn't something that would be at all vulnerable to guessing or a dictionary attack.


1Password Version: 8.4.1
Extension Version: 2.2.3
OS Version: Win10
Referrer: forum-search:invalid weak password warning

Comments

  • Hey @cresswellc 👋

    Did you generate this password with the 1Password password generator? Or did you enter it manually or copy & paste it there?

  • cresswellc
    cresswellc
    Community Member

    Hi @Blake

    I will definitely have generated the password with the 1P generator. I can’t remember the exact steps by which the password was saved against the particular account, but it’s very likely to have been directly through the application (or phone app), rather than me having pasted it in as a second step.

    I obviously don’t know the criteria 1P is using to judge that password as weak, but it looks to me as random as any other that it generates.

    Do you want me to take a copy of that password to paste here (after changing the password for the service) so you can analyse it offline?

  • Hi @cresswellc , thanks for these details. We won't ask you to share a test password at this point, but we do appreciate what you've shared so far (and we may be back with a few more questions as things progress).

    We'll dig into this on our end to determine what might be going on here. Thank you for letting us know! I've passed your descriptions here on to our developers for further looking-into.

    ref: dev/core/core#12744

  • MaRu0610
    MaRu0610
    Community Member

    @PeterG_1P I'm new to 1P as well and am finding a similar problem. In my search for an answer I see this appears to have been an issue for at least two years: using the password generator but then the password is still categorized as weak, even though it doesn't look particularly weak. So I still have about 5 sites in my "Weak Passwords" category that just won't go away no matter how many times I use the generator to improve it. Is there something I'm doing wrong?

  • Hello @MaRu0610! Thanks for reporting that you are seeing this behaviour as well with a Weak password generated by 1Password. I've included this report within the issue we're currently tracking.

    In the meantime, does following the steps to change and strengthen your passwords in your browser or in the apps, help to improve the password strength rating of those sites you've mentioned?

    ref: dev/core/core#12744

  • MaRu0610
    MaRu0610
    Community Member

    @ag_mike_d I just tried again, using the browser, and it still says it's weak. When I go to the desktop app for Mac, I don't see this feature that allows you to customize the password.

  • MaRu0610
    MaRu0610
    Community Member

    This is what I see in the app for Mac. I've been wondering how to arrive at a customization option because in the manager that I used before 1P that feature was right in the pop-up generator. This seems complicated.

  • Hi @MaRu0610, thanks for helping us understand your use case!

    We're working on making the password-rating system as consistent as possible across apps (it works well in the large majority of cases, but we do see examples from time to time where it judges a genuinely strong password as "weak" or "fair", and we're working to improve in that area).

    You mentioned:

    When I go to the desktop app for Mac, I don't see this feature that allows you to customize the password.

    Assuming you're using 1Password 8 for Mac (feel free to let me know if you're on something different), you can:

    1. Select your item of interest from the list
    2. Select Edit
    3. Select the item's password field, then Create a New Password
    4. Here, you'll find a password generator menu that lets you adjust the password length, type of password (random, memorable, and so on), and whether it uses numbers or symbols.

    You can find a similar password generator feature in the browser as well.

    Let me know if this is helpful for your purposes - and we appreciate your feedback!

  • MaRu0610
    MaRu0610
    Community Member

    @PeterG_1P I had been using 1P7 but just discovered Version 8 a few hours ago. The passwords still showed as "weak" but after changing them one more time, they are now "fantastic". Phew! And in 8, I am now seeing the customizer.

    Here's a new issue, though. On login pages the little 1P icon appears in the login boxes but it doesn't populate anything. I still have to move my cursor up to the top of the menu bar and work from there. At least it's working now but it seems like it should work from the login boxes themselves.

    Thanks for your help today!

  • Good morning @MaRu0610, thanks for the update about using version 7. I happy to hear you were able to resolve this password strength issue after updating to version 8! Great news!

    With regard to your new issue with 1Password in the browser, can you right click the 1Password icon > Settings and scroll down to Autofill and check that Show Autofill on Field Focus is enabled. If not, enable it and completely close and restart the browser and let us know if this helps.

    As next step, does removing the extension and reinstalling it help at all. You can download a fresh copy of the extension here: 1Password in the browser

    Let us know how this goes!

  • MaRu0610
    MaRu0610
    Community Member

    @ag_mike_d So, the AutoFill was enabled already. I removed the extension and am trying to download a fresh copy. Should I have to download the entire desktop app again? Because that seems to be what happened. Should I trash the entire app, too, or just the extension?

  • Hello again @MaRu0610, let's try just the extension to start. Ensure the app is completely closed and remove only the extension. Then close and reopen the browser window to install 1Password in the browser.

    Please let us know if this helps with the missing inline menus in those fields. Thanks!

  • MaRu0610
    MaRu0610
    Community Member

    @ag_mike_d Okay, looks like I finally have it all sorted out. Thanks for your help!

  • Thanks for letting us know, @MaRu0610 - and we'll be here if there's any further assistance we can offer!

  • mscx
    mscx
    Community Member
    edited July 2022

    Hi, I am also having problems with weak password warnings but found a funny workaround for this issue:
    The password of a login is marked as "terrible" (though it was generated by 1Password). I now edit the item, let 1Password generate a new password (copied the old one to the clipboard before) and save it. After that I edit the item again and replace the new password with the old one by pasting it from clipboard. After saving the item again the password is now marked as "fantastic". The "weak" password has been generated with 1Password 7.x.

    1Password for Windows 8.7.3
    Windows 10 Pro (21H2) 64-bit

  • Hey @mscx, thanks for reaching out. We greatly appreciate you sharing your experience with this issue and workaround. I'll pass these details along to our developers for further investigation.

    Thanks again and let us know if there's anything else we can help with!

    Ali

    ref: dev/core/core#12744

This discussion has been closed.