Live data from Hacker News

On Password Managers

tbray.org

81–90 of 347 posts

Re: On Password Managers

#81
post #11

I totally missed this switch by AgileBits. Does anyone know how to ensure that the data file continues to be synced to Dropbox or iCloud, not AgileBits? (Looking into my configuration, it would appear that AgileBits has silently moved my data from iCloud to the AgileBits cloud.) EDIT: Found: https://support.1password.com/sync-with-dropbox/

> Looking into my configuration, it would appear that AgileBits has silently moved my data from iCloud to the AgileBits cloud

How could that possibly happen? Local vaults can't just silently turn into cloud vaults, and you need a subscription license to use cloud vaults anyway.

Re: On Password Managers

#82
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

For Windows, there is "1Password for Windows" and 1Password 4. I've never used the "for Windows" version, but I believe it's cloud only. 1Password 4 allows local vaults. However 1Password 4 is in maintenance mode and missing lots of nice features, like searching two vaults at once.

Re: On Password Managers

#83
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

How do you feel about in-browser password managers--Chrome in particular?

Re: On Password Managers

#84
post #33
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

> I recommend 1Password, and there's currently no other commercial password manager that I recommend. Are there any open source password manager products that you would recommend?

It's not quite ready for prime time yet, but my company is working on Passit[0], which is going to do open source cloud-based password management. Feel free to check it out; we hope to do a 1.0 release soon.

I've been working on the marketing a bit, and the sense I get in this space is that, like home security, password security is a series of trade-offs. One size doesn't fit all; different situations require different needs, and everyone tries to balance the safety they want to feel with convenience that they desire.

So, in our case, there are a couple of good options. You could operate on a hosted service and get the cloud-based benefits without needing to worry about infrastructure or updates, or you could self-host and trade a bit of hassle in exchange for trusting the host and verifying that the updates will do what they say they're going to do.

[0]: http://passit.io

Re: On Password Managers

#85
post #18
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

Lastpass doesn't necessarily have the best track record, and you said you couldn't go into detail, but I'm curious so will ask - if you feel comfortable sharing, what securities issues do you see with lastpass besides storing secrets in some companies cloud?

By default the browser plugin is configured in such a way that 2FA is completely bypassed for a second when logging in. This is officially documented, so we can likely assume that it will never be fixed.

https://lastpass.com/support.php?cmd=showfaq&id=2775

Re: On Password Managers

#86
post #30

I've been using password managers (KeePass, in my case) for about a year and all I can think is, why I didn't start using them earlier. It is cheaper to generate a long, random password using alphanumerical and special characters than trying to think a clever yet memorable unique password by myself, and probably more secure. Plus, it's true that you end up storing other sensible things that are not passwords, such as…

Password managers are indeed a dramatic quality-of-life boost. Social security numbers for important family members, software license keys...one stop shopping for any sensitive or easily-misplaced information in my life.

Re: On Password Managers

#87

I use Enpass on Linux, Windows, OS X, Android, and iOS. I also use the Chrome extension. It has a similar user experience to 1Password, but is actually serverless (you sync your encrypted blob to a cloud service of your choice, or not at all). I wish Enpass were open source, but I can understand their decision not to make it so -- its desktop application is free and its mobile apps include a small perpetual license f…

I've recently installed Enpass and I'm currently in the process of evaluating it. I really like the idea so far. My main concern is that they're not charging enough and wonder if the business model is sustainable.

Re: On Password Managers

#88

I use Enpass on Linux, Windows, OS X, Android, and iOS. I also use the Chrome extension. It has a similar user experience to 1Password, but is actually serverless (you sync your encrypted blob to a cloud service of your choice, or not at all). I wish Enpass were open source, but I can understand their decision not to make it so -- its desktop application is free and its mobile apps include a small perpetual license f…

I'm using Enpass, too. Your sentiments mirror mine exactly. In general I'm surprised they are not getting more press. Perhaps if they were more explicit and open about their underlying data format (the SQLite+SQLCipher database)?

Re: On Password Managers

#89
post #33

Earlier quoted context omitted.

> I recommend 1Password, and there's currently no other commercial password manager that I recommend. Are there any open source password manager products that you would recommend?

Keepass and its various forks are open source. Keepass itself uses dotNet so Linux guys need mono which not all people like. Those people use KeepassXC (a fork of KeepassX which is Keepass in C++ and is unmaintained). I use Keepass. Reasonable security but ugly gui in linux due to mono. Has plugins. Completely offline.

ditto.

+ kpcli for TTY use, keepassdroid for android, sync to owncloud, voila.

If you are extra concerned with security after storing your file remotely, you can have it use an addtional external keyfile in addition to the which you manually copy to 'authorize' devices

Re: On Password Managers

#90

Just to be clear, it's still 100% possible to keep your 1Password vault in Dropbox etc and not use the SaaS version [1]. I felt like this fact was buried in the article. Edit: Here's the link to buy the standalone license [2] which is hard to find on the site now. In a post from the founder one week ago [3] he said, "We know that not everyone is ready to make the jump yet, and as such, we will continue to support cus…

On the other hand, the fact that they're saying not everyone is ready "yet" seems to imply that they expect to eventually migrate everyone off standalone vaults.
Post reply on HN