Skip to main content
August 13, 2021
Question

Two accounts - now needs two different passwords every time you login?

  • August 13, 2021
  • 65 replies
  • 4224 views

With the old version, I was able to have a personal account and a business account. Once I connected them, I only had to use my personal password going forward. Now it looks like I have to enter a password for each account every time I restart my computer?

Is there an option to go back to how it used to deal with accounts? Or am I missing somenting?

65 replies

December 8, 2021

@"jack.platten" I'm not seeing that behavior on Windows. I had a company account manually. I had no idea it was even locked. I couldn't find a password and then went to the vaults and it showed a lock beside it. I was like what the heck is this?? Then I clicked it and it prompted me for the password. It didn't do that before.

December 8, 2021

@"jack.platten" It also doesn't help that there has been zero justification of why this was changed. It feels like development just decided to change it with no thought as to how it would impact anyone.

Jack_P_1P
1Password Employee
December 8, 2021

@shadcollins:

As I mentioned, if you're using multiple account passwords for various accounts, unlocking all of them at least once with your various account passwords will then allow you to use Windows Hello to unlock all these accounts.

In this example, my Jack Platten account, and my Platten Family account use the same account password, while the Wendy Appleseed account is using a separate account password. When I initially unlock 1Password, using the account password for my two actual accounts unlocks both of them, with the Wendy Appleseed account needing to be separately unlocked before I can use Windows Hello (in this case just a PIN, but a Hello fingerprint or face device would work just the same) to unlock all three accounts simultaneously. This behavior would be the same using 1Password 8 for Mac, just with Touch ID or Apple Watch unlock instead of Windows Hello.

Jack

December 9, 2021

While I personally have never used multiple vaults, and thus this change won't effect me, I can actually think of multiple scenarios wherein this change would quickly become a nightmare.

One such scenario I can think of:
* You have a single personal account that you and your partner share.
* You have a work account.
* You help a friend manage his/her account.
* You help a parent(s) manage their account.

In this case, since your personal account is shared with another user, you would want it to have a unique password from your business account. Since you are helping manage a friend's account s/he will want to have their own password. And finally, with your parent, again there will be a separate password. In this scenario it would be completely untenable for each of these accounts/vaults to have the same password. As such, we are up to 4 unique passwords that would need to be entered in each time. While TouchID or Windows Hello could help mitigate this to an extent, every time you restart your computer or 1Password has to be re-authenticated you would have to put in each password again. This is significantly exacerbated by computers that DO NOT SUPPORT TouchID or Windows Hello - and there are quite a few out there that don't.

This is yet another example, in a sea of examples, where 1Password 8 introduces a major change that completely breaks users workflows, and it continues to show that the developers have simply not thought everything through when it comes to 1Password 8.

December 11, 2021

It also doesn't help that there has been zero justification of why this was changed. It feels like development just decided to change it with no thought as to how it would impact anyone.

The main reason for this change is that this new way makes sense. It isn't what we've grown used to, but it really is far more coherent than the sort of kludge that evolved over time with "primary accounts.

Suppose Patty has two accounts. One of them is her personal account and the other is with her job at the DIA (Dog Intelligence Agency). Patty does not want account PW unlocked most of the time, but she does want PP unlocked most of the time. In particular, she doesn't want the unlocking of the two accounts in lockstep. (All puns intended.) So. what does she do? She sets up a different account password for each. (Many of my examples involve my dogs Patty and Molly.)

Molly, on the other hand (paw) has a personal account, MP, and a work account, MW. She wants to unlock both with a single account password. If you (or Molly) want to unlock two accounts using a single account password it makes most sense to set the same account password for both of those accounts. This is what I meant when I said the new system makes more sense.

Suppose also that the DIA (not being as intelligent as their name claims) insists that account passwords be changed every two dog years. (Or every four months). If Patty always unlocks her work account with her personal account password she is certainly violating the intent of her employer's policy. Probably the letter of it as well. This is just one of the ways in which Patty may want to need different account password practices for her different accounts. She most certainly does not want to change her personal account password every few months.

Molly wants her account unlocking to be in lockstep with each other. The most natural and semantically coherent way to achieve that is to have the same account password for those accounts she wants to unlock as a group.

The old system

In the old system, there was a little known and poorly understood concept of "primary account." It would, on your own disk, have encrypted secrets needed to unlock other accounts. Your primary account was rarely something a user chose for that purpose, but instead was a consequence of the order in which they set up their accounts on that device. It was fairly arbitrary which account became the primary.

One difficulty with the lack of transparency to the user about what account password was unlocking what is that users could forget that they even had a different account password for their non-primary accounts. Forgetting you have a separate password for an account is a good way to forget that password. Suppose Molly was using the old system. She regularly unlocked both her accounts with the password for her primary account on her computer. Note that "primary" may not mean the one that has the information that Molly needs the most. It just happens to be the one that she set up first on that device. She is never prompted for the account password for the "secondary" account (which might contain the most important data for her). She forgets that secondary account password and she forgets that she even has a different password for that account.

Now suppose the nefarious Mr Talk (the neighbor's cat) steals Molly's computer, and there is no way for Molly to get it back from him. Molly also doesn't have good back ups. So now Molly needs to set things up on a new computer. She does have her Secret Keys for both accounts safely stored for such an event, but she doesn't have the passwords written down because she is supposed to remember them. She can set up her new computer and unlock what was in her old primary account, but she has no way to unlock what was under an account password that she'd forgotten about.

This kind of problem is the result of the old system being very opaque to users. Now having a much clearer relationship between account password and the accounts it unlocks should very much reduce that problem. If you want multiple accounts to unlock when you give a single account password there is a very natural thing to do about it. You no longer have silent unlocking of accounts.

Somewhere above I gave a bit of a history lesson. The old system was never designed for a world in which lots of users have multiple accounts. Instead it was the result of hacks and patches to a system that was originally built for individual users who would have a single vault/account. The people who started playing with multiple vaults were expert users who had to do additional tricks to synchronize data from multiple vaults. It also wasn't even consistent across platforms. Now we make it easy for people (and dogs) to have multiple accounts, and these different accounts are part of different teams and families with their own policies. So we took the opportunity to design unlocking in a way that makes sense on their own at the expense of a substantial behavior change.

December 12, 2021

@jpgoldberg You've conveniently ignored some of the legitimate points made here (including my example above) about how this change is completely destroying people's work flow, and is in many way completely untenable going forward. Perhaps give users a choice to setup a primary account, and have that password open up the other accounts.

Or, better yet, why not allow users to setup a PIN code for all of their accounts? This PIN code would be device specific, so it wouldn't compromise security. Each account could have their own PIN code, thus forcing the user to enter each PIN individually. Or, you could create the same PIN for all of your accounts, thus allowing you to unlock all of the accounts at once (just like if they all used the same password).

Alas, based on the history of the 1Password 8 development cycle, most legitimate user suggestion have been flat out ignored (i.e. search is still broken, categories are still hidden behind a drop down menu, etc.)

December 12, 2021

So maybe have an "App Master Password" for the app itself and we can choose which vaults/accounts the app master password unlocks?

December 13, 2021

So maybe have an "App Master Password" for the app itself and we can choose which vaults/accounts the app master password unlocks?

@adamjb, can you let me know what that does for you that setting all of the account passwords the same doesn't?

December 15, 2021

@jpgoldberg Dude, read my above posts and you’ll find your answer.

December 15, 2021

It appears that I failed to read to read carefully enough what people have written, I apologize for that.

Sharing an account password?

If I understand correctly (and I may still be failing to understand), some of you have a workflow in which you actually share account passwords with some clients. That is, you may be consulting for Alice and fully managing her account to the point where you, the consultant, has Alice's account password. Naturally, you would want to unlock a whole bunch of such accounts at once, but you don't want to let Alice have your account passwords for your other accounts,

If that is what is going on (for some of you) then, yes, the new system really does break that workflow, and badly. It is easy for me to say that you shouldn't have a shared account password (and I do say that), but when a client just asks you to take care of things and doesn't want to deal with anything more complicated for them, you are kind of stuck.

Possible work-around

I think that there is a work-around, but it isn't pretty. On the other hand, having two people use the same account password is inherently ugly anyway. The work around is also more expensive. (This isn't some plot to get your clients to send us more money, but it may have that consequence.)

Each of your clients need to have their membership in a non-Individual account. Individual accounts are simply not set up for sharing. Whether that is a team that you are the owner of, or whether you direct your clients to set up a non-individual account will probably depend on your client's needs. But let's suppose it is a separate account "owned" by Alice, even though you set everything up. You make yourself a co-owner of Alice's account. And you create your own membership on her account. You then set up a shared vault (or several) on that account between you and Alice. Alice keeps her own individual account password (although you will know it, you will rarely need it beyond setup). For your membership on Alice's team or family you can use the same account password that you use for all of your clients. So you can get all of those vaults to unlock with a single account password of your choosing without giving Alice and other clients a password that is used for anything other than their own account.

Setup is a bit more complicated, and it won't really work if each of your clients only have Individual accounts, but it makes the flow more coherent. There is not going to be a pretty solution to multiple individuals using the same membership, and thus the same account password. But perhaps this work-around will work for you or at least help you come up with solutions that don't go so much against the grain of what Individual accounts are for.