Live data from Hacker News

On Password Managers

tbray.org

261–270 of 347 posts

Re: On Password Managers

#261
post #160

Earlier quoted context omitted.

I have it and it's terrible IMO.

As another opinion, I use 1Password 4 for Windows, and am quite happy with it.

I'm happy with it with Google Chrome, which is what I use on my Windows gaming desktop.

However, on my Surface Pro 4 I use Edge, because it supposedly uses less power than Chrome.

If I've understood the 1Password forums correctly, the Edge integration that they are working on will only be in the subscription version. Those of us staying on 4 will be stuck with manually looking up passwords in 1Password.

Re: On Password Managers

#262
post #87

I use Enpass on Linux, Windows, OS X, Android, and iOS. I also use the Chrome extension. It has a similar user experience to 1Password, but is actually serverless (you sync your encrypted blob to a cloud service of your choice, or not at all). I wish Enpass were open source, but I can understand their decision not to make it so -- its desktop application is free and its mobile apps include a small perpetual license f…

I've recently installed Enpass and I'm currently in the process of evaluating it. I really like the idea so far. My main concern is that they're not charging enough and wonder if the business model is sustainable.

I was thinking exactly the same. However it can't take that much effort to keep it maintained.

Re: On Password Managers

#263
post #78

Earlier quoted context omitted.

Maybe, then they should say so, indirectly better for me. But bugs and vulnerabilities? On a years old, widely tested and used "static" (or almost "static" ) product? How many possible ones they are introducing by completely changing the tool to be on the "cloud"?

1Password had vulnerabilities disclosed by Tavis Ormandy within the last year regarding the communication between the application and the browser extension. Those vulnerabilities were part of the so-called "static" product, and were not related to the new cloud functionality. [0] https://bugs.chromium.org/p/project-zero/issues/detail?id=88...

Yes, I wasn't saying that the one had not bugs, all software may have some of them, I was only saying that the risks of introducing more, new ones when changing completely a software (or rewriting it) are bigger.

Re: On Password Managers

#264
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

I changed from LastPass to 1Password for big part because it was "pay once, use forever" instead of LastPass' subscription service. It hasn't even been 3 years since I switched and I paid what felt like a lot of money, but I figured that it would still be less over all in comparison. Now I can't get my vault to sync on my Windows machine and last time I reinstalled my Mac it was a hunt for the right executable.

I've been considering just going back to LastPass, but it all seems like a hassle. Why am I even paying for these companies if I can't rely on them? I should be paying because I don't want to deal with this shit. Which is ironically why I've toyed around using ownCloud and KeePassXC

Re: On Password Managers

#265

Earlier quoted context omitted.

Why couldn't they offer the native app with local vaults and subscription pricing? I don't mind a recurring fee, its just that I want a native (cloud-free) password manager.

I think you can currently do this? The subscription gives you access to 1Password.com syncing, but you should still be able to sync via Dropbox (or not at all).

I assumed not, but after reading this thread it seems this may be possible?

It's crazy that it isn't clear.

Re: On Password Managers

#266
Password managers are the definition of "putting all your eggs in one basket". You need to compromise 1 (ONE) password to get access to EVERYTHING. They are a lot more convenient, but barely more secure than a plaintext notepad file. And some people actually storing bank accounts and credit cards info there. This is insane to me.

Re: On Password Managers

#267

Earlier quoted context omitted.

On the other hand, the fact that they're saying not everyone is ready "yet" seems to imply that they expect to eventually migrate everyone off standalone vaults.

This is an important point. I think 1Password folks need to hear that for a lot of customers, it will never be the case. There are many of us that consider managing the storage of our vaults as a fundamental safety feature of a password manager and will never cede control over that function to the company behind our password manager. Moreover, subscription pricing is a no-go for many of us. The possibility that a com…

I'm fine with subscription pricing provided the vault format remains published and and accessible and I can control the storage of my vault files if I choose.

I'd even encourage it, I'd like AgileBits to be a long term viable business.

Re: On Password Managers

#268
Is there simple open source non-commercial self-hosted password manager? I need something like 1Password, but with much more primitive interface, 1Password is just too user-friendly for me, so I'm reverted to text files which isn't very good from security point. I don't really need native apps, web interface would be sufficient, of course with crypto implemented in JavaScript.

Re: On Password Managers

#269

With a couple UI/UX enhancements, Apple could take over the iOS/MacOS marketshare of these products with Keychain. It's already possible to use keychain in your workflow for password management, it's just not super convenient. I'd switch from Lastpass, if Apple made it easier to autofill and autogenerate passwords and added support for sharing / teams.

Being Apple, they aren't going to release apps for non-Apple platforms or extensions for other browsers. So they could only take over the marketshare among people who only use Apple products.

Re: On Password Managers

#270
post #228
post #98

Earlier quoted context omitted.

I recently moved to using SyncThing for syncing my keepass database. I realised that syncing it with Dropbox was not that much better than using a Web-based service.

You're mistaken. It's completely different. While all file syncing tools will let the NSA intercept and mess with your data, a web client like 1Password could trivially be modified to intercept a password or decrypt in place and send data back to the mothership in the clear. Dropbox can't force 1Password to modify its binary.

True, Dropbox is better in that regard. Still, the advantage of SyncThing is that an attacker would have to break TLS to even get to the point of entering the master password.
Post reply on HN