Skip to main content
January 21, 2022
Question

Master Password required to be entered every 2 weeks on Beta 8.5.0

  • January 21, 2022
  • 16 replies
  • 781 views

On the beta Mac version 8.5.0, there is no way to disable "Master Password required to be entered every 2 weeks". Could you give me a way to do that?


1Password Version: 8.5.0
Extension Version: Not Provided
OS Version: Mac OS 12.1
Referrer: forum-search:https://1password.community/search?Search=2%20weeks

16 replies

August 6, 2022

Until yesterday, I thought it is arbitrary and pestering to require the master password sometimes, although a pin is set.
Until I learned my father, always using the Windows hello pin on his computer, completely forgot his Windows password behind his pin. He didn't record it anywhere, even he thought he has. He used only the pin, for months, probably a year or longer. I had to use some recovery means to get him back into full usage of his account.
So I admit it's actually a good thing to require the master password now and then to remind you to memorize it.

1Password Employee
August 7, 2022

Thanks for sharing that anecdote, Former Member. Indeed; this was a common case before the requirement was added, and has significantly decreased since adding it. 1Password intentionally cannot recover your account password if you forget, making it that much more important.

Ben

August 13, 2022

As a service you trust with securing your passwords and other sensitive data, we take your security seriously and are partially responsible for it.

I didn't have to trust 1password this much until now that I am forced to use the cloud service. Since the very beginning 1password had made it very clear that the user was the only one that's solely responsible for securing the vault, master password and secret key because the data is encrypted/decrypted locally. By requiring your users to enter the password more often, the responsibility structure does not change a tiny bit -- it only reduces your support cost because the average Joes will be less likely to forget the password and waste your support resource. What's worse, now you push advanced users to choose less complex passwords so they are easier to type in on smart phones.

1Password has a lot of enterprise customers now, and you surely can understand that different businesses may have different threat models. My company has our own protocols to deal with forgotten or compromised passwords and it is not up to the vendor to say "No, you can't forget your password or terrible things will happen to you". In version 7, the "Never" option is hidden deeply in an advanced setting screen, why is that not enough? Why is "2 weeks" an ok threashold for every single user?

August 13, 2022

@zzyzxd +1

August 29, 2022

Um, VERY flawed thinking. I have multiple vaults, I have complex master passwords. Of course I don't remember them, but I have them available in case of an emergency, new install, etc. But now you are forcing me to put them on paper in front of the computer because I can't get to them any other way (they are stored, but not conveniently depending on where I am) once you lock me out.

September 7, 2022

I'm confused. When you set up 1P8 an Emergency kit is created which you are advised to print out and safeguard. On the page is an entry for your Master Password. The entry must be hand written unless you have a pdf reader that allows you to create text fields.
That is 1P making sure you are safe, all this other stuff for making you not forget your password by forcing you to enter it every now and again is 1P in Nanny State mode.