Live data from Hacker News

1Password X: A look at the future of 1Password in the browser

blog.agilebits.com

141–150 of 181 posts

Re: 1Password X: A look at the future of 1Password in the browser

#142

I find myself wondering if keepass is going to introduce a new vault type of small individual files in a directory and move into where 1Password used to be (including "cloud" using any of many cloud storage options). edit: Seems to me that even if you set a fixed file size of 1-2k for each entry it wouldn't be too huge, or perhaps a dual-file per entry system with one small fixed-size file (128-256 bytes?) for indexe…

That's how we designed the original 1Password data format (.agilekeychain). It certainly made syncing with Dropbox much simpler.

It does have its drawbacks though. Once you have too many files (and make too many requests), both Dropbox and iCloud will start throttling you.

It also might take a while to reload the data, even from the local disk. We had to add a cache file at some point.

Re: 1Password X: A look at the future of 1Password in the browser

#143

Earlier quoted context omitted.

> I'm a patient person and beggars can't be choosers. Is it begging when you pay $50 per license for the product?

Yes it is because you're asking to get the upgrade for free. The version you paid $50 for has standalone support and will continue to work exactly as it did when you bought it. Maybe that's a caveat of the SaaS/hosted model. I don't see why they should be obligated to give anyone the version with new features for free, though.

Likely because they’re giving other users who happened to start using 1Password later, new features for free.

Re: 1Password X: A look at the future of 1Password in the browser

#144
post #126

Earlier quoted context omitted.

All it would take for 1Password to decrypt our entire vault is for 1Password to push out a software update that simply made it so that the client app uploaded the keys to 1Password's servers after the user typed it in. Without 1Password releasing their source code, end users would have no idea if such an update ever took place. We just have to trust 1Password as a company. Well, if we already trust 1Password as a com…

If that's your concern then I'm afraid there's little we can do to change your opinion and perhaps 1Password isn't the solution for you. I don't mean to sound rude or anything like that. Just being honest. We have had grand visions of offering portions of our source (notably the cryptographic portions) available for review, note, not open source in the sense you can use it but in a license that makes it available for…

I'm simply pointing out the elephant in the room. If there is no ability to audit the source code of the password manager, and the source code is managed by a third party company, then for all intents and purposes, the third party company has theoretical access to everything (regardless of what encryption is used). It boils down to trust, and that trust can be violated by a single rogue employee at AgileBits. It could also be potentially violated by a government agency gaining control of AgileBits.

Re: 1Password X: A look at the future of 1Password in the browser

#145
post #111

Earlier quoted context omitted.

Disclosure: I work for AgileBits, makers of 1Password We outline the entirety of how this works in our white paper: https://1pw.ca/whitepaper We cannot tell what your data is. It's encrypted on your device using keys that only you know. Then we store it on our side on the server. The unique solution of using your Master Password and your Secret Key, makes brute forcing the data on our server an incredibly expensive j…

All it would take for 1Password to decrypt our entire vault is for 1Password to push out a software update that simply made it so that the client app uploaded the keys to 1Password's servers after the user typed it in. Without 1Password releasing their source code, end users would have no idea if such an update ever took place. We just have to trust 1Password as a company. Well, if we already trust 1Password as a com…

[deleted]

Re: 1Password X: A look at the future of 1Password in the browser

#146
post #138

Earlier quoted context omitted.

> You guys have already been caught erasing and hiding the previous versions on your site to convert people to 1Password.com. Wow, that is BS. You can download any previous version of 1Password, starting with version 0.8.0 (May 2006): https://app-updates.agilebits.com/

No it is not at all. This is what the whole debacle was a few months ago when you removed most of the download links from your website. https://twitter.com/cryptovillage/status/884205077459738624

Every version of 1Password available on https://1password.com/downloads/ works with standalone vaults. The only exception is 1Password 6 for Windows, but there is a link to download 1Password 4 for Windows. The link for that even says "Get 1Password 4 (standalone version)".

Re: 1Password X: A look at the future of 1Password in the browser

#147
post #126

Earlier quoted context omitted.

If that's your concern then I'm afraid there's little we can do to change your opinion and perhaps 1Password isn't the solution for you. I don't mean to sound rude or anything like that. Just being honest. We have had grand visions of offering portions of our source (notably the cryptographic portions) available for review, note, not open source in the sense you can use it but in a license that makes it available for…

I'm simply pointing out the elephant in the room. If there is no ability to audit the source code of the password manager, and the source code is managed by a third party company, then for all intents and purposes, the third party company has theoretical access to everything (regardless of what encryption is used). It boils down to trust, and that trust can be violated by a single rogue employee at AgileBits. It coul…

First, I'd like to point out that this concern is completely orthogonal to a hosted service, and has no connection to it.

Second, with the inability to check that a given binary came from a given source tree, open source does not help us audit what gets executed. If we're supposing that Agilebits' build process has been compromised, then we're in the same realm as considering a compromised build process for .deb or .rpm.

Re: 1Password X: A look at the future of 1Password in the browser

#148
Hi, big fan of hosted 1Password here!

I'm just curious, in the blog post you guys mentioned it autofills two-factor codes. I just tried using the extension on Postmark, and it didn't recognise the input field for my code. What heuristics are you using to determine the code input? As a front end developer myself, is there an autocomplete attribute for instance I could add that would help?

Re: 1Password X: A look at the future of 1Password in the browser

#149

Earlier quoted context omitted.

Yes it is because you're asking to get the upgrade for free. The version you paid $50 for has standalone support and will continue to work exactly as it did when you bought it. Maybe that's a caveat of the SaaS/hosted model. I don't see why they should be obligated to give anyone the version with new features for free, though.

Likely because they’re giving other users who happened to start using 1Password later, new features for free.

But those people will have to pay for the new version. They're not getting the upgrade for free either. They're either paying monthly for those features or they paid for the latest version that includes those features. You paid for the software you've been using the whole time that they haven't been using. I don't understand this attitude where users of old versions are entitled to full version upgrades for free.

Re: 1Password X: A look at the future of 1Password in the browser

#150
post #95

Earlier quoted context omitted.

In the context of iOS at least, it has the potential to stop working or lose functionality as time goes on. Compatibility for apps that are not continuously updated is not high on Apple's priority list.

Disclosure: I work for AgileBits, makers of 1Password. We recently updated 1Password 6 for iOS to work with the new Dropbox version 2 API. Going forward it should be fine until the next Dropbox API changes and presumably that will be a lot smoother than the change from version 1 to 2 that we just did... at least, I hope. We had several people put a lot of time into that transition. I'm not sure if your comment applie…

No, sorry, I probably wasn't clear. I didn't mean to say that 1Password does not provide updates.

I was just talking about the hypothetical situation for iOS apps (and thus their users) _if_ the apps don't get updates.

Post reply on HN