Live data from Hacker News

On Password Managers

tbray.org

201–210 of 347 posts

Re: On Password Managers

#201
post #161

Earlier quoted context omitted.

You have to explicitly sign up for their subscription service, so no, it can't currently be done silently.

You're confusing "they don't do that" with "they can't do that". Their terms of service appears to specifically allow this: You agree to grant AgileBits, Inc. a license to store, retrieve, backup, restore, and otherwise copy Your Data so that we may provide you with the Service.

If you don't have a 1Password cloud account, you're not using their "Service".

Re: On Password Managers

#202

I use Enpass on Linux, Windows, OS X, Android, and iOS. I also use the Chrome extension. It has a similar user experience to 1Password, but is actually serverless (you sync your encrypted blob to a cloud service of your choice, or not at all). I wish Enpass were open source, but I can understand their decision not to make it so -- its desktop application is free and its mobile apps include a small perpetual license f…

I've used it but there are two major issues they still haven't fixed.

On windows there's some bug with a qt library they're using that, of all things, messes up network connectivity. It does polling of the network interfaces every 30 seconds (I believe) which causes traffic to completely stop for a couple of seconds.

On Android at least, it is EXTREMELY slow. Search works about 10% of the time, and the other 90% of the time you have to kill the app and relaunch it.

Re: On Password Managers

#203
post #160

Earlier quoted context omitted.

This won't help new users, but for people who own a previous release (before it turned into a "modern app") you can still download 1Password v4 for Windows. https://app-updates.agilebits.com/

I have it and it's terrible IMO.

As another opinion, I use 1Password 4 for Windows, and am quite happy with it.

Re: On Password Managers

#204

Earlier quoted context omitted.

How could that possibly happen? Local vaults can't just silently turn into cloud vaults, Why not, all they'd have to do is copy the local vault to their cloud service and you'd never notice until you discover that the local file you're syncing somewhere else no longer contains your new passwords. I'm not saying they've done this, but they could.

You're confusing what's theoretically possible with what they're actually doing. You asserted that they did something that they categorically do not do , and are trying to defend it by saying "but they could!". I don't understand why you're doing this though, unless you're trying to intentionally create FUD around 1Password.

You asked "How could that possibly happen". I gave an answer for how that could possibly happen.

Re: On Password Managers

#205
"2. In­stall a cam­era any­where I work and fo­cus it on my hand­s"

I feel like we need to be talking about this more. For all the hullabaloo concerning password strength and encryption key length, MANY of our secret key entry methods would be quite easily defeated by a common webcam and a pair of human eyeballs.

That's kind of scary! It's not about to make me stop using passwords, but it is going to make me stop and think before I log into anything in a coffee shop.

Re: On Password Managers

#206

Earlier quoted context omitted.

You're confusing what's theoretically possible with what they're actually doing. You asserted that they did something that they categorically do not do , and are trying to defend it by saying "but they could!". I don't understand why you're doing this though, unless you're trying to intentionally create FUD around 1Password.

You asked "How could that possibly happen". I gave an answer for how that could possibly happen.

Not very helpful. I wasn't asking you to theorize on how AgileBits could change 1Password in the future to do that. Rather, I was expressing skepticism that events happened as you described (e.g. that 1Password just arbitrarily decided to convert local vaults to cloud vaults without any instruction from you).

Re: On Password Managers

#207

Earlier quoted context omitted.

Is 1Password membership not inclusive of advanced sync options? edit: I thought it was, but not sure.

Yes, you can make/use local vaults (and sync them e.g. using Dropbox) on iOS/macOS with a membership. Open 1Password, then "Preferences -> Advanced -> Allow creation of vaults outside of 1Password accounts". Also see: https://discussions.agilebits.com/discussion/comment/316463/...

You can do that, but those local vaults aren't part of the team/family.

Re: On Password Managers

#208

I use Enpass on Linux, Windows, OS X, Android, and iOS. I also use the Chrome extension. It has a similar user experience to 1Password, but is actually serverless (you sync your encrypted blob to a cloud service of your choice, or not at all). I wish Enpass were open source, but I can understand their decision not to make it so -- its desktop application is free and its mobile apps include a small perpetual license f…

I can definitely endorse Enpass as a great product. I never used to believe in password managers but the past year has made a believer of me. I had the passcode to our garage door stored as an encrypted note and ended up getting home for ElixirCon via a late night Uber and rather than wake up the family, I looked it up in Enpass, keyed it and and it was perfect.

I have it on all my Macs, my iPad and iPhone and sync via Dropbox has been flawless so far.

Re: On Password Managers

#209

I'm a 1Password user, and have synced my vault between devices through both Dropbox and iCloud at various points. I can't help but feel like either there's something I'm missing or something everyone else is missing, which statistically means that it's most likely me. But: When I sync with iCloud, Apple can't read my vault--even though it's on their servers, it's strongly encrypted with my passphrase, and the encrypt…

It's more that in-browser JS changes all the time and is basically never audited, nor can it be pinned and prevented from changing. It'd be downright trivial and unnoticeable to change it to capture your password rather than to behave as advertised.

Compare that with the app. Sure it has an updater, but you can use it offline. Don't trust it in day-to-day affairs? Block network access. You can reliably not trust it, and trust that it hasn't exposed your password behind your back (minus on-disk, but that's a risk either way, and it's more audit-able / third parties can build against the format to verify it independently).

Re: On Password Managers

#210

Earlier quoted context omitted.

Yes, you can make/use local vaults (and sync them e.g. using Dropbox) on iOS/macOS with a membership. Open 1Password, then "Preferences -> Advanced -> Allow creation of vaults outside of 1Password accounts". Also see: https://discussions.agilebits.com/discussion/comment/316463/...

You can do that, but those local vaults aren't part of the team/family.

"You can do that, but those local vaults aren't part of the team/family."

Yes, this is correct. So if you want to share items or share a vault with a family member, you are obligated to store and sync with 1Password servers.

Post reply on HN