Live data from Hacker News

LogMeIn Acquired by Private Equity

techcrunch.com

171–180 of 319 posts

Re: LogMeIn Acquired by Private Equity

#171

Earlier quoted context omitted.

Replying to this as I can't reply to the other child comment: The secret key is emailed given to you when you enroll and is used, frequently, every time you enroll a new device. 1Password would have to screw up catastrophically to just not use it. Obviously they _could_ screw up catastrophically, but if you don't trust them to operate their service with a basic level of competence you probably shouldn't be using them…

The comment above says Secret Key is generated on my device, how can it be emailed anywhere? I don't quite understand how one can enroll other devices with local Secret Key, so I assume Secret Key has to leave my device and travel over the wire. Which raises even more questions, but even if it's not the way it's generated makes a big difference.

It is NOT emailed to you.

It is generated locally as I indicated, and as outlined in our white paper.

Where some users get confused, and perhaps rightfully, is that when you sign in you can generate a PDF called an Emergency Kit, that contains the Secret Key. This PDF is generated entirely in JS within the browser. It is not generated on our servers and then downloaded. Some users do get confused about that.

Our web client is effectively a client running in the browser, it's all local and communicates with our servers the same way that a native app would.

Kyle

1Password Security Team

Re: LogMeIn Acquired by Private Equity

#172

Earlier quoted context omitted.

An interesting approach. When I worked at a university and had 100+ machines to handle (back in the WinXP days), we just used udpcast + sysprep to do full disk cloning. We never bothered with individual machines, if anything ever went wrong we just wiped the whole thing and re-cloned it. Keeping 100+ machines up and running, and caring for individual ones sounds like a whole lot of work. Admittedly we got away with i…

My second job out of high school was at my school district as a PC Tech. I had the highest successful case closures of any technician because they all tried to fix the problem. I just moved the user's local docs to their network share, re-imaged the PC in 5-10 minutes, and copied their local docs back to their local folder. I had ~1000 desktops under my management between my 3 K-9 schools. Worst job I have ever had t…

I thought most k12 were running stuff like Deep Freeze.

https://en.m.wikipedia.org/wiki/Deep_Freeze_%28software%29

Re: LogMeIn Acquired by Private Equity

#173
post #120

Earlier quoted context omitted.

I think you may want to take a closer look at how 1Password works. I'll give a quick rundown here, but our security white paper goes into much greater detail: https://1pw.ca/whitepaper Your data is encrypted locally on your devices, it is never available in a decrypted form on any of our servers. A compromise of our servers would result in the attacker getting gibberish (encrypted data). To decrypt that data the atta…

> Edit: apparently markdown isn't a thing here. Extremely satisfied 1Password customer here. You're correct about lack of Markdown, and for the details: https://news.ycombinator.com/formatdoc

Hey thanks! I guess I've never had reason to use Markdown here until now and just discovered that after years of posting here.

Kyle

Re: LogMeIn Acquired by Private Equity

#174
post #161

Earlier quoted context omitted.

Does BitWarden do auto-fill on iOS?

No, but with some settings adjustments you can use it as your password manager and it becomes accessible from the keyboard.

Correct me if I’m wrong but this is the same for Lastpass on IOS. At least if LP does auto fill it’s never worked for me.

The keyboard shortcut to paste a password is better than autofill imo.

Re: LogMeIn Acquired by Private Equity

#175
post #111

Earlier quoted context omitted.

https://www.cloudberrylab.com/remote-assistant.aspx Not only free, they don't even have a paid version.

If I can't understand the business model, I'm probably not going to use the software.

They primarily sell backup software, and they show the occasional ad to you in the app.

Re: LogMeIn Acquired by Private Equity

#176
post #120

Earlier quoted context omitted.

I think you may want to take a closer look at how 1Password works. I'll give a quick rundown here, but our security white paper goes into much greater detail: https://1pw.ca/whitepaper Your data is encrypted locally on your devices, it is never available in a decrypted form on any of our servers. A compromise of our servers would result in the attacker getting gibberish (encrypted data). To decrypt that data the atta…

While what you are saying seems technically sound it implies that you do everything right when generating Secret Key. Let's imagine you have a bug and it fills Secret Key with zeros (or some fixed sequence) and it becomes known after quite some time, and in between your server is compromised. How much easier it makes for an attacker to decrypt data en masse? I would assume some people may not like that such attack ve…

We can talk all day about bugs and mistakes. They're a fact of life and we are human.

It's also important to remember that your Master Password still plays a role and YOU provide that. If you use a weak Master Password, and we somehow introduced a bug that set the Secret Key to 0's, then your Master Password would be the only thing protecting you. In an ideal world you'd continue to use a strong Master Password.

Kyle

1Password Security Team

Re: LogMeIn Acquired by Private Equity

#177

Off-topic, but can anyone tell me of an instance whereby a software entity was acquired by a VC firm and things turned out great?

Others have pointed out the difference between VC and PE, but I think there's a crucial thing missing from your question: turned out great for whom ?

I'm assuming they mean users/customers of the firm being aquired.

Re: LogMeIn Acquired by Private Equity

#178

A lot of discussion surrounding LastPass and alternatives, but what are some actual LogMeIn alternatives that people like?

ssh, RDP

What? How is a user supposed to show you and reproduce their problem when you're connected over SSH or RDP? Both run in a different session than the user's

Re: LogMeIn Acquired by Private Equity

#179
post #54

My old company used Logmein professionally to remotely manage 100s of computers for many years before switching to ConnectWise. They had a great product for a long time but some of the worse licensing decisions I've ever seen. It went from being completely free to several thousand dollars overnight without any additional features, support, etc being offered. And meanwhile development was stagnant with only weird chan…

For what it's worth, ConnectWise is also owned by private equity (Thoma Bravo). TB seems to be supporting the growth of the company.

Re: LogMeIn Acquired by Private Equity

#180
post #133
post #93

Earlier quoted context omitted.

Re: 1. Got it. Re: 2. It's not just subscription. Download the app (Mac or Windows) and in the options choose to create a new local vault. You'll be presented with a dialog to buy a license if you don't already have one. I get the complaints about subscriptions, but there are certainly pieces of software I am willing to pay a subscription for. One that is actively improved, secured, and is used throughout my day is o…

As an ex-1Password user, y'all lost me when you released a new Windows client that didn't support local vaults and let the old client stagnate while pushing everyone to switch to a cloud subscription. I waited and waited for local vault support to come back and finally migrated to something else. No other password manager is as good as 1Password but stringing that out for so long cost AgileBits my business, forever.

Sorry for the trouble.

We had a greater need for the 1Password.com support in the Windows client. So when we started our rewrite efforts it focused on that.

In general, we'd agree that it took longer than we wanted, and I'm sorry if that caused you to leave. In the end we were really doing the best we could given the demands we had and the time/resources available to do it. It sounds like in this case it wasn't enough.

Kyle

1Password Security Team

Post reply on HN