Live data from Hacker News

On Password Managers

tbray.org

121–130 of 347 posts

Re: On Password Managers

#121

If I understand correctly, the main problem here is that if a password manager at some point asks you for a password in an online environment, they're subject to coercion. This is especially dangerous if you're using auto-updating code like Javascript in a browser or code on a remote service, because it could get backdoored at any time and you wouldn't notice. Isn't the real problem auto-updating code with access to…

> Isn't the real problem auto-updating code with access to a network?

At least in theory you can sandbox an app so that it does not have (unlimited) access to the network.

Re: On Password Managers

#122
post #15

Just to be clear, it's still 100% possible to keep your 1Password vault in Dropbox etc and not use the SaaS version [1]. I felt like this fact was buried in the article. Edit: Here's the link to buy the standalone license [2] which is hard to find on the site now. In a post from the founder one week ago [3] he said, "We know that not everyone is ready to make the jump yet, and as such, we will continue to support cus…

Is it possible to use the 1Password "family" or "team" accounts with Dropbox or iCloud storage?

I was not able to do that with standalone 6.8 for mac and ios. I bought 1Password back in version 4.2, and have gotten free automatic upgrades to 6.8. I believe I even bought the family plan back then, but when I tried to use it recently, I got nothing but dialogs asking me to log in to 1password.com (which I don't have an account on), and/or get a subscription which I have no interest in doing.

It was only by trying to activate an additional family account did I discover the change in the business plan.

Re: On Password Managers

#123
post #97

Earlier quoted context omitted.

> "Today, over 95% of our revenues are coming from subscribers" https://blog.agilebits.com/2017/07/13/why-we-love-1password-...

That doesn't explain why the old model became or didn't become unprofitable...

The parent comment was a loaded question that there was some sudden change. If the old model did good / better, they wouldn't have switched to a more profitable model. I believe it's well established in our industry that SaaS models are more profitable than one-time software sales. The analogy is equivalent to why Adobe switched Photoshop to a SaaS model and why Microsoft did the same for Office. Recurring revenue is king in the long run.

Re: On Password Managers

#126
post #78

Earlier quoted context omitted.

The new model is better for you if you want the company to make enough money to be able to support the product and put out new releases to fix bugs and vulnerabilities.

Maybe, then they should say so, indirectly better for me. But bugs and vulnerabilities? On a years old, widely tested and used "static" (or almost "static" ) product? How many possible ones they are introducing by completely changing the tool to be on the "cloud"?

It's not a static product even if the feature set is relatively static. Take a look at their Mac app changelog for instance.

https://app-updates.agilebits.com/product_history/OPM4

Re: On Password Managers

#127
post #76
post #17

I totally agree with Tim Bray's post. The bottom line is that the pestering that I get from AgileBits makes me, as a customer, really doubt their integrity after trusting them for years. Why are they trying to force me do to this? Obviously because they want more money (but are betraying their own oft-stated security attitudes) and maybe even for some other reason (the backdoor thing?).

I think they're doing it for 2 reasons: 1. Money, and 2. Significantly reducing complexity and maintenance burden. Supporting cloud-only vaults is a lot simpler than also supporting local vaults plus multiple different third-party sync mechanisms.

Generally speaking, when a vendor want more money to do less, it's time to get a new vendor.

Re: On Password Managers

#128

I have 1Password and I love it. But my biggest fear that I have is; if my laptop was ever pwned in some way, due to some noval 0-day etc - is that everything stored in 1Password could be compromised. But more importantly - the hackers would have an address book of banks, servers, databases etc that I have access to. I dont know if there is a solution - but I feel it is like putting all your eggs in one basket.

you would still need to use your master password to unlock the vault

Re: On Password Managers

#129
post #18

Earlier quoted context omitted.

Lastpass doesn't necessarily have the best track record, and you said you couldn't go into detail, but I'm curious so will ask - if you feel comfortable sharing, what securities issues do you see with lastpass besides storing secrets in some companies cloud?

To start, the LastPass browser extension auto logout feature has critical bugs. I've come back to my computer after several days and found it still logged in with full access to the vault (no master password re-entry required) even with auto logout set to 15 minutes of inactivity. After that happened several times, I lost trust in the product.

There is also a serious bug regarding 2FA. There is a race condition where if you know a users master password you can bypass 2FA for 1 single login.

Apparently someone commented below that is a documented "feature". Wow.

Post reply on HN