Live data from Hacker News

1Password X: A look at the future of 1Password in the browser

blog.agilebits.com

131–140 of 181 posts

Re: 1Password X: A look at the future of 1Password in the browser

#131

Ugh. Agilebits left out until the very end that this is only for their hosted solution. No surprise but looks like standalone users are left out in the cold. Again. Much as I like and use 1Password every day, I really really do not like the fact that they moved to a hosted model.

Just to add on to this now that I see that Agliebits staff are in this thread. I'm not against paying for major version updates. Think of it as a tradeoff between time to market vs. revenue. I'm fine with Teams getting features first (other than security fixes) and paying more infrequently than subscription. It's certainly a business model that previously sustained Agilebits and plenty of other software providers. I…

Thank you, @newman314!

While we think that subscription makes it easier to use 1Password and not have to purchase apps and upgrades for every platform, there are many users that prefer to use licenses. We are going to support both for upcoming 1Password 7 on Mac and Windows.

The same is true for 1Password service vs host-it-yourself model. I have 30+ vaults shared with my team and family and it is much easier to use the service but I can still keep the data locally and set up sharing manually if needed.

There are some features that are simply not possible without the servers doing the heavy lifting: shared vaults and permissions, travel mode, Chromebooks, etc. I just hope that technically savvy HN crowd understands that and doesn't see it as an attempt to push everyone to have a subscription.

Roustem, Founder of AgileBits

I used to develop 1Password for Mac and iOS. I now develop 1Password service with Go, ReactJS, and Terraform/AWS.

Re: 1Password X: A look at the future of 1Password in the browser

#132
post #115

There is a segment of your users that still want the original 'on-prem' version that you started out with. These nerds have money and understand you want a sustainable business model. Just charge these people an annual software maintenance fee and stop neglecting the standalone version. Yes it wont satisfy everyone, but it will stop all the negative PR that comes out whenever you do something that is artificially clo…

Disclosure: I work for AgileBits, makers of 1Password How are we neglecting our standalone users? I'm really curious here because we are still introducing features in our existing applications that work for our standalone users. Certain new applications like 1Password X and our CLI are only really easily possible because of 1Password.com, but just because these are being offered doesn't mean we're neglecting our stan…

You don't discard them completely, but new things that can be made by reading local files vs using a cloud API are just made using a cloud API. Updates to current apps I'm guessing will still support local file users if it's easy.

Your website has no obvious way on how to buy the standalone version now. It's pretty obvious through behavior that it's a deprecated mode without stating it outright.

Most people can deduce it's an official PR position to deny the behavior that is being shown, like your doing right now.

But please, just be honest and say it's deprecated. Or start supporting the on-prem users again & ask for a software maintenance fee. None of this on the fence stuff. One guy that I have seen that has done it out right is this one: http://www.keyboard-and-mouse-sharing.com/maintenance.htm

Once deprecation enforcement starts becoming too much, those users are going to go away. A chunk of these customers don't want to do that although, because just paying the $24/year is cheaper than the time and hassle it would take to switch to something else. You could even combine it with the cloud version and just let people choose. But they are not going to chose that if they know on-prem is still deprecated.

You guys used to make features that would explicitly avoid server side decryption, like watchtower. We want that back.

Re: 1Password X: A look at the future of 1Password in the browser

#133

Earlier quoted context omitted.

It never has been supported on Linux. Why is that suddenly a surprise to you?

I built a Linux machine to perform my development work on and found it out. "It has never been supported on Linux", uh, okay? I'm saying it's totally shitty that a major platform is not supported.

Yeah... Linux is not a major platform for anything except web servers and I don't think web servers have a need for 1Password yet.

Re: 1Password X: A look at the future of 1Password in the browser

#134
post #118
post #106

Earlier quoted context omitted.

Disclosure: I work for AgileBits, makers of 1Password Hello fellow (or former) password manager person! Fancy seeing you here. The previous model wasn't killing us, in fact it isn't even "previous" because we still offer standalone licenses for those that want them and will continue to do so. For those who aren't aware of our upgrade cycle in the past: For Mac, we last charged for 1Password 4 back in 2013. Version 5…

I'm a bugcrowd customer too, but offering a prize to say you are secure is a fallacy. It's also not how bugbounties work... Example: - https://moxie.org/blog/telegram-crypto-challenge/ The fact remains the same that the things you championed against LastPass doing are now the features and products you are providing. You guys have already been caught erasing and hiding the previous versions on your site to convert peo…

> You guys have already been caught erasing and hiding the previous versions on your site to convert people to 1Password.com.

Wow, that is BS.

You can download any previous version of 1Password, starting with version 0.8.0 (May 2006):

https://app-updates.agilebits.com/

Re: 1Password X: A look at the future of 1Password in the browser

#135

Earlier quoted context omitted.

Supposedly, 1Password 7 for Windows will bring back standalone vaults to Windows. Since the hosted solution brings them the bulk of their revenue (I'm guessing), it made sense to me for them to focus on the Windows upgrade with hosted accounts and I forgave them for it as long as 1Password 4 continued to work. I really hope that same attitude continues on with later versions of 1Password X. Starting out with accounts…

> I'm a patient person and beggars can't be choosers. Is it begging when you pay $50 per license for the product?

Yes it is because you're asking to get the upgrade for free. The version you paid $50 for has standalone support and will continue to work exactly as it did when you bought it. Maybe that's a caveat of the SaaS/hosted model. I don't see why they should be obligated to give anyone the version with new features for free, though.

Re: 1Password X: A look at the future of 1Password in the browser

#136
post #33

Earlier quoted context omitted.

Supposedly, 1Password 7 for Windows will bring back standalone vaults to Windows. Since the hosted solution brings them the bulk of their revenue (I'm guessing), it made sense to me for them to focus on the Windows upgrade with hosted accounts and I forgave them for it as long as 1Password 4 continued to work. I really hope that same attitude continues on with later versions of 1Password X. Starting out with accounts…

You’re not a beggar, though. You paid for the product! Honestly as long as they don’t break the current version, I’m fine with what I bought. I have 1Password now on MacOS, iOS, Android, Windows — and I guess I can get it on my Linux box now if I want to pay a subscription.

Yes you are. You paid for a product that continues to work exactly the way it did when you paid for it. They're not obligated to give me new features to the product I paid for at no cost to me, especially when it's a from-scratch rewrite. That makes all of us beggars since what we paid for still exists and they're not taking it away.

Re: 1Password X: A look at the future of 1Password in the browser

#137
post #98

Earlier quoted context omitted.

Does this scare you? I'm asking honestly, I'm currently building a password manager in react native, and thus the core crypto is all js, relying on crypto-js. Would this be a deal-breaker for you?

I don't think I know enough to feel a particular way about it. All I know is that some people I respect seem to dislike it[0][1], so I've just defaulted to avoiding it where I can. [0] https://www.nccgroup.trust/us/about-us/newsroom-and-events/b... [1] https://tonyarcieri.com/whats-wrong-with-webcrypto

The biggest concern with WebCrypto (with the JavaScript code using WebCrypto) is the fact that you have to trust the delivery mechanism.

If there is a problem with TLS then there is a potential for a MITM attack that could modify the JavaScript code.

Another potential issue is phishing. It is easier to create a fake web app compared to a fake native app.

Re: 1Password X: A look at the future of 1Password in the browser

#138
post #118

Earlier quoted context omitted.

I'm a bugcrowd customer too, but offering a prize to say you are secure is a fallacy. It's also not how bugbounties work... Example: - https://moxie.org/blog/telegram-crypto-challenge/ The fact remains the same that the things you championed against LastPass doing are now the features and products you are providing. You guys have already been caught erasing and hiding the previous versions on your site to convert peo…

> You guys have already been caught erasing and hiding the previous versions on your site to convert people to 1Password.com. Wow, that is BS. You can download any previous version of 1Password, starting with version 0.8.0 (May 2006): https://app-updates.agilebits.com/

No it is not at all. This is what the whole debacle was a few months ago when you removed most of the download links from your website.

https://twitter.com/cryptovillage/status/884205077459738624

Re: 1Password X: A look at the future of 1Password in the browser

#139

In-browser password managers are completely insecure by design. Any site can write whatever they want within the page, so it's easy to fake the prompt and steal the password. The only way to prevent this is if the password manager runs as a standalone application, so that the password is entered outside the browser. 1password has this, and the workflow is fine --- switching to the insecure one makes no sense.

You are correct. This is the main reason 1Password X never uses a web page when it prompts for the master password -- the master password must be entered in the popup that is only accessible to the extension itself.

It is certainly tricky and there are many other concerns. We hope to have a white paper about the security decisions made in 1Password X design.

Re: 1Password X: A look at the future of 1Password in the browser

#140
post #115

Earlier quoted context omitted.

Disclosure: I work for AgileBits, makers of 1Password How are we neglecting our standalone users? I'm really curious here because we are still introducing features in our existing applications that work for our standalone users. Certain new applications like 1Password X and our CLI are only really easily possible because of 1Password.com, but just because these are being offered doesn't mean we're neglecting our stan…

You don't discard them completely, but new things that can be made by reading local files vs using a cloud API are just made using a cloud API. Updates to current apps I'm guessing will still support local file users if it's easy. Your website has no obvious way on how to buy the standalone version now. It's pretty obvious through behavior that it's a deprecated mode without stating it outright. Most people can deduc…

> Your website has no obvious way on how to buy the standalone version now.

It is not easy. In the beginning we had a website that offered both standalone version and a subscription on the same page. It is easy for HN people to make this decision but we had hundreds of customers purchasing both, most of them having no idea what is the different between license and subscription.

Since the purchase-separate-license-for-each-platform-and-host-data-yourself requires more expertise, it made sense to make it less visible and make the subscription option to be default.

> You guys used to make features that would explicitly avoid server side decryption.

All encryption is still performed on the client side. In fact, with 1Password service we went overboard and now encrypting much more data on the client side than we used to.

We also added a separate Secret Key that makes sure the encryption strength does not depend on the master password alone (many people still use pretty weak master passwords).

Post reply on HN