Live data from Hacker News

1Password X: A look at the future of 1Password in the browser

blog.agilebits.com

71–80 of 181 posts

Re: 1Password X: A look at the future of 1Password in the browser

#71
post #63

Earlier quoted context omitted.

I'm worried about this too. The entire reason I migrated to 1Password over Lastpass is that I don't trust Lastpass' extension. There are too many edge cases, too much fuzziness around "offline usage", and too much reliance on the browser. 1Password's extension acting as an anchor for 1Password Mini, which runs as a separate application on my desktop outside of the browser ecosystem, is a major draw. I don't see how t…

1Password X is a pure Chrome extension and does not rely on the native app. This has its benefits and obvious drawbacks. Some of the benefits: * Simpler installation * Support for multiple users on the same computer with Chrome user profiles * Support for Chrome OS

Is this an option for Chrome/Linux/ChromeOS users to provide a more streamlined first-use experience? The "a look at the future" and "this is just the beginning" wording in the announcement blog post implies that this is the direction that 1Password is taking as a product, and Chrome support is just the beginning.

As a user who prefers a native implementation, uses local vaults, and uses Firefox, none of these advantages matter much. If it's not "for me", that's totally cool. If this new experience will replace the existing one, 1Password is no longer the solution for me.

Re: 1Password X: A look at the future of 1Password in the browser

#72

In-browser password managers are completely insecure by design. Any site can write whatever they want within the page, so it's easy to fake the prompt and steal the password. The only way to prevent this is if the password manager runs as a standalone application, so that the password is entered outside the browser. 1password has this, and the workflow is fine --- switching to the insecure one makes no sense.

How are sites going to trick the extension into believing the site is on a different domain?

https://blog.lastpass.com/2017/03/important-security-updates...

Re: 1Password X: A look at the future of 1Password in the browser

#73

In-browser password managers are completely insecure by design. Any site can write whatever they want within the page, so it's easy to fake the prompt and steal the password. The only way to prevent this is if the password manager runs as a standalone application, so that the password is entered outside the browser. 1password has this, and the workflow is fine --- switching to the insecure one makes no sense.

How are sites going to trick the extension into believing the site is on a different domain?

The problematic bit is that the browser itself would prompt you for your master password. Getting users into the habit of entering their master password in a browser window means that it's relatively easy for sites to create a fake prompt that's likely to fool a lot of people.

1Password does a couple of things to mitigate this. First, the master password alone would not be sufficient to get access to your passwords. An attacker would also need access to your vault files (for local vaults) or your secret key (for 1Password Accounts, their SaaS offering). Second, the password prompt isn't rendered within the "danger zone" - the part of your browser window where the page you're visiting is rendered. Instead, it's a dialog on top of the extension toolbar where it's distinguishable from the site (at least with the Chrome extension for the standalone version on macOS, I haven't checked to see if this changed).

Neither of these mitigations are perfect. Leaking your master password is obviously bad either way, and while I have some faith in my ability to detect a fake password prompt that's rendered in the wrong position, that's a bit like an anti-phishing strategy that boils down to "always check the domain", which we know doesn't work. Ultimately, not using an extension reduces your attack surface significantly, but incidentally that comes at the cost of some phishing-resistance that you gain from only ever entering your password through an extension matching the domain.

Re: 1Password X: A look at the future of 1Password in the browser

#75

Ugh. Agilebits left out until the very end that this is only for their hosted solution. No surprise but looks like standalone users are left out in the cold. Again. Much as I like and use 1Password every day, I really really do not like the fact that they moved to a hosted model.

> No surprise but looks like standalone users are left out in the cold. Again.

There is no money there, without a MRR companies won't do it.

Re: 1Password X: A look at the future of 1Password in the browser

#77

Am I the only one in here who loves their hosted solutions? We use Teams at work and I use Family for my wife and I. It's important to me that I have access to certain passwords on my desktop, laptop and phone. These items also need to be accessible to others who should be able to view/edit. There's no way to do with without some sort of cloud solution and so the decision becomes which cloud solution. I used to use D…

I disagree. In fact, given the regular loss of online credentials, I think you are misguided in your faith in a hosted password solution. There are plenty of people that do not want to for very good reasons. As far as syncing using non-hosted 1Password, I use a combination of wifi sync (for mobile devices) and Resilio (in local sync only mode, no tracker, no cloud copy a la Dropbox) to sync. Works very nicely across…

Does that work well with multi device updates? What happens if two devices write to the database and then sync?

Re: 1Password X: A look at the future of 1Password in the browser

#78

Ugh. Agilebits left out until the very end that this is only for their hosted solution. No surprise but looks like standalone users are left out in the cold. Again. Much as I like and use 1Password every day, I really really do not like the fact that they moved to a hosted model.

I’m not against the hosted model, but at the moment for me they don’t have enough compelling reasons to use it if you purchased the standalone version. It sounds like they’re trying to get there with X and I wish them luck, but in the meantime I’m a happy standalone user.

I don't think we are. 1Password X is a purely in browser app. It doesn't have local access to your files, it is an extension. The only way for it to get data is from some server outside, i.e. cloud. Don't try to see the malicious intent where it was just practical decision.

At the moment this is the only way to get 1Password to work on Linux (except older OPW4 with local sync support under Wine). I personally happy about it. You don't have to be, if you don't use cloud. No one pushes you.

Post reply on HN