Forum Discussion

danielrosehill's avatar
danielrosehill
Occasional Contributor
2 months ago

Passwords that don't save in time

One more thread if I may (would love to hear how folks are managing this).

Firstly, environment details: Linux (Ubuntu) and Chrome for the most part. Extension and client and CLI all jiving happily along. 

1Password is slowly improving my password hygiene and I'm increasingly using the autogenerate features to offload repetitive form completions. 

There's one kink in the workflow however that I haven't figured out yet and I thought I'd see if others have figured out a fix or workaround:

I'll complete a sign-up form and choose the automatically generated credential that 1Password suggests. The UI flow that I'm expecting is for the extension to detect when I complete the form, at which point the extension usually pops up with a notification to save, which I click yes to. 

the problem that I've experienced a few times: this doesn't always work reliably.

The outcome: I've no clue what random credential the password manager set for me and I have to go through an immediate password refresh with the website which sometimes triggers account lockouts due to account freshness filters. 

I'd love to get the automatic save prompt before I register, so that if the credential didn't go through, there's some fallback. Another issue in the workflow is when one password generates a password but it fails validation for whatever reason, which sometimes isn't properly disclosed. 

The issue here becomes that 1Password has saved a credential that never got accepted, requiring manual editing to update it. All small points of friction in the backdrop of an overall smooth user experience, but I thought I'd see if anyone has any ideas. 

 

1 Reply

  • AJCxZ0's avatar
    AJCxZ0
    Super Contributor

    Having encountered the problem of unsaved password quite a few times, I've made the habit of revealing and copying the password into the primary paste buffer. That way I can add it to the item and paste it into the password field if needed - a process which may prompt a save.
    Memory claims that Watchtower might privilege autogenerated passwords, but not pasted passwords which were autogenerated, however that is not a reliable source of truth.

    Password setting workflows which fall far from best practices and don't revel that they can't handle a long password, or don't allow "special" characters because they get passed through to the back end unhashed and will break the database, or are trying to run some JavaScript validation process which only works when typing, or... can result in multiple "old" invalid passwords cluttering the item history as the form is refilled and the new (worse) password is saved. It would be nice to be able to purge these.