1Password X bypasses Duo Prompt

Options

It appears that with 1Password X, the Duo Prompt is bypassed when I visit the 1Password sign in page. Made no difference when I signed out and back in. The Duo Prompt doesn't appear and 1Password Extension 4.6.x is affected.

I haven't disabled Duo at all.


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Sync Type: Not Provided

Comments

  • khad
    khad
    1Password Alumni
    Options

    @wkleem,

    1Password X and the 1Password website use the same authorization. So if you have already authorized in Duo on the 1Password website, 1Password X is already authorized too.

  • wkleem
    wkleem
    Community Member
    Options

    Khad,

    It may have something to do with cookies clearing. I will have to look into that.

    Thanks.

  • beyer
    beyer
    1Password Alumni
    Options

    Let us know how it goes! It should also be noted that Duo is still a beta feature of 1Password accounts.

    --
    Andrew Beyer (Ann Arbor, MI)
    Lifeline @ AgileBits

  • wkleem
    wkleem
    Community Member
    Options

    Hi

    I have tested with 1Password X disabled, with v4.6.x only, and Duo Prompt popped up. Enable 1Password X and the Duo Prompt didn't appear. I cleared cookies prior to going to Teams. 1Password X is currently disabled, for me.

  • beyer
    beyer
    1Password Alumni
    Options

    Thanks for letting us know your results. I've opened an issue on your behalf so we can look into this further.

    --
    Andrew Beyer (Ann Arbor, MI)
    Lifeline @ AgileBits

    ref: b5-3467

  • wkleem
    wkleem
    Community Member
    Options

    Thanks. I have installed 1Password X on my MAC but left it disabled for now.

  • beyer
    beyer
    1Password Alumni
    Options

    You're welcome. I'll keep this thread updated. :) :+1:

    --
    Andrew Beyer (Ann Arbor, MI)
    Lifeline @ AgileBits

  • wkleem
    wkleem
    Community Member
    Options

    1Password X does appear to have teething problems as discussed in other threads like a conflict with some Chrome Extensions?

  • khad
    khad
    1Password Alumni
    edited November 2017
    Options

    It is a 1.0 after all. :) And you're right, Screen Shader seems to prevent 1Password X from working correctly.

    We are still encouraging folks to use the 1Password extension on Mac and Windows instead of 1Password X if they want a more mature solution. We are still full speed ahead on the Mac/Windows apps (and extension!) and don't plan on slowing down there either as we barrel ahead with 1Password X.

  • wkleem
    wkleem
    Community Member
    Options

    Khad,

    No password generator limits it’s usefulness even if the latest Windows v6 and 1Password.com versions cannot generate numeric passcodes-

    Thanks.

  • khad
    khad
    1Password Alumni
    Options

    Thanks for reminding us that this is important to you. It's on our list. :+1:

  • wkleem
    wkleem
    Community Member
    Options

    Hi. With X v1.2 I managed to see that Duo now works with 1Password X but I haven’t investigated further other than seeing a Duo Prompt and it appears to work.

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    :) :+1:

  • wkleem
    wkleem
    Community Member
    edited December 2017
    Options

    Hi

    Also, unlike 1Paasword Extension v4.7.0.1 and 1Password 4 or 6, I am still seeing a double unlocking. First one like the usual unlock for local vault and second one like a sign in to 1Password.com

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    @wkleem: I'm not sure what you mean by "double unlocking". Would you be able to record a video, or give exact steps with screenshots about what you're seeing? That sounds really weird.

  • wkleem
    wkleem
    Community Member
    Options

    Here is what I meant:

    First Master Password unlock

    Second

    I see this irrespective of whether I am on the MAC or Windows.

  • wkleem
    wkleem
    Community Member
    edited December 2017
    Options

    I noticed when the single Master Password unlock for 1Password X appeared, Duo Prompt stopped appearing.

    I will report back in a day or two.

  • wkleem
    wkleem
    Community Member
    edited December 2017
    Options

    A double Master Password thread early December:

    https://discussions.agilebits.com/discussion/84644/double-password-to-get-into-1password-x#latest

    Apologies for the duplication.

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    @wkleem: No worries. Just want to make sure we're on the same page here. I apologize if I'm misunderstanding, but it seems like this is working as intended: while 1Password X can unlock multiple accounts together if they're using the same Master Password, you should have to lock 1Password X and unlock it again using the correct Master Password if they are different. We recommend using a single long, strong, unique Master Password for 1Password as a whole, not multiple 1Passwords. You're welcome do do so if you wish, but it will mean you'll have not only more to remember (or forget) but also to type in to unlock. :blush:

  • wkleem
    wkleem
    Community Member
    Options

    I found it strange as from my diagnostic session with you for the MAC, I removed the local vault which I have not re added so only one Master Password for 1Password.com not two but I still saw the above screens.

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    @wkleem: Can you clarify what you mean? That does sound a bit odd, but I'm not sure how a local vault would be involved here. 1Password X only works with 1Password.com accounts. How many of those are you using in 1Password X?

  • wkleem
    wkleem
    Community Member
    edited December 2017
    Options

    Hi

    I do have 60 vaults of which quite a few are test vaults.

    I am waiting for improvements in Windows to match MAC Security Audit.

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    @wkleem: But all of those should be part of a 1Password.com account, not local vaults (which don't work in 1Password X) unlocked with different Master Passwords. And I don't think that Security Audit coming to the Windows app soon will help you with this. 1Password X unlocking accounts separately when the Master Password is different is by design.

  • wkleem
    wkleem
    Community Member
    Options

    I thank you for your team's input. I thought I would highlight what I thought was an anomaly when traditionally, I only needed one Master Password to unlock and now I may need two.

    I have not actually set up any alternate Master Password for 1Password.com vaults. They have been the same since I signed up.

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    I thank you for your team's input. I thought I would highlight what I thought was an anomaly when traditionally, I only needed one Master Password to unlock and now I may need two.

    @wkleem: Ah, I see. That makes perfect sense. Indeed, while the native apps have sort of faked this by using the Master Password for the first vault/account to unlock, even when other vaults/accounts required a different Master Password, we're trying to keep 1Password X more in line with the 1Password.com model, since it doesn't have any legacy baggage: each account's vaults can be accessed all together using the account's Master Password. We recommend using one Master Password, but for those who want to use a different one for each account, the accounts will also unlock separately as well.

    I have not actually set up any alternate Master Password for 1Password.com vaults. They have been the same since I signed up.

    To be clear, it isn't possible to set vault-specific passwords with 1Password.com, as all vaults unlock as part of the account, which has a single Master Password. This has been a conscious decision to bring 1Password more in line with the name "one password", since having separate passwords for each sync'd vault before (using Dropbox, for example) caused a lot of confusion. I'm sorry that by rectifying this we've cause some confusion for you and others who have grown accustomed to the way it worked historically, but long-term it's going to help a lot of people use a stronger Master Password and not get locked out of their data. :blush:

This discussion has been closed.