Live data from Hacker News

1Password Secrets Automation

blog.1password.com

131–140 of 186 posts

Re: 1Password Secrets Automation

#131

The documentation is very sparse. I have a few questions. - Why does the integration require two servers with exposed ports? The REST API documentation doesn't say which service I need to connect to for the resources, so I assume the answer is the API server, so what does the other server listen for? - How do I request a TOTP? In particular, am I correct in my assumption that the implementation is simply providing yo…

Hello!

> - Why does the integration require two servers with exposed ports? The REST API documentation doesn't say which service I need to connect to for the resources, so I assume the answer is the API server, so what does the other server listen for?

The server you'd interact with is the API server. The other server is responsible for syncing. The fact that there are two was a design decision.

> - How do I request a TOTP? In particular, am I correct in my assumption that the implementation is simply providing you with the TOTP seed values, rather than a TOTP?

I don't believe we can provide the current OTP value as it stands. This is something I'd be happy to suggest to the team that we look at for a future iteration.

> - Is there any audit logging whatsoever?

Yes! You can either audit from the container directly, or through the item usage report in the 1Password.com web app.

If you need further assistance please feel free to reach out to us. We'd be happy to help. https://support.1password.com/contact/

- Ben, 1Password

Re: 1Password Secrets Automation

#132
post #66

Earlier quoted context omitted.

A new feature that adds value is not a 'dark pattern'. Lets not be dramatic. Even moving from one-time to subscription isn't a 'dark pattern', its a business model move to shift to recurring revenue, which we know is something that businesses need to keep the lights on. You can debate the merits of it, but it's not a dark pattern in and of itself. HOW they execute that might be, but the change itself isn't. You just…

> A new feature that adds value is not a 'dark pattern'. Lets not be dramatic. Family plans are in my eyes. They log users more into the platform and makes it very difficult to switch. If you want to move away from Spotify, you now have to convince enough of the others to make it feasible. > Even moving from one-time to subscription isn't a 'dark pattern' I did not claim that it was one. I also was not even mad about…

I'm trying to charitably understand what you're advocating for but it sounds like you're arguing that getting multiple people to use any app is criteria for dark pattern because once they do start using that app, to switch you have to convince them as a group. So.. should everyone use different apps? Or is a protocol the solution?

As far as where data is stored, which sounds a bit like a different argument, I guess what you're advocating for is some kind of peer-to-peer sync solution across family member devices that would work anywhere. That's cool but I think it may a lot of technical complexity vs a cloud solution, and it still doesn't change the fact that you still have the issue above about switching as a group.

It might be worth reviewing what dark pattern actually means - UI tricks to get people to do things they don't want to do. If people like a product enough that they convince others to use it as well, that's ... a good product? I get the data storage concern though.

https://en.wikipedia.org/wiki/Dark_pattern

Re: 1Password Secrets Automation

#133

Earlier quoted context omitted.

If I were unfamiliar with 1Password, I'd imagine the product is an absolute dumpster fire from your post. In reality, the macOS and iOS clients work fine. I have a dozen friends and family members using the product with no complains on those platforms. I surely haven't seen any performance or UI problems that aren't worse on different services. Sure, there is some current confusion between the use of the 1Password X…

Disagree. Currently the product IS a dumpster fire imo. On macOS, half the time auto fill doesn't work. Saving a password is very inconsistent. When you auto generate a password, the least resistance UI workflow is to first save and fill it - but then when you create the account it is saved again, making it a duplicate. And don't get me started on the Windows client - on my fast gaming PC it takes forever just to unl…

And the “Convert to login” button is hidden away now for some reason.

Re: 1Password Secrets Automation

#135

The documentation is very sparse. I have a few questions. - Why does the integration require two servers with exposed ports? The REST API documentation doesn't say which service I need to connect to for the resources, so I assume the answer is the API server, so what does the other server listen for? - How do I request a TOTP? In particular, am I correct in my assumption that the implementation is simply providing yo…

Hello! > - Why does the integration require two servers with exposed ports? The REST API documentation doesn't say which service I need to connect to for the resources, so I assume the answer is the API server, so what does the other server listen for? The server you'd interact with is the API server. The other server is responsible for syncing. The fact that there are two was a design decision. > - How do I request…

Thanks for the reply! You didn't quite completely answer my first question. Why does the "sync" server have an exposed port? I'm going based on the docker-compose.yml you provide.

Re: 1Password Secrets Automation

#136
post #2

This looks interesting. We use 1Password, and I always thought it would be useful to programmatically pull values out and use in our cloud infrastructure. Currently we end up using the secret managers available in AWS or GCP, which seems pretty half baked. In GCP, for example, secrets are stored at a project level. It's not unusual to have certain secrets that are needed by more than one project, which means they get…

We reverse engineered it so we can pull stuff ourselves.

BTW: don’t forget to empty trust in 1P. Noticed the API giving back a lot more stuff than expected and that is why.

Re: 1Password Secrets Automation

#137

I’ve never commented on a HN post, but finally you’ve all got to me. Why are people mostly commenting moaning about something completely different to what the article is about? Fine, I get it, you don’t like 1Password’s tactics regarding subscription models. But this is about infrastructure secret management. It’s the same with Google Cloud announcements “hOw LoNg UnTiL tHeY dEprEcAtE iT???” ... boooooooring

The problem with a comment like this is that it actually commits the sin you're complaining about (i.e. not talking about what the article is actually about) worse than the comments being denounced. That can't help.

Re: 1Password Secrets Automation

#138

Earlier quoted context omitted.

There’s also 2 native apps - if you install from the App Store, you don’t get all the same OTP features as an install from the website download

That is a limitation imposed by the App Store's rules. We're unable to use the screen recording system permission to look for QR codes on screen. Otherwise all of the OTP features are there. You can drag and drop a QR code onto the reader to add an OTP to a record, for example. - Ben, 1Password

Ben, can you address what is going on with the password save UX / convert to login flow?

Re: 1Password Secrets Automation

#139
post #118

Earlier quoted context omitted.

There is a rub to this too however. In a pay to upgrade model you are incentivised to stuff your application with features and also need to support old versions indefinitely if they have network components. Granted in 1Pssword case, their classic app would not have stopped working without upgrades. And to my knowledge it should also still work? I have since switched to the subscription model but I have used the old p…

Using 1Password 6 standalone app here without issues. Dropbox integration still works, and that's all the "cloud" I need.

Same with me with 1Password 4 on Windows, via Dropbox as well
Post reply on HN