We are updating the 1Password Community between 9am EST and 10am EST on June 12th. The web experience may be impacted during this time.

Forum Discussion

Former Member's avatar
Former Member
4 years ago

Invalid weak password warning.

I'm receiving a weak password warning. The password concerned was generated by 1P, is 31 characters long, and contains a mixture of uppercase, lowercase, numbers, and special characters. I don't believe the warning for this password is valid. I'm obviously not going to post it, but I'm looking at the password and it isn't something that would be at all vulnerable to guessing or a dictionary attack.


1Password Version: 8.4.1
Extension Version: 2.2.3
OS Version: Win10
Referrer: forum-search:https://1password.community/search?Search=invalid%20weak%20password%20warning

16 Replies

  • Former Member's avatar
    Former Member

    ag_mike_d I just tried again, using the browser, and it still says it's weak. When I go to the desktop app for Mac, I don't see this feature that allows you to customize the password.

  • ag_mike_d's avatar
    ag_mike_d
    Icon for 1Password Team rank1Password Team

    Hello @MaRu0610! Thanks for reporting that you are seeing this behaviour as well with a Weak password generated by 1Password. I've included this report within the issue we're currently tracking.

    In the meantime, does following the steps to change and strengthen your passwords in your browser or in the apps, help to improve the password strength rating of those sites you've mentioned?

    ref: dev/core/core#12744

  • Former Member's avatar
    Former Member

    1P_PeterG I'm new to 1P as well and am finding a similar problem. In my search for an answer I see this appears to have been an issue for at least two years: using the password generator but then the password is still categorized as weak, even though it doesn't look particularly weak. So I still have about 5 sites in my "Weak Passwords" category that just won't go away no matter how many times I use the generator to improve it. Is there something I'm doing wrong?

  • 1P_PeterG's avatar
    1P_PeterG
    Icon for Community Manager rankCommunity Manager

    Hi @cresswellc , thanks for these details. We won't ask you to share a test password at this point, but we do appreciate what you've shared so far (and we may be back with a few more questions as things progress).

    We'll dig into this on our end to determine what might be going on here. Thank you for letting us know! I've passed your descriptions here on to our developers for further looking-into.

    ref: dev/core/core#12744

  • Former Member's avatar
    Former Member

    Hi 1P_Blake

    I will definitely have generated the password with the 1P generator. I can’t remember the exact steps by which the password was saved against the particular account, but it’s very likely to have been directly through the application (or phone app), rather than me having pasted it in as a second step.

    I obviously don’t know the criteria 1P is using to judge that password as weak, but it looks to me as random as any other that it generates.

    Do you want me to take a copy of that password to paste here (after changing the password for the service) so you can analyse it offline?

  • 1P_Blake's avatar
    1P_Blake
    Icon for Community Manager rankCommunity Manager

    Hey @cresswellc 👋

    Did you generate this password with the 1Password password generator? Or did you enter it manually or copy & paste it there?