Live data from Hacker News

1Password Secrets Automation

blog.1password.com

21–30 of 186 posts

Re: 1Password Secrets Automation

#21
post #19

Earlier quoted context omitted.

I thought AgileBits was pretty well respected around here. What dark patterns are you referring to?

I'm assuming he's referring to their beginnings of being a mostly local password manager (iirc they also had a one-off lifetime purchase), to forcing people to migrate to their cloud only infrastructure with a relatively high subscription price. I'd never heard of 1Password before they were fully SaaS, but as I understand it, some of the original users were pretty upset with this move. Either way, I used to be a 1Pas…

What did you switch to if you stopped using 1Password?

Re: 1Password Secrets Automation

#23

Hah. With the gimmicks, tricks, and dark patterns this company has pulled with consumer, what are the chances professionals would trust them with something like this?

This is getting a lot of downvotes, but I agree with it to a certain degree. Have a look through the Agile Bits support forums and you'll find all the dark patterns you want - the most famous being their hiding of buy outright options to push you to subscription, and the crippling of Dropbox sync to try to push you to their proprietary sync service. I've used 1Password for well over a decade, but a lot of their tactics in the last couple of years left a real sour taste and promoted me to try out every alternative available. Luckily for Agile Bits, the alternatives are all appalling.

Re: 1Password Secrets Automation

#24
While this looks interesting, I'll admit I feel like there's been a bit of drift from their bread and butter over the years since they launched their cloud thing and started pushing hard towards a subscription model. I chose them long ago specifically over options like LastPass because I liked having a rich application without internet dependency and their attention to detail and features there, but it's been a while since it feels like it got major new improvements vs the site. For example, while macOS and Windows have supported smart cards and security tokens like YubiKeys forever now, and I use them to login, unlock, authorize sudo/SSH, etc every day, 1Password still has no support. There are things that can now only be done through the web interface, like finer grained control over permissions for shared vaults, and some of those are also nastily locked away behind more expensive subscriptions. I think everything should be manageable through the application, without ever visiting the site. Duplicate items across vaults remain completely manually managed, when automating stuff like that is kind of the purpose of a password manager. Etc. Heck, even within their own subscription service I think they're missing a trick by not having more powerful/flexible organization(including families) and inter-organizational capabilities.

I still think 1Password is the best option for most people. I specifically want my non-technical family and friends to use password managers too as long as its necessary, and having some multiperson capability is also key to that. I can't say though that I feel like the move to subs has been a huge win in terms of development.

Granted, I'm a little down on the whole field which colors things a bit. Ultimately underlying my feelings is a touch of bitterness that their entire industry even exists. Passwords and password managers are mostly recreating public key auth really, really badly and it stinks. Passwords and other symmetric tokens by definition should never be shared. A website being hacked should never affect me in the slightest, in the same way that me getting hacked doesn't somehow suddenly mean attackers now own Debian/Apple/FreeBSD/Microsoft. Everywhere should just have public keys. We've had the tech for decades and sufficient crypto speed on client systems since at least AES-NI. What's been missing has been glue and effort. It's frustrating every time a hack happens. We shouldn't have to care! Sigh.

Re: 1Password Secrets Automation

#25
post #12

Hah. With the gimmicks, tricks, and dark patterns this company has pulled with consumer, what are the chances professionals would trust them with something like this?

What gimmicks, tricks, and dark patterns are you referring to? I've been using 1Password for my personal accounts for probably close to 10 years and have been happy with it. There are some things I feel are clunky, but I've never felt like I was being tricked or deceived by the company.

"It used to be free but now you have to pay" is really the only dark pattern they are guilty of.

Re: 1Password Secrets Automation

#26
post #20

Why would anyone trust their passwords with closed source software, when there's alternatives out there that are?

Because it works seamlessly on all of my devices and has done so for years. Never encountered any issues and syncing happens within seconds.

I've been quite happy with KeePassXC / KeePass2Android and syncing via Google Drive.

Re: 1Password Secrets Automation

#27
Strange to see this. The product is a mess on MacOs right now. Support can’t decide which extension to recommend.

Their messaging has been inconsistent, saying the browser will integrate with the native client. But then also that the browser only version is the future of the product.

This says nothing of the performance and UI problems the product has faced. Recently it was so bad the company was telling people to use the beta version.

I bought the legacy versions and switched to subscription last year.

Re: 1Password Secrets Automation

#28
post #18
post #6

Here's to hoping there's finally a Hashicorp Vault competitor. It's shocking that the only mature option for runtime secret delivery is Vault after all these years. Some companies have created 'competitors', but they aren't even remotely mature (google secrets manager, aws secret manager, etc)

We use EnvKey [0], it's far friendlier to use than Vault and very mature. My only dislike is the Electron based app, but I so rarely have to open it that I can live with it. https://www.envkey.com

Still no option to self host.

The founder of Envkey claimed they were working hard on V2 and self hosting 1.5 years ago[0] so it’s anyone’s guess as to why that’s been delayed/isn’t happening.

[0] https://news.ycombinator.com/item?id=21226715

Re: 1Password Secrets Automation

#29
post #20

Why would anyone trust their passwords with closed source software, when there's alternatives out there that are?

Because it works seamlessly on all of my devices and has done so for years. Never encountered any issues and syncing happens within seconds.

Amusingly enough 1Password's main area of pain (for me) has been integration with Safari itself. It's much better on Chrome until you turn off Apple's password thing in Safari.

It works great to have both enabled on iPhone/iPad however. No idea why they can't fix the overlapping fields in Safari.

https://1password.community/discussion/116898/in-big-sur-saf...

Re: 1Password Secrets Automation

#30
post #19

Earlier quoted context omitted.

I'm assuming he's referring to their beginnings of being a mostly local password manager (iirc they also had a one-off lifetime purchase), to forcing people to migrate to their cloud only infrastructure with a relatively high subscription price. I'd never heard of 1Password before they were fully SaaS, but as I understand it, some of the original users were pretty upset with this move. Either way, I used to be a 1Pas…

What did you switch to if you stopped using 1Password?

Bitwarden. One of the big reasons for doing so was because when I left my company, they took my Mac away from me, so I invested in a new laptop, for me there was no way I was going for Windows or Mac. So Linux it is. 1Password at the time had extremely poor support for Linux - no desktop client, their 1PasswordX was missing a lot of features and was super slow too.

I switched to Bitwarden because it's open source, and because they have a good enough Linux client. Their browser extension and desktop client doesn't come close to what 1Password provided on Mac, but it does the job.

Bitwarden isn't without its issues, but at $10 a year, and its open source nature, it's worth every penny and then some.

Post reply on HN