Live data from Hacker News

On Password Managers

tbray.org

71–80 of 347 posts

Re: On Password Managers

#71
post #69

Earlier quoted context omitted.

I'm not sure where that concern is founded. They've been extremely clear that: - both products will continue to be supported - your master password doesn't sync to their cloud - your vault doesn't sync to their cloud unless you're using the subscription version and when it does sync, it's encrypted

Well, no, unless I missed something, they have not been clear that local-storage 1Password will continue to work. They have carefully left the door open to changing that at some undefined point in the future. At which point I will migrate away. I love the apps (use it on MacOS and iOS), but local-only storage and non-cloud sync are my hard requirements. I'm willing to pay a monthly rent, but will not 'cloudify' my pa…

Did you see the links included in my parent post? The founder specifically said that standalone vaults will continue to be supported. You don't have to sync your standalone vault to any service if you don't want to. Though of course it'd be difficult to use both the desktop and mobile apps if you don't sync somehow.

Re: On Password Managers

#72
I use Enpass on Linux, Windows, OS X, Android, and iOS. I also use the Chrome extension. It has a similar user experience to 1Password, but is actually serverless (you sync your encrypted blob to a cloud service of your choice, or not at all). I wish Enpass were open source, but I can understand their decision not to make it so -- its desktop application is free and its mobile apps include a small perpetual license fee ($10 per user, one-time). The format of the encrypted blob is a simple SQLCipher database that uses your (memorized) master password as the secret key, so even though the application is closed source, the data seems to be stored in an open format. Overall, it's probably the best option on the market in a very bad category of software. After evaluating them all, IMO, you should run away from 1Password, Dashlane, Lastpass, etc and use Enpass instead. Even better if the place you sync your encrypted blob is protected by strict 2FA and has good (enforceable) privacy policies.

Re: On Password Managers

#73
post #52

The one place that 1Password doesn't meet my needs is in ChromeOS. The browser plugin requires the machine you're on to have the 1Password app running in the background, which is how it gets its data from the local (and synced) vault. But there is no 1Password ChromeOS app (and I don't think it's really even possible for there to be something like that in ChromeOS), so the browser plugin does not work in Chrome on Ch…

I don't use it personally because I have some reservations about it, but Enpass (https://www.enpass.io/) supports ChromeOS. I wish 1Password supported ChromeOS as well.

Re: On Password Managers

#74
post #34

Any password manager recommendations such that people don't need to deal with 1Password's cloud-based storage?

I recently switched from 1password to Enpass and have been very happy. If you want to use more than 20 passwords on their mobile app it will cost you a one time fee of $9.99 per platform. Very reasonable in my opinion. https://www.enpass.io

After evaluating pretty much all free and non-free alternatives to 1Password, I eventually switched to Enpass as well.

Re: On Password Managers

#75
post #27
post #15

Earlier quoted context omitted.

Is it possible to use the 1Password "family" or "team" accounts with Dropbox or iCloud storage?

Yes. (iCloud sync is limited to Mac/iOS devices) https://support.1password.com/sync-options/

No. The alternative sync options are for "If you don’t want the benefits of a 1Password membership", and a "team" or "family" account is by definition a 1Password membership.

Re: On Password Managers

#76
post #17

I totally agree with Tim Bray's post. The bottom line is that the pestering that I get from AgileBits makes me, as a customer, really doubt their integrity after trusting them for years. Why are they trying to force me do to this? Obviously because they want more money (but are betraying their own oft-stated security attitudes) and maybe even for some other reason (the backdoor thing?).

I think they're doing it for 2 reasons:

1. Money, and

2. Significantly reducing complexity and maintenance burden. Supporting cloud-only vaults is a lot simpler than also supporting local vaults plus multiple different third-party sync mechanisms.

Re: On Password Managers

#77
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

> They're promoting cloud vaults and hiding local vaults, and the Windows version of 1Password has apparently never used local vaults. 1Password 4 for Windows uses local vaults just fine - I'm using it right now. The new 1Password 6 for Windows does not support local vaults.

Apart from 1Password 4, there used to be a lesser known 1Password for Windows Modern Alpha/Beta[1] which was a UWP app and supported local vault. The Windows Modern version is no longer in development as far as I know, but I hope they add local vault support to the 1Password 6 for Windows in the future (even though I'm a happy paying 1Password.com user).

[1]: https://www.microsoft.com/en-us/store/p/1password-alpha/9nbl...

Re: On Password Managers

#78
post #40

IMHO this part is where the nail is hit right on the head: >Why is AgileBits doing this? · For the same reason that Adobe has been pressuring its customers, for years now, to start subscribing to its product, rather than buying each successive version of each app. A subscription business is much nicer to operate than one where you have to go out and re-convince people to re-buy your software. It is the part (common t…

The new model is better for you if you want the company to make enough money to be able to support the product and put out new releases to fix bugs and vulnerabilities.

Maybe, then they should say so, indirectly better for me.

But bugs and vulnerabilities? On a years old, widely tested and used "static" (or almost "static" ) product?

How many possible ones they are introducing by completely changing the tool to be on the "cloud"?

Re: On Password Managers

#79
Does anyone know anything about Dashlane? I had a free commercial account from a previous employer and it seemed nice, other than the popup every time you logged in to an unknown website asking you to save your credentials. I'm pretty sure that was configurable, though.

I don't see Dashlane spoken about much in these conversations (I have no affiliation).

Re: On Password Managers

#80

Just to be clear, it's still 100% possible to keep your 1Password vault in Dropbox etc and not use the SaaS version [1]. I felt like this fact was buried in the article. Edit: Here's the link to buy the standalone license [2] which is hard to find on the site now. In a post from the founder one week ago [3] he said, "We know that not everyone is ready to make the jump yet, and as such, we will continue to support cus…

that feature is one of the primary reasons i jumped into the 1password boat from keepass. i have a personal vault and a shared team vault, both sitting on dropbox and shared to various devices and users as required. there is no need to use 1password.com at all.
Post reply on HN