Forum Discussion

ScarySulley's avatar
ScarySulley
Occasional Contributor
2 months ago
Solved

Watchtower and password ages

Hello, Watchtower is informing me of accounts that have 2FA available but not enabled. How does 1Password check to see if you have 2FA enabled on an account? I had an account and enabled 2FA and tha...
  • 1P_Dave's avatar
    1P_Dave
    2 months ago

    ScarySulley​ 

    Thanks for the reply. If you didn't save a one-time password for a certain website in 1Password, and you used a different 2FA authenticator app instead, then 1Password has no way of knowing that you've enabled 2FA for a website. 

    That being said, 1Password's Watchtower feature does know if a certain website offers 2FA since it uses the following website as a source of knowledge: 2fa.directory 

    It's a convenient way to know how old a password is and whether or not it's due for a password change.

    1Password doesn't include a reminder to change your passwords when an arbitrary amount of time has passed because we don't recommend that practice. Regular password changes for no other reason but because an amount of time has passed is no longer recommended as a security practice by many cybersecurity experts and organizations such as the National Institute of Standards and Technology (NIST).

    Instead we recommend that you change your passwords if one of the following conditions is met:

    1. The password for a website/account is not a secure and unique password generated by 1Password.
    2. 1Password's Watchtower sends you a warning that your password for a website/account has been reused or was found in a data breach.


    You can read more about how Watchtower helps you keep your
    passwords safe here: Use Watchtower to find account details you need to change

    -Dave