Live data from Hacker News

LogMeIn Acquired by Private Equity

techcrunch.com

111–120 of 319 posts

Re: LogMeIn Acquired by Private Equity

#112

Earlier quoted context omitted.

> but there are certainly pieces of software I am willing to pay a subscription for. There shouldn't be. > One that is actively improved, secured, and is used throughout my day is one of them. Not when those problems are completely self-inflicted by injecting Cloud Bullshit into stuff that doesn't need it.

If there weren't pieces of software that people were willing to pay a subscription for, then software quality would be horrible. The reason why 1Password is so good is that the developers are paid to work on it, and some business needs (such as having really good quality stuff so you can get recommended to more potential customers, and so that your existing customers don't leave) push you towards higher quality softw…

I don't remember software quality being a ton worse before software subscriptions became common. Operating systems and certain development practices (maybe, less certain about that one) have led to some noticeable improvements, but that mostly happened before the shift.

Re: LogMeIn Acquired by Private Equity

#113
post #93
post #82

Earlier quoted context omitted.

Safe to say it's: 1) It's generally preferable that open-source solutions be as capable & usable as closed-source ones, and 2) having the best option be a subscription service is very, very "ugh", as has been constantly complained about here and elsewhere.

Re: 1. Got it. Re: 2. It's not just subscription. Download the app (Mac or Windows) and in the options choose to create a new local vault. You'll be presented with a dialog to buy a license if you don't already have one. I get the complaints about subscriptions, but there are certainly pieces of software I am willing to pay a subscription for. One that is actively improved, secured, and is used throughout my day is o…

Hey Kyle! Been a long time paying user. 1Password has helped me help my family use better passwords. We all have local vaults, but I often recommend and help onboard companies I consult with to the hosted service. Thanks for building an awesome app!

Re: LogMeIn Acquired by Private Equity

#114
post #94

Earlier quoted context omitted.

Not the OP, but I dropped 1Password when it became clear you're forcing folks to cloud storage. I was sort of hoping the carefully chosen weasel-words about that used at the time meant you'd reconsider if enough of us made noise, but later releases made it clear where you're headed. It bummed me out - I really like 1pw. And I still don't have my password situation back to the same level of ease-of-use yet, but I swit…

>> Storing my password DB on other people's computers is simply not going to happen. What is the risk scenario you're worried about?

A situation where the remote datastore is compromised and now with it, all of my passwords.

Or if I was to buy into 1Password's worldview, all of my credit cards, bank accounts, ID cards, everything I want to keep a secure digital copy of, is at risk.

Having a sense of control is a huge part of the way we think. Despite the greater risk of death in a car compared to an aeroplane, there's less concerns about car travel because there's a sense of control. Similarly, having the data under my control may be less secure, but that's still within my control rather than dependent on someone else doing the right thing.

Re: LogMeIn Acquired by Private Equity

#115
post #54

My old company used Logmein professionally to remotely manage 100s of computers for many years before switching to ConnectWise. They had a great product for a long time but some of the worse licensing decisions I've ever seen. It went from being completely free to several thousand dollars overnight without any additional features, support, etc being offered. And meanwhile development was stagnant with only weird chan…

I agree. I have around 500 computers under management, finally left them for Teamviewer after LMI's price tripled and their features halved (or worse). I ran it mostly from Linux, which they seemed to be withdrawing support for.

Re: LogMeIn Acquired by Private Equity

#117
post #54

My old company used Logmein professionally to remotely manage 100s of computers for many years before switching to ConnectWise. They had a great product for a long time but some of the worse licensing decisions I've ever seen. It went from being completely free to several thousand dollars overnight without any additional features, support, etc being offered. And meanwhile development was stagnant with only weird chan…

At the time I loved their product and installed it on parents machines. It was great. I was happy to pay 100 or 200 a year but they wanted way more. Stopped using it and never found an equivalent.

I use copilot when I need to remotely help my parents.

https://www.copilot.com/Pricing

Re: LogMeIn Acquired by Private Equity

#118
post #94
post #78

Earlier quoted context omitted.

Heads up: I work for 1Password Any reason why you'd say unfortunately there? I see it as a pretty big perk rather than an unfortunately. But I would also like to understand a bit more so I can pass along any necessary feedback to our team. Thanks! Kyle 1Password Security Team

Not the OP, but I dropped 1Password when it became clear you're forcing folks to cloud storage. I was sort of hoping the carefully chosen weasel-words about that used at the time meant you'd reconsider if enough of us made noise, but later releases made it clear where you're headed. It bummed me out - I really like 1pw. And I still don't have my password situation back to the same level of ease-of-use yet, but I swit…

+1 for this.

The only reason I ever got onto 1Password in the first place was because I didn't have to use any cloud storage, and could use wifi sync between my devices.

I was extremely disappointed as that started to change. It was an absolute nightmare having to retrain all family members in the nuanced differences in how Bitwarden works compared to 1Password. I hope I don't end up having to eat that cost a second time.

Re: LogMeIn Acquired by Private Equity

#119

Earlier quoted context omitted.

> but there are certainly pieces of software I am willing to pay a subscription for. There shouldn't be. > One that is actively improved, secured, and is used throughout my day is one of them. Not when those problems are completely self-inflicted by injecting Cloud Bullshit into stuff that doesn't need it.

If there weren't pieces of software that people were willing to pay a subscription for, then software quality would be horrible. The reason why 1Password is so good is that the developers are paid to work on it, and some business needs (such as having really good quality stuff so you can get recommended to more potential customers, and so that your existing customers don't leave) push you towards higher quality softw…

Software quality was a lot higher before the Internet was a thing. What you shipped had to work, as shipping patches was non-trivial and expensive.

Most such software wasn't subscription based either.

Re: LogMeIn Acquired by Private Equity

#120

Earlier quoted context omitted.

>> Storing my password DB on other people's computers is simply not going to happen. What is the risk scenario you're worried about?

A situation where the remote datastore is compromised and now with it, all of my passwords. Or if I was to buy into 1Password's worldview, all of my credit cards, bank accounts, ID cards, everything I want to keep a secure digital copy of, is at risk. Having a sense of control is a huge part of the way we think. Despite the greater risk of death in a car compared to an aeroplane, there's less concerns about car trave…

I think you may want to take a closer look at how 1Password works. I'll give a quick rundown here, but our security white paper goes into much greater detail: https://1pw.ca/whitepaper

Your data is encrypted locally on your devices, it is never available in a decrypted form on any of our servers. A compromise of our servers would result in the attacker getting gibberish (encrypted data).

To decrypt that data the attacker will need both your Master Password and your Secret Key. A Secret Key is a 128-bit key generated locally on your device, your Master Password is a passphrase set by you. These two keys are combined and, to simplify greatly, used to decrypt your data.

The only way an attacker is going to acquire your Master Password and Secret Key are from your devices. Those are the only places those keys really exist.

Guessing both the Secret Key and a strong Master Password are effectively going to cost such a significant amount of money, or due to time and processing constraints, be infeasible.

An attack would have to be highly targeted. In other words, you would have to be a specific target to make any attack be worthwhile. If you believe you are likely to be the target of such a very specific attack you probably have a team of security personnel working for you who could better advise you than I could.

I'd really suggest looking into how we do things. The only feasible attack on your data would be through your devices, and any other password manager that stores data locally on your devices will be impacted the same exact way in this case.

Hope that helps but if you have questions please let me know and I'll do my best to help get you answers.

Kyle

1Password Security Team

Edit: apparently markdown isn't a thing here.

Post reply on HN