Skip to main content
ScarySulley
August 26, 2025
Solved

Watchtower and password ages

  • August 26, 2025
  • 7 replies
  • 115 views

Hello,

Watchtower is informing me of accounts that have 2FA available but not enabled. How does 1Password check to see if you have 2FA enabled on an account? I had an account and enabled 2FA and that account was still listed as not having 2FA enabled, even though it was. I then added a 2FA tag to the entry and it was removed from Watchtower. I then added a 2FA tag to another account that was in Watchtower where 2FA was available, but not enabled. I did not enable 2FA on the account, but did add 2FA tag to the entry and that caused it to disappear from Watchtower. Does Watchtower check the account somehow or does it just check to see if you have a 2FA tag on the entry? Not sure if other similar tags would give the same result.

Also, does 1Password 8 have the feature where it has categories on the left side showing passwords that are 3, 6 etc. months old or 1-3 years old?

Thank you!

Best answer by 1P_Dave

@ScarySulley 

Thanks for the reply. If you didn't save a one-time password for a certain website in 1Password, and you used a different 2FA authenticator app instead, then 1Password has no way of knowing that you've enabled 2FA for a website. 

That being said, 1Password's Watchtower feature does know if a certain website offers 2FA since it uses the following website as a source of knowledge: 2fa.directory 

It's a convenient way to know how old a password is and whether or not it's due for a password change.

1Password doesn't include a reminder to change your passwords when an arbitrary amount of time has passed because we don't recommend that practice. Regular password changes for no other reason but because an amount of time has passed is no longer recommended as a security practice by many cybersecurity experts and organizations such as the National Institute of Standards and Technology (NIST).

Instead we recommend that you change your passwords if one of the following conditions is met:

  1. The password for a website/account is not a secure and unique password generated by 1Password.
  2. 1Password's Watchtower sends you a warning that your password for a website/account has been reused or was found in a data breach.


You can read more about how Watchtower helps you keep your
passwords safe here: Use Watchtower to find account details you need to change

-Dave

 

7 replies

1P_Dave
1Password Employee
1Password Employee
August 28, 2025

Hello @ScarySulley! 👋

Thanks for the question! 1Password checks to see if you've saved a one-time password for a certain website in the same login item as your username and password. If you haven't then it'll alert you that 2FA is available for that website. 

If you're using a different authenticator app to store your one-time password then 1Password won't know that you've already enabled 2FA. In those cases you can either add a 2FA tag to the item or click Ignore in the 2FA reminder banner at the top of the item to dismiss the alert. 

Also, does 1Password 8 have the feature where it has categories on the left side showing passwords that are 3, 6 etc. months old or 1-3 years old?

1Password 8 doesn't have this kind of feature. Was there a particular reason why you wanted to see the age of certain passwords? You could sort your items by date to get a sense of when you last updated your items. 

-Dave

AJCxZ0
August 29, 2025

What is 1Password's reference source for sites which offer one-time passwords?

For passkeys we know and and can use Passkeys.directory run by 1Password. There is 2FA Directory, though it's not run by 1Password (which is no impediment).

1P_Dave
1Password Employee
1Password Employee
August 29, 2025

@AJCxZ0 

Thanks for the question. 1Password uses 2FA Directory. I hope that helps. 

-Dave

1P_Dave
1Password Employee
1P_DaveAnswer
1Password Employee
September 2, 2025

@ScarySulley 

Thanks for the reply. If you didn't save a one-time password for a certain website in 1Password, and you used a different 2FA authenticator app instead, then 1Password has no way of knowing that you've enabled 2FA for a website. 

That being said, 1Password's Watchtower feature does know if a certain website offers 2FA since it uses the following website as a source of knowledge: 2fa.directory 

It's a convenient way to know how old a password is and whether or not it's due for a password change.

1Password doesn't include a reminder to change your passwords when an arbitrary amount of time has passed because we don't recommend that practice. Regular password changes for no other reason but because an amount of time has passed is no longer recommended as a security practice by many cybersecurity experts and organizations such as the National Institute of Standards and Technology (NIST).

Instead we recommend that you change your passwords if one of the following conditions is met:

  1. The password for a website/account is not a secure and unique password generated by 1Password.
  2. 1Password's Watchtower sends you a warning that your password for a website/account has been reused or was found in a data breach.


You can read more about how Watchtower helps you keep your
passwords safe here: Use Watchtower to find account details you need to change

-Dave

 

ScarySulley
September 9, 2025

Thanks for clarifying @1P_Dave.

1P_Dave wrote:

Thanks for the reply. If you didn't save a one-time password for a certain website in 1Password, and you used a different 2FA authenticator app instead, then 1Password has no way of knowing that you've enabled 2FA for a website. 

That being said, 1Password's Watchtower feature does know if a certain website offers 2FA since it uses the following website as a source of knowledge: 2fa.directory 

This helps understanding how Watchtower works.

1P_Dave wrote:

1Password doesn't include a reminder to change your passwords when an arbitrary amount of time has passed because we don't recommend that practice. Regular password changes for no other reason but because an amount of time has passed is no longer recommended as a security practice by many cybersecurity experts and organizations such as the National Institute of Standards and Technology (NIST).

Instead we recommend that you change your passwords if one of the following conditions is met:

The password for a website/account is not a secure and unique password generated by 1Password.
1Password's Watchtower sends you a warning that your password for a website/account has been reused or was found in a data breach.

You can read more about how Watchtower helps you keep your passwords safe here: Use Watchtower to find account details you need to change

In regards to the bold text.

If there is a data breach, it might be some time after the data breach is actually reported and Watchtower alerts us. I think it's good practice to change passwords, especially for important websites (such as banks) every so often, just incase IMO. Of course, having 2FA enabled on important websites can help mitigate that threat of a data breach.

Thank you again for the clarifications!

1P_Dave
1Password Employee
1Password Employee
September 9, 2025

Thank you for the discussion! Let me know if you have any other questions in the future. 

-Dave