Live data from Hacker News

1Password Secrets Automation

blog.1password.com

121–130 of 186 posts

Re: 1Password Secrets Automation

#121
post #109

Earlier quoted context omitted.

If I were unfamiliar with 1Password, I'd imagine the product is an absolute dumpster fire from your post. In reality, the macOS and iOS clients work fine. I have a dozen friends and family members using the product with no complains on those platforms. I surely haven't seen any performance or UI problems that aren't worse on different services. Sure, there is some current confusion between the use of the 1Password X…

I wouldn't say the product is a dumpster fire, but core workflows are a mess. This is how you generate and save a password for a new site: 1) Extension button > Generate Password > Save & Copy 2) After creating account, extension button again > select entry > Edit 3) Click Save in opened modal 4) Click Convert to Login in opened modal 5) Click Edit in opened modal 6) Manually type in the username/email you used on th…

Yes, this convert to login only after the item being saved makes little sense. It took a few times of catching the button being shown to figure out the pattern of clicks needed to do this fundamental aspect of what the product is intended to do.

Re: 1Password Secrets Automation

#122
post #26

Earlier quoted context omitted.

I've been quite happy with KeePassXC / KeePass2Android and syncing via Google Drive.

Not sure about Android but, for iOS users, it makes no sense trusting open source software. So, even if you choose strongbox or keepassium as they’re open source you’re still trusting some dude as you have no option to verify that the iOS build is the same as the build on github. This is why I prefer to give my password to a company like Bitwarden and 1Password. At least, they have less incentive to be malicious than…

Bitwarden used to be a "random dude" project for quite a while...

Re: 1Password Secrets Automation

#123

The article is a little light on details but this seems like a cool addition to 1Password. The op cli is alright but having to re-unlock it every 30 minutes (plus I'm shell dumb so my session is nuked every new tab I open) means there's quite a lot of friction compared to the desktop version where I just double tap the side button on my Apple watch I wonder if this could be a potential alternative in some roundabout…

Probably about them not supporting personal hosting as well anymore. I get that customers got angry, but as someone who started using their product after that, with their hosting, they have been nothing but nice and receptive to feedback.

Re: 1Password Secrets Automation

#124
post #76

Earlier quoted context omitted.

If I were unfamiliar with 1Password, I'd imagine the product is an absolute dumpster fire from your post. In reality, the macOS and iOS clients work fine. I have a dozen friends and family members using the product with no complains on those platforms. I surely haven't seen any performance or UI problems that aren't worse on different services. Sure, there is some current confusion between the use of the 1Password X…

The iOS app is stable and fine. The MacOS native / extension interaction and choice is a mess. From a UX perspective, the single most important thing the product can do is interact with the browser effectively. Embedded in this "feature" is that the product is stable, and responsive in behavior. If you go to the chrome web store, 1password extension page and sort by recently updated, you'll see review after review of…

There’s also 2 native apps - if you install from the App Store, you don’t get all the same OTP features as an install from the website download

Re: 1Password Secrets Automation

#125
post #118
post #42

Earlier quoted context omitted.

It's a fundamental concern I've always had with subscriptions for non-entertainment services or trivially fungible goods. I've become a big believer in business incentives and feedback loops for sustainable commercial relationships. Individual leadership and culture can stand against them to some extent for a time, but individuals move on and it seems that near inevitably over enough years organizations tend to track…

There is a rub to this too however. In a pay to upgrade model you are incentivised to stuff your application with features and also need to support old versions indefinitely if they have network components. Granted in 1Pssword case, their classic app would not have stopped working without upgrades. And to my knowledge it should also still work? I have since switched to the subscription model but I have used the old p…

Using 1Password 6 standalone app here without issues. Dropbox integration still works, and that's all the "cloud" I need.

Re: 1Password Secrets Automation

#126
The documentation is very sparse. I have a few questions.

- Why does the integration require two servers with exposed ports? The REST API documentation doesn't say which service I need to connect to for the resources, so I assume the answer is the API server, so what does the other server listen for?

- How do I request a TOTP? In particular, am I correct in my assumption that the implementation is simply providing you with the TOTP seed values, rather than a TOTP?

- Is there any audit logging whatsoever?

Re: 1Password Secrets Automation

#127
post #122

Earlier quoted context omitted.

Not sure about Android but, for iOS users, it makes no sense trusting open source software. So, even if you choose strongbox or keepassium as they’re open source you’re still trusting some dude as you have no option to verify that the iOS build is the same as the build on github. This is why I prefer to give my password to a company like Bitwarden and 1Password. At least, they have less incentive to be malicious than…

Bitwarden used to be a "random dude" project for quite a while...

Yeah and I’ve never used it while it was a random dude project. You need enough street cred if you want me to trust my whole life in your hands.

Re: 1Password Secrets Automation

#128

Earlier quoted context omitted.

Hi! I work for 1Password. We have this functionality available in beta with our 1Password for Linux app. It will be available on Mac and Windows in the not-too-distant future, though I can't say more specifically when that will be. [1] https://1password.community/discussion/comment/591579/#Comme...

Can you explain why this was removed, and why it was re-introduced on a platform other than OS X (given that biometric identifiers have become standard in Apple hardware)?

It was removed because we needed to change directions on development and continuing to maintain it as well as build out the new implementation was untenable. It came out on Linux first because the Linux app was developed with it in mind, whereas on other platforms we were re-working existing systems to integrate with it. The former materialized quicker.

- Ben, 1Password

Re: 1Password Secrets Automation

#129
post #76

Earlier quoted context omitted.

The iOS app is stable and fine. The MacOS native / extension interaction and choice is a mess. From a UX perspective, the single most important thing the product can do is interact with the browser effectively. Embedded in this "feature" is that the product is stable, and responsive in behavior. If you go to the chrome web store, 1password extension page and sort by recently updated, you'll see review after review of…

There’s also 2 native apps - if you install from the App Store, you don’t get all the same OTP features as an install from the website download

That is a limitation imposed by the App Store's rules. We're unable to use the screen recording system permission to look for QR codes on screen. Otherwise all of the OTP features are there. You can drag and drop a QR code onto the reader to add an OTP to a record, for example.

- Ben, 1Password

Post reply on HN