I was hoping this was a way to automate changing my passwords. That’s something no password manager does, Anna would be great if I could rotate my hundreds of passwords on a regular basis.
1Password Secrets Automation
151–160 of 186 posts
Re: 1Password Secrets Automation
#152Earlier quoted context omitted.
Bitwarden. One of the big reasons for doing so was because when I left my company, they took my Mac away from me, so I invested in a new laptop, for me there was no way I was going for Windows or Mac. So Linux it is. 1Password at the time had extremely poor support for Linux - no desktop client, their 1PasswordX was missing a lot of features and was super slow too. I switched to Bitwarden because it's open source, an…
Thanks for sharing. I’m sorry it took us so long to release a native Linux app. We have a great app for Linux now in beta and will move it to an official release shortly. https://blog.1password.com/1password-for-linux-beta-is-now-o... I hope you can give us another chance. —Dave 1Password Founder
Re: 1Password Secrets Automation
#153Earlier quoted context omitted.
Hi! I work for 1Password. We have this functionality available in beta with our 1Password for Linux app. It will be available on Mac and Windows in the not-too-distant future, though I can't say more specifically when that will be. [1] https://1password.community/discussion/comment/591579/#Comme...
Can you explain why this was removed, and why it was re-introduced on a platform other than OS X (given that biometric identifiers have become standard in Apple hardware)?
A it more than a year ago we had
- 1Password for Mac and iOS written in Objective-C and Swift - 1Password for Android, written in Java - 1Password for Windows, written in C# - 1Password CLI, written in Go - 1Password web-app, in Typescript - Browser extension in Typescript
Introducing new features was an ever more difficult task. Even getting the behavior of things like password strength meters or generators behaving the same across these platforms was increasingly difficult. (Hint, they didn’t behave the same.)
So we have been taking the time to develop a common core of code that can be used everywhere. And this does take time. Writing the common modules is often relatively easy, but we have to get them to work with the platform specific code
Late 2019 was our first successful deployment of any such function, and that was the TOTP calculator. It was largely transparent to users, except for settling on which sorts of TOTP “quirks” we were going to follow. (TOTP standards are a mess, and different Authenticator apps deal with special cases differently. At least 1Password is now fully consistent with itself)
Over the past year, we’ve been plugging more such things into the apps. And it allows us to fix bugs more quickly as well ashen they are in the common code.
1Paaword for Linux is built on all the new/common code. So while it doesn’t have everything that the others do, it is also where you will see the née stuff that is coming.
This has been a huge effort, and the transition has some rough spots, but once we get there we will be able to move much more quickly in developing and refining features and behaviors.
Re: 1Password Secrets Automation
#154Earlier quoted context omitted.
Very much agree. My pet peeve at the moment is this[1], where they removed a feature I very much like (TouchID in the standalone browser extension) and still have yet to replace that functionality despite many promises that it is just around the corner. It was removed in August 2020. Definitely feel like they've lost sight of why people chose them in the first place, and stuff like this is certainly not helping assua…
It's a fundamental concern I've always had with subscriptions for non-entertainment services or trivially fungible goods. I've become a big believer in business incentives and feedback loops for sustainable commercial relationships. Individual leadership and culture can stand against them to some extent for a time, but individuals move on and it seems that near inevitably over enough years organizations tend to track…
honestly i think these things are more about lock-in or perceived lock-in, or simply not wanting to waste precious time. even though it's actually fairly easy to jump between password managers, it's still a "migration" or another task where when one's time becomes scarce the thrill of a sundry task like redoing one's passwords is overshadowed by the laundry list of things one could do with their time instead. sure, it's nice to tend the garden, but how many other things would you rather spend an afternoon on that either develop skills, enhance life or recreate in one way or another.
Re: 1Password Secrets Automation
#155Earlier quoted context omitted.
I'm trying to charitably understand what you're advocating for but it sounds like you're arguing that getting multiple people to use any app is criteria for dark pattern because once they do start using that app, to switch you have to convince them as a group. So.. should everyone use different apps? Or is a protocol the solution? As far as where data is stored, which sounds a bit like a different argument, I guess w…
I think you are interpreting too much into my side comment of “its a dark pattern I guess”. Hereby I retract this part of my statement.
Re: 1Password Secrets Automation
#156While this looks interesting, I'll admit I feel like there's been a bit of drift from their bread and butter over the years since they launched their cloud thing and started pushing hard towards a subscription model. I chose them long ago specifically over options like LastPass because I liked having a rich application without internet dependency and their attention to detail and features there, but it's been a while…
there are commercial entities today that i don't have to trust, but will help me set up multiparty signatures for sending bitcoin transactions. i could see a similar mechanism being used for creating/revoking/recovering a compromised identity.
hierarchical deterministic wallets seem a decent blueprint for identity. if i can generate arbitrary pubkeys from a single seed, then i maintain my privacy across providers i use my identity with.
i used to think that the blockchain itself could make for a decent revocation list, but i don't think that's even neccessary. maybe it's simply time for governments to grow up and accept that the internet is critical now and as such provide basic digital identity services as they do with travel documents today. it doesn't have to be perfect, just publish revocations on behalf of citizens.
Re: 1Password Secrets Automation
#157I’ve never commented on a HN post, but finally you’ve all got to me. Why are people mostly commenting moaning about something completely different to what the article is about? Fine, I get it, you don’t like 1Password’s tactics regarding subscription models. But this is about infrastructure secret management. It’s the same with Google Cloud announcements “hOw LoNg UnTiL tHeY dEprEcAtE iT???” ... boooooooring
The problem with a comment like this is that it actually commits the sin you're complaining about (i.e. not talking about what the article is actually about) worse than the comments being denounced. That can't help.
Re: 1Password Secrets Automation
#158Earlier quoted context omitted.
Can you explain why this was removed, and why it was re-introduced on a platform other than OS X (given that biometric identifiers have become standard in Apple hardware)?
To elaborate on what my colleague, Ben, said, we have been in the process moving to more common cross platform code. A it more than a year ago we had - 1Password for Mac and iOS written in Objective-C and Swift - 1Password for Android, written in Java - 1Password for Windows, written in C# - 1Password CLI, written in Go - 1Password web-app, in Typescript - Browser extension in Typescript Introducing new features was…
Reading between the lines a bit - biometric authentication was deprecated (from ‘for Mac’) as it was broken or at risk of breaking, and further dev on legacy code was moot due to the transition?
Re: 1Password Secrets Automation
#159Earlier quoted context omitted.
> I use a password manager but, as a mostly-Apple user, I see very little reason not to just use iCloud Keychain Storing 2FA tokens is one thing iCloud Keychain cannot do (yet ?), and it’s the primary reason I use 1Password over iCloud Keychain. That being said, with Big Sur, 1Password changed its default behavior from being unintrusive to literally obscuring input fields with big “unlock 1Password” pop up’s. I’m cur…
> That being said, with Big Sur, 1Password changed its default behavior from being unintrusive to literally obscuring input fields with big “unlock 1Password” pop up’s. That's not a Big Sur thing, that's a 1Password thing (I've not upgraded to Big Sur still).
Re: 1Password Secrets Automation
#160Earlier quoted context omitted.
> I use a password manager but, as a mostly-Apple user, I see very little reason not to just use iCloud Keychain Storing 2FA tokens is one thing iCloud Keychain cannot do (yet ?), and it’s the primary reason I use 1Password over iCloud Keychain. That being said, with Big Sur, 1Password changed its default behavior from being unintrusive to literally obscuring input fields with big “unlock 1Password” pop up’s. I’m cur…
I think the fingerprint auth stuff Apple’s working on will replace MFA: as I understand it, in Safari, the MacBook’s Fingerprint sensor implements the same protocol as a Yubikey or similar.
Hope because it would allow me to utilize my mac as a Yubikey. I have no idea how they would synchronize it to all Apple devices, but i'm fairly certain they will find a way.
Fear because it will pretty much guarantee i cannot use my password manager on other platforms.
I already use Secretive (https://github.com/maxgoedjen/secretive) to store SSH keys in the secure enclave with touch id integration, and it works really well. I also keep a couple of Yubikeys as backup :)