Skip to main content
August 9, 2022
Question

Disable Password Reauthentication After 2 Weeks in 1Password 8

  • August 9, 2022
  • 27 replies
  • 3619 views

Hello,

On 1Password 7 I remember there being an option to disable reauthentication permanently, this allowed me to use Face ID to authenticate for many months and ensure that I’m not prompted to type in a password (especially in a public place where someone might be behind me).

On 1Password 8 for iOS I see in the settings it states “You’ll still need to enter your account password every 2 weeks or when Face ID isn’t available”.

Is there any way to disable reauthentication via a Master password every two weeks?


1Password Version: 8.9.0
Extension Version: Not Provided
OS Version: iOS
Browser:_ Not Provided

27 replies

1Password Employee
August 9, 2022

Hi @Oddycm

There was an option called "never" in 1Password 7, but it wasn't truly never. There isn't a way to disable this, but I wrote about our latest thoughts on the subject here:

https://1password.community/discussion/comment/650390/#Comment_650390

While I can't promise any specific changes at this point, there are some interesting ideas on the table to make this a better user experience.

Ben

August 9, 2022

I really need this feature back. Or at least an option that is longer than 2 weeks. I don't understand the resistance to offer more options to users...

Jack_P_1P
1Password Employee
1Password Employee
August 9, 2022

Hi @The2ndOctave:

Thanks for your additional feedback here. As Ben mentioned in his linked post, adding the two week timer has reduced the number of forgotten password situations. While I can't promise anything specifically, what would be ideal here is some sort of global sync timer, where entering your account password on your desktop means you won't be prompted on your phone.

Jack

August 9, 2022

+1

Forcing user to enter there Password every 2 weeks will just end with user turning to weak Master-Passwords...

August 9, 2022

That's precisely what I'll have to do if I'm forced to enter the password every 2 weeks. I'll change it to a weaker password—which sucks.

August 9, 2022

+1 on this. I absolutely hate the fact that I need to authenticate every 2 weeks. It’s honestly infuriating. The fact I can’t turn this off and JUST use biometrics is upsetting even further. For security reasons, I don’t want to open my phone up to be prompted to type in a password where I may be filmed doing so.

Same goes for the safari extension. Reauthorising the extension….every week….is not acceptable in my standards. I’d like to see both these options removed and the ability to have ‘Never’, and actually be never.

August 9, 2022

By removing the feature to set Require Master Password to “Never”, you will lose customers. I have the family plan, and this will be a deal breaker for some of us. We will continue to use 1Password 7 for now, but eventually we will switch to another service if this feature doesn’t return.

August 9, 2022

The thing is, it was hard enough to get the octogenarians and nonagenarians in the family to use 1password WITHOUT the mandatory reauthentication. With it? Not possible. Please bring back the “Never” option. Otherwise my parents will go back to reusing the same old password every time and I will be very sad.

August 9, 2022

This leads to a very poor mobile experience- or a very week master password- like the new home screen, the choice is yours!

August 10, 2022

@1P_Ben @Jack_P_1P

It seems there is some pushback to this design decision in 1Password 8, not just here but in a couple other posts and on Reddit as well.

I understand the reasoning falls in the realm of helping users remember their password to ensure they are not locked out, though realistically there is only so much you can do to prevent people from shooting them selves in the foot.

The crowd of people that don’t plan ahead with saving their master password and secret key will always be at risk of locking themselves out, I hope those of us that do have a plan and may even practice our Master passwords by ourselves do not have to be forced to do so by the software.

Furthermore, bringing back the “Never” authentication option may be the simplest path forward rather than something a lot fancier like a global counter.

Please convey these dissatisfactions internally though any ticketing procedures you may have.