Live data from Hacker News

1Password for Linux development preview

discussions.agilebits.com

91–100 of 352 posts

Re: 1Password for Linux development preview

#92
post #87
post #76

Earlier quoted context omitted.

Hosting my encrypted data means anyone with sufficient access at any single time can copy the encrypted data and attack it or me, then or later when eventually feasible. Hosting only an executable I download and execute means the adversarial extraction of data must be contained within the executable and bypass all security from within my system. There is a window of opportunity for sending out a signal indicating the…

> I do trust the team of 1Password to be competent and not evil, but there are many things that can go wrong anyway. Very much this. I don't benefit in any way from having a copy of my sensitive data in their cloud, so as a very basic security principle, I don't want them to have it . And that's just for my personal use. If they drop support for local vaults, I have to stop using it for work, too, because my employer…

I agree; and unfortunately I found self-hosted vaults to always be a bit challenging to get right, if I wanted to use my vault on multiple devices. The local-network only sync engine never worked for me, so I ended up using another third-party's servers to sync anyway. I signed up for 1password.com a couple months ago and it's been painless. To each their own!

Re: 1Password for Linux development preview

#93

KeepassXC is the perfect solution in my opinion. It is open source, has a huge number of features (that don't get in the way of basic usage), and has mobile apps and desktop apps that work well on all platforms. Right now I am using it on Windows, Mac, AND Linux, as well as my Android phone. I have it syncing over Dropbox, but you can sync it however you like. The Android app automatically fetches the latest version,…

I second this. KeePass is awesome (across all platforms)

Re: 1Password for Linux development preview

#94

KeepassXC is the perfect solution in my opinion. It is open source, has a huge number of features (that don't get in the way of basic usage), and has mobile apps and desktop apps that work well on all platforms. Right now I am using it on Windows, Mac, AND Linux, as well as my Android phone. I have it syncing over Dropbox, but you can sync it however you like. The Android app automatically fetches the latest version,…

I'm the same way. The most important parts of the KeePass ecosystem to me are:

1. It runs on every platform I currently use, as well as any platform I might care to use, whether or not that platform is sufficiently "popular" for a company to justify caring about it.

2. It isn't dependent on the continued healthy existence of a company to remain usable, as I could simply self-maintain in a worst case scenario.

These are very important things about a password manager to me, personally, which is why any of these more polished/popular options would be an extremely tough sell.

Re: 1Password for Linux development preview

#95

What are peoples thoughts about firefox lockwise? I have been using keepass for forever but I want something that easily syncs between devices and doesn't require copy/paste in to the browser. Lockwise seems perfect but I haven't used it much yet.

Well one difference is you just login with a password and you have access to all your passwords. Whereas with 1Password you use the long key to set up a new device, so it requires either memorizing that key, writing it down, or having a different device with that key on it.

Re: 1Password for Linux development preview

#96
post #76
post #55

Earlier quoted context omitted.

If you can't trust them to host an encrypted blob, you can't trust them to run code on your local machine. I agree with you that the resistance isn't rational.

Hosting my encrypted data means anyone with sufficient access at any single time can copy the encrypted data and attack it or me, then or later when eventually feasible. Hosting only an executable I download and execute means the adversarial extraction of data must be contained within the executable and bypass all security from within my system. There is a window of opportunity for sending out a signal indicating the…

> an executable I download and execute means the adversarial extraction of data must be contained within the executable and bypass all security from within my system

(emphasis mine)

Security is about having layers. I can't begrudge someone wanting to add layers to their security.

Re: 1Password for Linux development preview

#98

I switched to "pass" from 1p and it is a breeze because it just works without all the bullshit and I don't have to place any trust on a company saying they do things right (they will never tell otherwise). And 1password never cared about Linux. I had to custom-script data export, they pretty much held data hostage by making it difficult to migrate from the platform, not to speak of the undocumented data formats. But…

I have to call this out as a bit of a hyperbole. They already participate, quite openly, in security audits[0], and while yes, I'd love it if it was OSS too, but the reality of making money on these services is that (especially I believe at the time 1Password was founded), is it wouldn't have likely done them any good, really. In fact it could hurt their business. I believe 1Password was one of (but not the only!) pi…

How can one be sure that the passwords are even encrypted, without having seen the program?

Audits don’t mean much for various reasons, including the conflict of interest.

Agencies such as NSA don’t have to say loudly that they have agreements with such and such companies through PRISM-like programs.

Re: 1Password for Linux development preview

#99
post #83

Earlier quoted context omitted.

Generally because the chance they serve a compromised client is lower than that your homegrown storage will be compromised, and because the UI affordances make it easier to use more unique passwords and multi-step authentication.

But if my machine were compromised, my 1password password would be compromised too, wouldn't it?

Maybe. It has some defenses against keyloggers. The local data is encrypted so the attacker would need your master password, which hopefully you wouldn’t have stored in plaintext on the same machine.

Regardless, the idea is still that a secure password manager would put you in a better situation more often than would a plain text file, cloud notes, physical notebook/sticky, etc.

Re: 1Password for Linux development preview

#100

I’ve been using 1Password every day for over 11 years now. The oldest passwords I’ve got stored are for Twitter and Dropbox (yes, the passwords have been changed but the records were first created in 2009). It’s one of those apps which has been made with proper craftsmanship and care, so while I’m not a Linux user, I’d have no problem recommending based solely on Agilebit’s reputation.

Also a longtime user. Did you kick over to their subscription model or have you stuck with the old installs attached to the grandfathered permanent license?
Post reply on HN