Live data from Hacker News

1Password Secrets Automation

blog.1password.com

81–90 of 186 posts

Re: 1Password Secrets Automation

#81
post #13

Earlier quoted context omitted.

I've had good luck with Azure KeyVault.

Ditto. The managed service provider VS user assigned rbac was confusing at first, but now I am happy that I took the time to understand it. Also the azure clouds handling of vaulted passwords in log files from services like Logic apps) is absolutely bad ass.

> Also the azure clouds handling of vaulted passwords in log files from services like Logic apps) is absolutely bad ass.

This is particularly interesting to me. Is there a good doc page or blog post that you're aware of that covers these capabilities? I'm curious and would love to learn more.

Re: 1Password Secrets Automation

#82

I was hoping this was a way to automate changing my passwords. That’s something no password manager does, Anna would be great if I could rotate my hundreds of passwords on a regular basis.

LastPass has been auto-changing passwords for quite awhile now [0]. I am a 1Password user, but I've considered making the switch to LastPass for this feature alone.

- [0] http://blog.lastpass.com/2014/12/introducing-auto-password-c...

Re: 1Password Secrets Automation

#83

This is very cool. I spent about 20 minutes playing with it and was successful in setting it up and getting some janky python code to work with it. The fact that it's a local sync daemon with local API, is super smart. No worries about cloud outages. Is Hashicorp vault "better"? Probably. However for groups that don't have the time and resources for Vault, this is a great first step. Much better than what most do whi…

Another reason for the local hosting is so that we (I work for 1Password) are never in a position to acquire secrets can be used to decrypt your data.

Re: 1Password Secrets Automation

#84
post #2

This looks interesting. We use 1Password, and I always thought it would be useful to programmatically pull values out and use in our cloud infrastructure. Currently we end up using the secret managers available in AWS or GCP, which seems pretty half baked. In GCP, for example, secrets are stored at a project level. It's not unusual to have certain secrets that are needed by more than one project, which means they get…

My team uses 1Password to share account credentials, etc. When we need to deploy secrets into production, we use AWS Systems Manager Parameter Store.

The name is quite a mouthful, but we have found the service to be awesome. We have a small Python script that loads a script with environment variable definitions from the Parameter Store and we use that as an EnvFile for our systemd services.

Re: 1Password Secrets Automation

#85
post #24

While this looks interesting, I'll admit I feel like there's been a bit of drift from their bread and butter over the years since they launched their cloud thing and started pushing hard towards a subscription model. I chose them long ago specifically over options like LastPass because I liked having a rich application without internet dependency and their attention to detail and features there, but it's been a while…

Very much agree. My pet peeve at the moment is this[1], where they removed a feature I very much like (TouchID in the standalone browser extension) and still have yet to replace that functionality despite many promises that it is just around the corner. It was removed in August 2020. Definitely feel like they've lost sight of why people chose them in the first place, and stuff like this is certainly not helping assua…

Yeah, definitely taking them longer to get this back than they’d planned. Fortunately the ‘classic’ extension for chrome still exists and works.

Re: 1Password Secrets Automation

#86
post #27

Strange to see this. The product is a mess on MacOs right now. Support can’t decide which extension to recommend. Their messaging has been inconsistent, saying the browser will integrate with the native client. But then also that the browser only version is the future of the product. This says nothing of the performance and UI problems the product has faced. Recently it was so bad the company was telling people to us…

If I were unfamiliar with 1Password, I'd imagine the product is an absolute dumpster fire from your post. In reality, the macOS and iOS clients work fine. I have a dozen friends and family members using the product with no complains on those platforms. I surely haven't seen any performance or UI problems that aren't worse on different services. Sure, there is some current confusion between the use of the 1Password X…

Disagree. Currently the product IS a dumpster fire imo. On macOS, half the time auto fill doesn't work. Saving a password is very inconsistent. When you auto generate a password, the least resistance UI workflow is to first save and fill it - but then when you create the account it is saved again, making it a duplicate. And don't get me started on the Windows client - on my fast gaming PC it takes forever just to unlock the vault.

I've cancelled my subscription and won't renew once it runs out.

Re: 1Password Secrets Automation

#87
post #48

Earlier quoted context omitted.

> I specifically want my non-technical family and friends to use password managers I consider it a victory if I can get non-techies to use their browser's facilities to store passwords, and then to choose reasonably long passwords and avoid reuse. (I use `pass`, myself.)

I use a password manager but, as a mostly-Apple user, I see very little reason not to just use iCloud Keychain: the UX of Apple’s solution is significantly better than all the alternatives because I don’t have to remember yet another password/mfa token to type in every once in a while.

> I use a password manager but, as a mostly-Apple user, I see very little reason not to just use iCloud Keychain

Storing 2FA tokens is one thing iCloud Keychain cannot do (yet ?), and it’s the primary reason I use 1Password over iCloud Keychain.

That being said, with Big Sur, 1Password changed its default behavior from being unintrusive to literally obscuring input fields with big “unlock 1Password” pop up’s.

I’m currently evaluating using either Password-store or Bitwarden with bitwarden_rs as a backend as I really don’t want my logins synchronized anywhere I don’t control.

Re: 1Password Secrets Automation

#88

Earlier quoted context omitted.

Very much agree. My pet peeve at the moment is this[1], where they removed a feature I very much like (TouchID in the standalone browser extension) and still have yet to replace that functionality despite many promises that it is just around the corner. It was removed in August 2020. Definitely feel like they've lost sight of why people chose them in the first place, and stuff like this is certainly not helping assua…

Yeah, definitely taking them longer to get this back than they’d planned. Fortunately the ‘classic’ extension for chrome still exists and works.

Link: https://support.1password.com/cs/1password-classic-extension...

I prefer the above classic extensions for switching between Chrome, Safari, Firefox and Edge all day and not having to sign in more than once. Plus the better desktop app integration, including the ability to opt-out of cloud storage of passwords.

Re: 1Password Secrets Automation

#89
post #63
post #39

Earlier quoted context omitted.

What do you mean by locked in? When I think of locked in, I imagine it being hard to cancel and move to another service. I switched to 1Password last year from LastPass and the first thing I checked was the process for exporting my data. It seemed on par with LassPass, which was very simple, so I made the switch.

That's the locked in - they have all your passwords and (in theory) could make a change that makes it hard to extract.

Using the term ‘locked in’ to mean ‘some day something maybe might lock me in’ is a huuuuuuge stretch. To the point that I’d say you’re wrong.

Re: 1Password Secrets Automation

#90

Earlier quoted context omitted.

If I were unfamiliar with 1Password, I'd imagine the product is an absolute dumpster fire from your post. In reality, the macOS and iOS clients work fine. I have a dozen friends and family members using the product with no complains on those platforms. I surely haven't seen any performance or UI problems that aren't worse on different services. Sure, there is some current confusion between the use of the 1Password X…

Disagree. Currently the product IS a dumpster fire imo. On macOS, half the time auto fill doesn't work. Saving a password is very inconsistent. When you auto generate a password, the least resistance UI workflow is to first save and fill it - but then when you create the account it is saved again, making it a duplicate. And don't get me started on the Windows client - on my fast gaming PC it takes forever just to unl…

Yes the password save, something that should be the bread and butter of UX is so awkward. It’s painful.
Post reply on HN