Live data from Hacker News

1Password Secrets Automation

blog.1password.com

111–120 of 186 posts

Re: 1Password Secrets Automation

#111

I’ve never commented on a HN post, but finally you’ve all got to me. Why are people mostly commenting moaning about something completely different to what the article is about? Fine, I get it, you don’t like 1Password’s tactics regarding subscription models. But this is about infrastructure secret management. It’s the same with Google Cloud announcements “hOw LoNg UnTiL tHeY dEprEcAtE iT???” ... boooooooring

Good comment. I disliked the 1P subscription model and moved to paying bitwarden for personal use but I use 1P for work and its a perfectly cromulent functional system, and works well.

Secrets management for network systems has been an issue since before kerberos. Having different models, isolating secrets from the repo and deployment codebase into a 3rd party module is one of the rational choices.

I would want to understand a secure secret import and export model, much as for an HSM you want to know how to move shrouded keys (if its not in FIPS mode i guess)

Re: 1Password Secrets Automation

#112

I purchased my first 1Password license when it was version 3, and have faithfully upgraded to every standalone version ever since. These days I’m not so sure I will be upgrading again (and I’m not sure there will be more stand alone versions). The latest version is a mess on Big Sur, with unlock fields obscuring input fields, conflicting with Apples iCloud Keychain, and just not working like I expect it to. Furthermo…

Just out of curiosity, as someone who selfhosts Bitwarden, how is 1Password so much more polished? I’ve never used 1Pass. Just, I’m always amazed by how well Bitwarden works and how there’s not really features I’m lacking.

As someone who switched form 1Password to Bitwarden a year or so ago, there are a few features I miss:

1. The ability to customize keybindings.

2. If try to autofill a form field, and BW is locked, then nothing happens. The same task in 1P will actually prompt me to unlock 1P, then I am able to autofill the field.

3. If create an account for a site not saved in BW, and BW is locked, then I am not prompted to save the login. However, 1P will prompt to unlock itself so that I may save the login. Also, the prompt for saving logins rarely works for me using BW, but worked rather well for me using 1P.

4. BW is not as keen as 1P for auto-filling various form fields

5. I like storing software licenses, wi-fi passwords, bank accounts, etc. in 1P vs. secure notes in BW.

6. I am not a fan of BW's folders for organizing logins.

7. BW relies too heavily on mouse usage for my liking. I felt that 1P had much better keyboard navigation.

There are probably other things I am missing, but with all that being said, I still have not left BW to return to 1P nor do I plan to anytime soon. Though, I will admit I miss many features from 1P still.

Re: 1Password Secrets Automation

#113

I purchased my first 1Password license when it was version 3, and have faithfully upgraded to every standalone version ever since. These days I’m not so sure I will be upgrading again (and I’m not sure there will be more stand alone versions). The latest version is a mess on Big Sur, with unlock fields obscuring input fields, conflicting with Apples iCloud Keychain, and just not working like I expect it to. Furthermo…

Just out of curiosity, as someone who selfhosts Bitwarden, how is 1Password so much more polished? I’ve never used 1Pass. Just, I’m always amazed by how well Bitwarden works and how there’s not really features I’m lacking.

Two things i miss in Bitwarden coming from 1Password are:

1. One shortcut for unlocking and auto filling. There is a long open issue[1].

2. Not needing to unlock the extension to add a new login entry. 1Password just detects new logins even when the vault is locked.

Otherwise Bitwarden is really solid.

[1] https://community.bitwarden.com/t/autofill-shortcut-should-o...

Re: 1Password Secrets Automation

#114

I’ve never commented on a HN post, but finally you’ve all got to me. Why are people mostly commenting moaning about something completely different to what the article is about? Fine, I get it, you don’t like 1Password’s tactics regarding subscription models. But this is about infrastructure secret management. It’s the same with Google Cloud announcements “hOw LoNg UnTiL tHeY dEprEcAtE iT???” ... boooooooring

I've found that HN often chats about something only tangentially related to the article. And I think it's actually part of the culture here. But I agree that when you are passionate about a given topic it is a bit of a letdown when the comments are not directly about the article. Note that we've both commented on something different from the article in this case.

Yes, the irony wasn’t lost on me haha!

I do like using 1Password, it does make life a bit easier, and I’m grateful for its existence.

I think this is an interesting offering and will take it for a spin soon!

Re: 1Password Secrets Automation

#115
post #2

This looks interesting. We use 1Password, and I always thought it would be useful to programmatically pull values out and use in our cloud infrastructure. Currently we end up using the secret managers available in AWS or GCP, which seems pretty half baked. In GCP, for example, secrets are stored at a project level. It's not unusual to have certain secrets that are needed by more than one project, which means they get…

This is why we use Vault. Until recently, there was no good option to host it, so you had to manage it. It's good to have independent competition in this space.

[I work for 1Password]

1Password is not competing with Vault. In fact we have very good relationships and mutual respect with HashiCorp on many levels.

Also Secret automation integrates (acts as a provider) with HC Vault[1]

1. https://github.com/1Password/vault-plugin-secrets-onepasswor...

Re: 1Password Secrets Automation

#116
post #6

Here's to hoping there's finally a Hashicorp Vault competitor. It's shocking that the only mature option for runtime secret delivery is Vault after all these years. Some companies have created 'competitors', but they aren't even remotely mature (google secrets manager, aws secret manager, etc)

[I work for 1Password] 1Password is not competing with Vault. In fact we have very good relationships and mutual respect with HashiCorp on many levels.

Also Secret automation integrates (acts as a provider) with HC Vault[0]

0: https://github.com/1Password/vault-plugin-secrets-onepasswor...

Re: 1Password Secrets Automation

#117
post #111

I’ve never commented on a HN post, but finally you’ve all got to me. Why are people mostly commenting moaning about something completely different to what the article is about? Fine, I get it, you don’t like 1Password’s tactics regarding subscription models. But this is about infrastructure secret management. It’s the same with Google Cloud announcements “hOw LoNg UnTiL tHeY dEprEcAtE iT???” ... boooooooring

Good comment. I disliked the 1P subscription model and moved to paying bitwarden for personal use but I use 1P for work and its a perfectly cromulent functional system, and works well. Secrets management for network systems has been an issue since before kerberos. Having different models, isolating secrets from the repo and deployment codebase into a 3rd party module is one of the rational choices. I would want to un…

Thanks! It seems I started using 1Password after its model changed, so I’ve never had to really think about it, but I can appreciate the frustration.

I’m happy to just have another offering in the world of secrets management

Re: 1Password Secrets Automation

#118
post #42

Earlier quoted context omitted.

Very much agree. My pet peeve at the moment is this[1], where they removed a feature I very much like (TouchID in the standalone browser extension) and still have yet to replace that functionality despite many promises that it is just around the corner. It was removed in August 2020. Definitely feel like they've lost sight of why people chose them in the first place, and stuff like this is certainly not helping assua…

It's a fundamental concern I've always had with subscriptions for non-entertainment services or trivially fungible goods. I've become a big believer in business incentives and feedback loops for sustainable commercial relationships. Individual leadership and culture can stand against them to some extent for a time, but individuals move on and it seems that near inevitably over enough years organizations tend to track…

There is a rub to this too however. In a pay to upgrade model you are incentivised to stuff your application with features and also need to support old versions indefinitely if they have network components.

Granted in 1Pssword case, their classic app would not have stopped working without upgrades. And to my knowledge it should also still work? I have since switched to the subscription model but I have used the old paid app years after they have switched models.

Re: 1Password Secrets Automation

#119
post #82

I was hoping this was a way to automate changing my passwords. That’s something no password manager does, Anna would be great if I could rotate my hundreds of passwords on a regular basis.

LastPass has been auto-changing passwords for quite awhile now [0]. I am a 1Password user, but I've considered making the switch to LastPass for this feature alone. - [0] http://blog.lastpass.com/2014/12/introducing-auto-password-c...

Wow that's amazing. I had no idea that existed anywhere, let alone for years now! Thanks for pointing that out... I wonder how many sites now actively support that, how it works with 2FA, etc. I have hundreds of passwords, many not from big shops. Hopefully 'it just works' with these.

Re: 1Password Secrets Automation

#120
post #18
post #6

Here's to hoping there's finally a Hashicorp Vault competitor. It's shocking that the only mature option for runtime secret delivery is Vault after all these years. Some companies have created 'competitors', but they aren't even remotely mature (google secrets manager, aws secret manager, etc)

We use EnvKey [0], it's far friendlier to use than Vault and very mature. My only dislike is the Electron based app, but I so rarely have to open it that I can live with it. https://www.envkey.com

Also a big fan of EnvKey here. We used them for over a year but ended up moving to AWS parameter store as part of a wider migration. Ability to self-host could have helped us stay on there longer, we just didn't want external dependencies in such a critical path. But otherwise, it served us well with zero hiccups.
Post reply on HN