Live data from Hacker News

1Password for Linux development preview

discussions.agilebits.com

341–350 of 352 posts

Re: 1Password for Linux development preview

#341

Earlier quoted context omitted.

There are also advantages for the user. For example, new features arrive for all platforms at the same time; there is no prioritization of platforms or such. Same for bugs - apart from issues stemming from Electron itself, they're likely to appear on all platforms and therefore likelier to get fixed. In essence, the old "only X% of our users use platform Y, it's not worth it to make this feature/fix this bug for them…

None of these are advantages over other, better cross-platform toolkits.

The important bit for us w/r/t making 1Password a better cross-platform citizen is the Rust core. - Ben, 1Password

Re: 1Password for Linux development preview

#342
post #203

Earlier quoted context omitted.

I am a 1password user, and have bene for about the same amount of time, but I've been slowly looking for an alternative. Unless I'm mistaken, 1Password no longer ephemerally decrypts passwords as needed and only while used and then scrubs the memory. [1, old but still] The excuse, if I remember it, was that garbage collected languages made this challenging. Even so, there is some irony in them moving away from the te…

> The excuse, if I remember it, was that garbage collected languages made this challenging This is one of the main reasons why the core of 1password was rewritten in Rust: https://support.1password.com/kb/201902a/

Interesting. But this doesn't seem to cover the Mac version.

Re: 1Password for Linux development preview

#343

Earlier quoted context omitted.

The Linux priorities I outlined are fundamentally different. It’s a demand that the maker of the software alter the core of their business model. This is very different from asking for a native UI or to use a core OS API, etc. Again, it’s fine to ask for a radical business change or require it but the frequency of this as a demand does help explain why few companies go down this path. (As for 1Password abandoning one…

Thanks for the comments. The crypto is open source. We use the ring library: https://github.com/briansmith/ring - Ben, 1Password

How can I verify this claim? De-compiling?

Also it's very easy to use proper crypto in the wrong way. How can I know this is not the case here?

Re: 1Password for Linux development preview

#344

Earlier quoted context omitted.

Thanks for the comments. The crypto is open source. We use the ring library: https://github.com/briansmith/ring - Ben, 1Password

How can I verify this claim? De-compiling? Also it's very easy to use proper crypto in the wrong way. How can I know this is not the case here?

You make a very fair point and raise a reasonable concern. We do participate in external security audits, and will be having Cure53 do an in-depth one of 1Password for Linux. https://support.1password.com/security-assessments/

Re: 1Password for Linux development preview

#345

Earlier quoted context omitted.

Would you mind sharing it, so that other people don't have to go through the same pain you did? Maybe even creating an issue and dropping the code there could be helpful. Then somebody could pick it up and reuse the algorithms you wrote. That'd be pretty great.

https://gist.github.com/ben0x539/9cf66dd8347c264179a89944278... Caveat that it doesn't emit a csv you can import elsewhere, it's not extremely polished, hasn't ever been run outside of my laptop, just does a bunch of unnecessarily clever things. Needs the 1password commandline utility `op` set up (ie you have to have told it your secret key already). It'll create `items/` and `documents/` dirs with one file per, well…

What people have to do to avoid KDBX4 db store :) Those are easy to backup, sync etc.

Re: 1Password for Linux development preview

#346

Earlier quoted context omitted.

Enpass isn't open source and the only security audit skipped Linux.[1] [1] https://dl.enpass.io/docs/EnpassSecurityAssessmentReport.pdf

Did 1Password pass an audit for Linux? I now use pass so I don't have to worry about it anymore. I trust GPG and Ed25519.

It's a preview so probably not yet. I think the core is cross platform. I wasn't recommending 1Password for Linux though.

Re: 1Password for Linux development preview

#347
post #281
post #13

Earlier quoted context omitted.

I’m a recent windows 10 convert from Mac and a 1password user for years, I have disagreements with my buddy who is a long time windows user along these lines _all_ the time. He thinks I’m insane for essentially paying for UI I prefer (I would disagree I think there’s some structural differences, but I’m okay with being reduced to that too). It’s like asking why someone buys anything, the products exist and sell and m…

> I’m a recent windows 10 convert from Mac What happened, if not too sensitive to share, of course.

Ah sorry I missed it. My poor macbook pro of 8 years finally chimed it's last boot chime, so to speak. I have a windows PC that I had used mostly for games/web, so "convert" might be strong, I just haven't decided if its worth replacing :)

Re: 1Password for Linux development preview

#348
post #109
post #104

Earlier quoted context omitted.

How do you sync your local vaults across different machines?

Some of them I sync via Dropbox’s native 1Password integration. Others are stored as raw files from 1Password’s perspective, and I sync them by either copying the files or storing the file vault in Google Drive.

If you don't mind sharing: what benefit do you get from this configuration vs using the features of 1Password.com that are included in membership? - Ben, 1Password

Re: 1Password for Linux development preview

#349
post #183

Earlier quoted context omitted.

But that's the point the OP is making, you have to trust what 1password is telling you. And they do have a very clear business interest in telling you that it uses best security practices even if they don't. I'm doubtful that you are able to look at the binaries and extract the inner workings from that.

>But that's the point the OP is making, you have to trust what 1password is telling you. Yeah, I have to trust a lot of software authors not to be actively malicious, because I don't have the time to audit literally everything I rely on. I have more reason to trust the authors of 1Password than those of almost any other package I use. >And they do have a very clear business interest in telling you that it uses best s…

These are great answers. Thank you. - Ben, 1Password

Re: 1Password for Linux development preview

#350

Earlier quoted context omitted.

€36 a year, so for a period of 5 years that makes €180. For me and my partner that would be €360 for 5 years! For a password manager... I also considered using KeepassXC and Strongbox on iOS, which is completely free (sync the database via iCloud.) KeepassXC's browser extensions are pretty bad though, hopefully that will change sometime soon. If you want to keep costs low, Bitwarden is currently your best option i th…

https://1password.com/families/ They’ve got a family-oriented subscription which is cheaper. Used it since it launched and it’s been transformative for both sharing credentials with my family and getting them into the habit of unique credentials on every site, and TOTP where possible as well. I can’t recommend 1Password enough and I’ve been a customer for a very long time, predating the move to subscription pricing a…

There's a problem with the family plan:

There's always 1 person (family organizer) who is in charge of everything, and can reset the other accounts...

Post reply on HN