Live data from Hacker News

1Password for Linux development preview

discussions.agilebits.com

111–120 of 352 posts

Re: 1Password for Linux development preview

#111
post #98

Earlier quoted context omitted.

I have to call this out as a bit of a hyperbole. They already participate, quite openly, in security audits[0], and while yes, I'd love it if it was OSS too, but the reality of making money on these services is that (especially I believe at the time 1Password was founded), is it wouldn't have likely done them any good, really. In fact it could hurt their business. I believe 1Password was one of (but not the only!) pi…

How can one be sure that the passwords are even encrypted, without having seen the program? Audits don’t mean much for various reasons, including the conflict of interest. Agencies such as NSA don’t have to say loudly that they have agreements with such and such companies through PRISM-like programs.

>How can one be sure that the passwords are even encrypted, without having seen the program?

We have seen the program. We can have as many binary copies of it as we’d like.

> Audits don’t mean much for various reasons, including the conflict of interest.

[citation needed]

> Agencies such as NSA don’t have to say loudly that they have agreements with such and such companies through PRISM-like programs.

The product uses end to end encryption. The database is encrypted locally before being uploaded. They would have to be using bad encryption or stealing your password to get at it. It is understood how 1P works, they have written about it extensively.

Re: 1Password for Linux development preview

#112

I’ve been using 1Password every day for over 11 years now. The oldest passwords I’ve got stored are for Twitter and Dropbox (yes, the passwords have been changed but the records were first created in 2009). It’s one of those apps which has been made with proper craftsmanship and care, so while I’m not a Linux user, I’d have no problem recommending based solely on Agilebit’s reputation.

But why a whole electron app just to store passwords?

Why a whole GTK or Mono app just to store passwords?

Once you’ve decided that you want to make a GUI for something you’ve already made the choice to increase the weight considerably. Electron is still the best cross platform toolkit when you need browser support too.

Re: 1Password for Linux development preview

#113

I’ve been using 1Password every day for over 11 years now. The oldest passwords I’ve got stored are for Twitter and Dropbox (yes, the passwords have been changed but the records were first created in 2009). It’s one of those apps which has been made with proper craftsmanship and care, so while I’m not a Linux user, I’d have no problem recommending based solely on Agilebit’s reputation.

But why a whole electron app just to store passwords?

The other versions are native. It's one of the things that sets 1Password apart. Is the Linux version Electron?

Re: 1Password for Linux development preview

#114

Earlier quoted context omitted.

1Password is pretty stable, I have not had any problems with applications freezing. I was going to switch to LastPass since I have two younger children that I'd like to use a password manager, but LastPass has the same 17+ restriction so I'm looking for other options. But if you don't have the same issue, 1Password is a solid choice.

I think you can just use 1Password for Families in this case https://1password.com/families/

That's what I use. The iOS app has a 17+ rating.

Re: 1Password for Linux development preview

#116
post #104
post #61

Earlier quoted context omitted.

As somebody who uses exclusively local vaults and pays via subscription, that is totally possible. It’s not possible on Linux, as noted above, but the Mac/iOS apps have supported that for the full lifespan of the subscription model.

How do you sync your local vaults across different machines?

[deleted]

Re: 1Password for Linux development preview

#117
post #83

Earlier quoted context omitted.

But if my machine were compromised, my 1password password would be compromised too, wouldn't it?

Maybe. It has some defenses against keyloggers. The local data is encrypted so the attacker would need your master password, which hopefully you wouldn’t have stored in plaintext on the same machine. Regardless, the idea is still that a secure password manager would put you in a better situation more often than would a plain text file, cloud notes, physical notebook/sticky, etc.

But the reasonable comparison wouldn't be "a plain text file" it would something like Jason Donenfield's pass (https://www.passwordstore.org/)

Now, there are some potential usability improvements they can offer by giving the passwords to "some company" but there's a serious price (not only financial) to pay for that.

Also, because it's designed as a standard Unix tool if you're comfortable in Unix (as we may suppose more Linux users are) you'll find pass fits better than 1password or similar programs. When did you change the password for your Hacker News account? You can use 'git' to ask like you would anything else. How will you ensure the passwords survive a house fire? They're on your filesystem and will be preserved with everything else in your backups (you do have backups and use encrypted storage for them right?).

And so on.

Re: 1Password for Linux development preview

#118

I’ve been using 1Password every day for over 11 years now. The oldest passwords I’ve got stored are for Twitter and Dropbox (yes, the passwords have been changed but the records were first created in 2009). It’s one of those apps which has been made with proper craftsmanship and care, so while I’m not a Linux user, I’d have no problem recommending based solely on Agilebit’s reputation.

> It’s one of those apps which has been made with proper craftsmanship and care

Is it? I've been using it for sometime as well but it seems like there is a lot of room for improvement. E.g:

- Support for unlocking via Watch ID on the Mac.

- Currently on iOS when searching for a password within an app, if a site prefix is included that doesn't match what's in 1Password the list will just show no results, with no way to navigate manually to the login. Instead, you have to close the app, open 1Password, and copy/paste the credentials back in. Typically the master password will have to be re-entered as well, despite touch ID being adequate a moment prior. Since it's rare to sign up via the web now for mobile apps, this is the most common scenario for me when using 1Password for apps on my phone (and occasionally websites as well).

- Improved UI/UX on mobile. Dashlane is way better in this regard. 1Password overemphasizes features I don't need like tags and favorites and has a pretty cluttered look in general.

I like the native Mac app and open/local vault format. (Dashlane by contrast has a very buggy desktop app and requires storing everything on their servers.) But I would jump at the chance to use an alternative with a simpler UI and better experience on mobile.

Re: 1Password for Linux development preview

#119

Earlier quoted context omitted.

But why a whole electron app just to store passwords?

The other versions are native. It's one of the things that sets 1Password apart. Is the Linux version Electron?

Yes. Not against Electron but maybe I'm underestimating the ui/ux complexity of a password manager since I have never use one.

Re: 1Password for Linux development preview

#120
post #27

Nice to see progress here, though 1P continuing to move away from local control to force subscriptions is regrettable. Even so, the UI hasn't been matched yet IMO, which is important for getting the less technical to use it. We're sadly also still a ways away from passwords being eliminated entirely, so it's still very important to get everyone using one. One thing still missing I really hope to see though is the loc…

For many/most types of software I am in the same camp of people who would prefer to pay more upfront for a license as long as the software continues working as is - I bought it because it worked and if I chose to pay more in the future for a better version, I will make that decision based on the new features added and not the old features being held hostage. However, for something as high-value as a password manager,…

So to preface: I don't use any web functionality in password managers at all, only the client applications. But that's the context for my regret over the forced subs too.

>I can't think of any other class of product where timely updates from the developers are so critical to the utility of the product.

I can think of a ton actually, although I guess it depends on what you consider important functionality there. Now, there is ongoing maintenance needed for things like keeping up with browser integration, but I'm not sure exactly what security updates should ever be needed unless they really fucked something basic up. The only things that need constant attention are their own cloud service, but that's a function of it being their own cloud service vs someone running their own server or syncing via Dropbox.

>You could even argue that an unpatched, out of date password manager is worse than no password manager.

I don't think you could frankly. Like, what's the threat model here when we're talking data that lives on our own systems and is E2EE? Fundamentally, password managers do not defend against the trusted end point being pwned, for that you need an HSM of some sort (or at least some weaker but still somewhat functional kinda of 2FA). All data from the end system should be fully encrypted before leaving, and since the system is trusted by definition timing attacks shouldn't be a concern (or at least are trivial here to negate entirely), so the security should depend purely upon the PM's ability to perform basic at rest crypto, use a decent key stretching as needed, etc. Which is frankly a solved problem with well vetted free libraries, that's not the hard part of security.

Honestly, 1Password and the like aren't that different from the macOS Keychain Access I'd been using for many many years before hand. They've got better organization and UX flow these days, and browser integration is a genuinely big deal. But I never had any problems with Dropbox sync with pre-1P.com nor do I still have any problems with sync there. In principle, the 1P team could have made all the admittedly alright group stuff and so on available as a standalone server thing people could run along with their own cloud offering of the same, similar to the way Gitlab and many others do. Buy the server/client licenses standalone and run infra yourself, or not, your call. WiFi sync didn't have to be left as primitive as it has been either. Etc. It's a business decision for them to push subs because subs are very profitable. And I recognize yeah, it's a way to make lots more money in a reliable fashion which people like. But I still regret the sub trend and think it's usually a negative overall particularly for people trying to fill situations outside the norm. 1Password's sub thing for example doesn't scale with large families, there is a huge disconnect between a small family and an "organization" in their pricing and general structure which isn't due to cost basis, it's due to their perceived ability to pay.

I'm genuinely optimistic though that things like Webauthn represent real turning points, and we're finally (10-15 years late but better late then never) moving away from the madness of service passwords and managers "have i been pwned" and all the layers that essentially recreate PKI, very badly. As far as security goes, neither I nor anyone else should need to give a single shit or change anything at all if a website is completely utterly hacked, because the only authentication that should be there should be a public cert for me. Damn it, asymmetric credentials was solved forever ago!

Post reply on HN