Live data from Hacker News

1Password Secrets Automation

blog.1password.com

161–170 of 186 posts

Re: 1Password Secrets Automation

#161

I purchased my first 1Password license when it was version 3, and have faithfully upgraded to every standalone version ever since. These days I’m not so sure I will be upgrading again (and I’m not sure there will be more stand alone versions). The latest version is a mess on Big Sur, with unlock fields obscuring input fields, conflicting with Apples iCloud Keychain, and just not working like I expect it to. Furthermo…

Just out of curiosity, as someone who selfhosts Bitwarden, how is 1Password so much more polished? I’ve never used 1Pass. Just, I’m always amazed by how well Bitwarden works and how there’s not really features I’m lacking.

Besides what others have mentioned, there is one feature i really miss from not just bitwarden but almost every other password manager. I basically just want a password manager that can store my secrets (2FA tokens included!) in an encrypted format, integrates with filling passwords on desktops and handheld devices, _AND is able to (two way) synchronize this encrypted storage as a simple file to whatever storage i prefer.

That might be iCloud, OneDrive, WebDAV, S3, or simply just a SMB server on my local network. My main negative point about Bitwarden is that it either requires me to store passwords in a cloud on a subscription service, or it requires me to selfhost something.

Selfhosting is (probably) fine if we're talking a Plex server or something that isn't mission critical, but hosting a bitwarden server suddenly requires me to be a sysadm in my spare time, something i'd rather keep to my daytime job (and nights when operations calls, and weekends when things needs upgrading).

The only password manager i've found that ticks most boxes is password-store (https://www.passwordstore.org/), but it lacks in browser integration, and by default leaks web addresses for the stored secrets. Other than that it works well. It's self contained, and uses git for synchronization, meaning i can be "on the go", add a password, and synchronize it to a local git service on my LAN when i get back home, or in case i need it on another platform _now_, i can connect through VPN and synchronize.

Re: 1Password Secrets Automation

#162

I purchased my first 1Password license when it was version 3, and have faithfully upgraded to every standalone version ever since. These days I’m not so sure I will be upgrading again (and I’m not sure there will be more stand alone versions). The latest version is a mess on Big Sur, with unlock fields obscuring input fields, conflicting with Apples iCloud Keychain, and just not working like I expect it to. Furthermo…

I don't understand why people think it's some nefarious dark pattern. It's perfectly clear, the old 1Password app is winding down, the future is their hosted version. The only way to even download the app is if you already knew about it's existence before. It's not a dark pattern, it's just directing people who sign up for 1Password today into their actually supported product instead of the end-of-lifed one. Your app…

I still think it's pretty terrible that they previously sold a lifetime license which no longer applies to the latest versions.

Re: 1Password Secrets Automation

#163
post #2

This looks interesting. We use 1Password, and I always thought it would be useful to programmatically pull values out and use in our cloud infrastructure. Currently we end up using the secret managers available in AWS or GCP, which seems pretty half baked. In GCP, for example, secrets are stored at a project level. It's not unusual to have certain secrets that are needed by more than one project, which means they get…

> The granularity also prevents me from controlling which secrets are visible to a given user. What do you mean by this? Each secret has a "Permissions" tab which allows you to grant access to individual IAM users.

You're correct. Not sure if I overlooked it or at some iteration of usage it wasn't there.

Re: 1Password Secrets Automation

#165
post #48

Earlier quoted context omitted.

> I specifically want my non-technical family and friends to use password managers I consider it a victory if I can get non-techies to use their browser's facilities to store passwords, and then to choose reasonably long passwords and avoid reuse. (I use `pass`, myself.)

I use a password manager but, as a mostly-Apple user, I see very little reason not to just use iCloud Keychain: the UX of Apple’s solution is significantly better than all the alternatives because I don’t have to remember yet another password/mfa token to type in every once in a while.

iCloud Keychain is ‘good enough’ if you are 100% in the Apple ecosystem, but there’s a lot it could do better, including password sharing as well as password export. Most glaringly there’s no support for storing additional meta data alongside the password; eg all the made up answers to “what was the street you grew up on?”, etc

Re: 1Password Secrets Automation

#167
post #109

Earlier quoted context omitted.

I wouldn't say the product is a dumpster fire, but core workflows are a mess. This is how you generate and save a password for a new site: 1) Extension button > Generate Password > Save & Copy 2) After creating account, extension button again > select entry > Edit 3) Click Save in opened modal 4) Click Convert to Login in opened modal 5) Click Edit in opened modal 6) Manually type in the username/email you used on th…

Yes, this convert to login only after the item being saved makes little sense. It took a few times of catching the button being shown to figure out the pattern of clicks needed to do this fundamental aspect of what the product is intended to do.

There are a few threads related to saving, and I wasn't sure which to jump in to, but I wanted to share a few of the ways we've tried to make saving better in the newer extension.

First of all, we have a new "Generator History" section, which contains passwords created by the generator. These are always available if you need them, but don't show up alongside other items, so are less important to clean up.

We've also been working on a brand new saving experience which is currently in beta. If we miss a field from the page, you can add it before you save. You can also add tags, and when updating items, see a side by side diff of the changes. There's a screenshot here if you're curious: https://twitter.com/oliverdunk_/status/1382302050369875969?s...

It sounds like you have a subscription so if you haven't already, I'd encourage you to give the new extension a try. I totally understand that native app integration might be a requirement for you there, and I'm sorry that it felt like you were getting mixed messaging. Really both things are true - we don't have a timeline for this, since it's a big bit of work and we want to get it right. Support are absolutely correct too though - we're actively working on this, and the integration with 1Password for Linux's beta is the first step, with support for other operating systems very much on our mind.

- Oliver, 1Password

Re: 1Password Secrets Automation

#168

Earlier quoted context omitted.

Hello! > - Why does the integration require two servers with exposed ports? The REST API documentation doesn't say which service I need to connect to for the resources, so I assume the answer is the API server, so what does the other server listen for? The server you'd interact with is the API server. The other server is responsible for syncing. The fact that there are two was a design decision. > - How do I request…

Thanks for the reply! You didn't quite completely answer my first question. Why does the "sync" server have an exposed port? I'm going based on the docker-compose.yml you provide.

That is a documentation clarification that should be made. That exposed port in the docker-compose is only there so someone running a health check from the host could see it. The docker-compose should be updated to remove the port exposure. Thanks for bringing that up!

Re: 1Password Secrets Automation

#169
post #23

Hah. With the gimmicks, tricks, and dark patterns this company has pulled with consumer, what are the chances professionals would trust them with something like this?

This is getting a lot of downvotes, but I agree with it to a certain degree. Have a look through the Agile Bits support forums and you'll find all the dark patterns you want - the most famous being their hiding of buy outright options to push you to subscription, and the crippling of Dropbox sync to try to push you to their proprietary sync service. I've used 1Password for well over a decade, but a lot of their tacti…

Yup. After using 1Password since 2014, I'm now in the very painful process of migrating to LastPassXC and syncing locally with my NAS. The way they push you to use the cloud was incredibly souring. They lost a happy customer.

Re: 1Password Secrets Automation

#170

Earlier quoted context omitted.

What are your criticisms of Google secrets manager? It works well for me, but it's the only one I've used so I don't know much about the competition.

By far the biggest missing control is you can't restrict access to google secrets manager by source CIDR. There were a bunch of other smaller nitpicks, but that was the overwhelming reason last time I looked at it.

IAM policies are designed for this reason, not IP based access controls.

E.g. in AWS you can specify the source CIDR range in an IAM policy.

Post reply on HN