Live data from Hacker News

1Password for Linux

blog.1password.com

171–180 of 282 posts

Re: 1Password for Linux

#171
post #76

Earlier quoted context omitted.

Bitwarden is awesome. It's my current password manager after I left 1P. I spent hundreds into 1P before the subscription model, as their apps were expensive and got them on multiple OS and for family members. Then Dropbox decided (rightfully) that you shouldn't use your public folder to host websites, and 1P told their customers to either get a subscription or lose the online vault which is a critical feature of any…

Like OP, I’ve used 1P since the early 2010s. Its approachability (and the fact that I pay for it) finally convinced my family (SO/siblings/parents) to use a password manager. I love the native experience on iOS, and the full desktop version + browser extensions I remember being frustrated by the Dropbox loss, and I’m still frustrated that they seem to push 1PasswordX over the native apps. Other than that I’ve only ha…

> I’m still frustrated that they seem to push 1PasswordX over the native apps

This is one of the things that pushed me to choose bitwarden over a 1password families subscription (even though I get the latter for free from my work).

I don't like the idea of credentials living in a browser extension (or even in a browser). I'm not confident in the long-term security of the entire setup, especially with the "evergreen" nature of modern browsers. I don't like telling my less-technical family that this extension is okay, but absolutely don't trust any other extensions.

Re: 1Password for Linux

#172
post #68

Earlier quoted context omitted.

Personally I prefer building GUIs in a scripting language like JavaScript over a compiled language like C and C++, GUIs changes a lot and needs to be tweaked in another way than system code does, so it is understandable to pick Electron, even though I loath the result. The Qt approach with QML + JavaScript with a C++ backend worked in that regard quite well, expose low level system calls from C++ and call it from Jav…

Yeah, I think I completely agree with this. Nominally GTK (and I think Qt?) is designed with scripting language support in mind. They export a bunch of XML that can be used to generate bindings in other languages, but said XML is miserably documented and in practice it's basically impossible to leverage it (I recall various attempts at generating Go bindings and all ended in failure--it became apparent that it was ea…

I guess there are two different kinds of bindings.

1) Scripting language is still the driver of the application, it uses "bindings" against a GUI library to implement the application. This is the one I'm most interested in. And if you need low level stuff, you implement that as dll/so library and uses that from you scripting language.

What usually happens is that you need to read the GUI library C or C++ code and examples to understand it, because the bindings documentation is not enough, and then translate that to your scripting language, can become a bit tedious with trial and error if it not obvious how to do it.

XML as descriptive source sounds good in theory, that is why I'm somewhat intrigued by how Microsoft has done it the past with COM and now how they have expanded that with WinRT where you can implement language projections that can handle cross language types (projected types?) so you can get a natural interface in the language you are working in. But I'm not a .NET developer.

I think I looked at Go-Qt binding but if I remember correctly it was alpha and had problems. Python-Qt exist but I don't know much about it. Read somewhere that I was just easier to use C++ directly, less hassle, don't know if that is true.

Vala looks like a nice solution if you want to go full GTK. Problem with GTK is that it is not truly cross platform, Gnome team does not prioritize other platforms as Qt does. And GTK breaks existing functionality too, even between minor versions (still true?).

That is why I started too look at IUP, IUP uses GTK on Linux, but win32 on Windows. Tried to do a C++20 project with IUP, but gave up, even with all the new fancy stuff for C++ it is still awful, better yes, but same old problems are mostly there. When you are writing a GUI code you don't really care if your string is a const ref or pointer or what not, you spend the time on all the wrong things and C++ invites to think and micro optimize all those decisions(use or not use auto in for loop? how to write to best constructor? Optimal initializer?). Then before you know it you binge watch C++ talks with Nicolai Josuttis and have difficult sleeping at night. And if you go heavy into smart pointers, why not just use a GC:ed language to begin with? Qt solves that well with QString, QList etct, doesn't matter if pass by value or not, but then you need to handle qmake. I'm tired of awful build systems, they are everywhere, still scarred for life by cmake and when I tried CLion. Now I do things over FFI instead, sleeps much better.

2) Scripting language has "bindings" to a GUI application/framework, more of a plugin system. Gnome is a good example there, but as you say, different JavaScript engines between these "bindings", and for Gnome, poorly documented.

I think for Gnome and other desktops that uses this technique, it is in the right direction, but the quality of the plugins I have used is most of the time poor, memory leaks etc, you end up using just use the approved ones if you don't like to restart your desktop once a day. If that is because of poor bindings or poor plugin implementations I don't know.

Re: 1Password for Linux

#173
post #76
post #41

Earlier quoted context omitted.

Bitwarden https://bitwarden.com/ Has clients for all platforms, open source, self hosting or free plans and saas. Waited long time for 1password for linux and switched last year to bitwarden. Family Account for 6 Users ($40 per year)

Bitwarden is awesome. It's my current password manager after I left 1P. I spent hundreds into 1P before the subscription model, as their apps were expensive and got them on multiple OS and for family members. Then Dropbox decided (rightfully) that you shouldn't use your public folder to host websites, and 1P told their customers to either get a subscription or lose the online vault which is a critical feature of any…

It's slightly shocking how angry people get about companies going from one-time purchase to subscription. Like many software companies, 1Password made a business decision to focus on a subscription product. This strikes me as reasonable and naturally aligned with the customer expectation that this software be supported in perpetuity as OSes and browsers evolve over time. $5/month is not a crazy price to pay for a critical piece of software you use every day—to the contrary I kind of feel like it's the minimum price for a consumer software product to be sustainable. I don't want my password manager to be cutting corners because they can't afford to invest properly in the product.

As far as deprecating the bring-your-own-sync approach, I understand this is legit flexibility that some customers want, and I'm glad there is a competitor that does a good job of it. Personally though, after many years of using 1Password + Dropbox, I must say I've had a lot fewer sync problems since migrating over to 1Password for Families. If I had a broad sync strategy maybe I would feel otherwise, but I don't—to the contrary, I'm moving away from Dropbox because of the shenanigans they are pulling with my OS internals, and maintaining a VPS or even an AWS account with S3 is a significant burden that I don't take lightly. As a product engineer, a single integrated sync is easier to provide guarantees, and prevents a lot of problems caused by third parties with no recourse to debug.

Re: 1Password for Linux

#174
post #101

PSA: Note that AgileBits intentionally hides the standalone license option and pushes subscription as the only visible scheme to get the application. This is a long standing dark pattern, and though the support staff will admit on their forums or here that the standalone license does exist, you wouldn't be able to find it without some special incantations on the forums. They will keep reiterating that it's for your o…

I started using 1Password a long time ago (~10 years) when the only option was the standalone license option. It is a lifetime license for about the cost of ~2 years of subscription. They still sell and "support" this standalone product. But I use the word "support" in quotes because the standalone license doesn't offer all the features of the subscription product. I resisted switching to the subscription product for…

Lifetime licenses rarely last a lifetime. Most products will run out of support long before you run out of life. You'd be lucky if the company even existed after 10 years.

Before subscription software became all the rage, you had to purchase a license for a specific version. You had the right to keep using the version you purchased for as long as it worked, but if you wanted any new features, you had to shell out money again for a new version every few years. Maybe you'd get free bugfixes from time to time, but that was about it.

Now we're all spoiled by the rolling updates funded by the subscription model. We keep asking for the old pricing model, and at the same time want all the new features to be backported perpetually. :)

Re: 1Password for Linux

#175
post #83

Earlier quoted context omitted.

Yup! In many ways Linux is leading the charge. Not just with these features but also for development as a whole. Here's the background story on how 1Password for Linux started and how it was built: https://dteare.medium.com/behind-the-scenes-of-1password-for... ++dave; 1Password Founder

What happened to accessibility on 1P for Mac? It's completely invisible to VoiceOver now.

Hey disgrunt. We have a number of VoiceOver users on Mac, so something doesn't sound quite right (no pun intended). Please reach out to our support team at support+mac@1password.com and we'll be happy to help.

- Ben, 1Password

Re: 1Password for Linux

#176

Earlier quoted context omitted.

Sidenote: 1password has no way of knowing if I am materially affected by a site breach, and its notifications about a site being breached annoy me

The functional uselessness of ALL site breach notifications from EVERYONE who will send them to you is something that pisses me off to no end. "Your Email was found in the data dump from the FooBarBaz.NET hack!" Okay, which site was this? Is there a password I'm supposed to change? Was it actually a password I stopped using 5 years ago, but is still floating out there somewhere? None of these questions are ever answe…

> Okay, which site was this?

The site it said it was?

> Is there a password I'm supposed to change?

Do you have a password saved or memorized? Does the site have a link or form to log in?

> Was it actually a password I stopped using 5 years ago, but is still floating out there somewhere?

They can't be sure. Why not change it to be safe?

Re: 1Password for Linux

#177
post #138
post #105

Earlier quoted context omitted.

Use the "classic" extension, it already does this. And has the added bonus of not putting ALL of your passwords into your browser memory.

Did the classic extension work on Linux? When I switched from MacOS having to use the (terrible) 1PasswordX was one of the things that really annoyed me.

Sorry, ignore me I was wrong

Re: 1Password for Linux

#178
post #107

Earlier quoted context omitted.

gopass [1] is a 100% compatible pass implementation that has some collaboration features added. However, I primarily use it for the `gopass search` output. This is where `pass` really sucks for those who copy-paste. [1] https://github.com/gopasspw/gopass

find ~/.password-store -name '*.gpg' -printf '%P\n' | sed -e 's:.gpg$::gi' | fzf | xargs pass -c There is also an extension: https://github.com/ficoos/pass-fzf

Good point, but `pacman -S gopass` is wa-a-ay easier ;-)

Re: 1Password for Linux

#179
post #95
post #27

I just use pass: https://www.passwordstore.org/

No, but in all seriousness, I emphatically DO NOT UNDERSTAND the extent to which people place trust in external services to manage passwords. While I appreciate that they do have good skin in the game by being paid, etc -- your password storage on SOMEONE ELSE'S MACHINE fundamentally creates another huge attack vector/opportunity to screw it up, when they also must be accessed locally somehow. I appreciate it if you'…

What’s the harm on storing your passwords on someone else’s machine, as long as they’re encrypted with a good password?

Re: 1Password for Linux

#180
post #102

Earlier quoted context omitted.

Just a warning for people who don't know the grandparent is referring to the extension formerly called 1Password X (now just 1Password in the browser because AgileBits wants you to use that one) which puts ALL OF YOUR PASSWORDS into your browser's memory. The "classic" 1Password browser extension already unlocked with the desktop app and does not dump your entire vault into browser memory just to fill one password.

I think you might have a misunderstanding of how our browser extension works. Just like our desktop app, your password is only in memory if you copy it to the clipboard, fill it in the browser, or reveal it within the app. Your passwords are always stored encrypted on both the desktop app and browser extension, and we make an active effort to keep secrets out of memory. I hope this clarifies things. - Jackson Lewis,…

Turns out that yes, I thought that the vaults were encrypted as a whole, but according to the security white paper that changed at some point. So you can decrypt individual passwords.
Post reply on HN