Live data from Hacker News

1Password for Linux

blog.1password.com

221–230 of 282 posts

Re: 1Password for Linux

#221
post #95

Earlier quoted context omitted.

No, but in all seriousness, I emphatically DO NOT UNDERSTAND the extent to which people place trust in external services to manage passwords. While I appreciate that they do have good skin in the game by being paid, etc -- your password storage on SOMEONE ELSE'S MACHINE fundamentally creates another huge attack vector/opportunity to screw it up, when they also must be accessed locally somehow. I appreciate it if you'…

Here's the mistake I made that made me decide to switch to 1password https://news.ycombinator.com/item?id=26801155 Also, depending on your phone, it might be significantly more secure against non-superpower actors.

Fair, but I just have them backed up to a non-encrypted USB key, offline.

Re: 1Password for Linux

#223
post #95

Earlier quoted context omitted.

No, but in all seriousness, I emphatically DO NOT UNDERSTAND the extent to which people place trust in external services to manage passwords. While I appreciate that they do have good skin in the game by being paid, etc -- your password storage on SOMEONE ELSE'S MACHINE fundamentally creates another huge attack vector/opportunity to screw it up, when they also must be accessed locally somehow. I appreciate it if you'…

What’s the harm on storing your passwords on someone else’s machine, as long as they’re encrypted with a good password?

I suppose I mean "service" more than "machine," i.e. any system in which the owner of the other machine has a shot at getting at your stuff. I know "zero-knowledge" is possible, but, again -- why risk it?

Re: 1Password for Linux

#224
post #202
post #95

Earlier quoted context omitted.

No, but in all seriousness, I emphatically DO NOT UNDERSTAND the extent to which people place trust in external services to manage passwords. While I appreciate that they do have good skin in the game by being paid, etc -- your password storage on SOMEONE ELSE'S MACHINE fundamentally creates another huge attack vector/opportunity to screw it up, when they also must be accessed locally somehow. I appreciate it if you'…

> * I emphatically DO NOT UNDERSTAND the extent to which people place trust in external services to manage passwords.* I'm generally fine with this if the password vault is end-to-end encrypted, the vault's password is never shared with the server, and the server doesn't have access to the plaintext passwords at all. At that point you have to trust that the crypto used for the vault is done correctly (and that trust…

Define sync? I still far more trust "my own encrypted volume" plus "home-rolled synchronization (Syncthing, in my case)" than e.g. a Bitwarden.

(also, I have no idea exactly what "end-to-end encrypted" actually means these days, given the loose way many apps/services seem to define it.)

Re: 1Password for Linux

#225
post #95

Earlier quoted context omitted.

No, but in all seriousness, I emphatically DO NOT UNDERSTAND the extent to which people place trust in external services to manage passwords. While I appreciate that they do have good skin in the game by being paid, etc -- your password storage on SOMEONE ELSE'S MACHINE fundamentally creates another huge attack vector/opportunity to screw it up, when they also must be accessed locally somehow. I appreciate it if you'…

Since most passwords can be reset via email, you're placing a similar level of trust in your email provider (and if you host your own, in your domain provider). At some point the paranoia isn't productive anymore.

My threat model isn't super high profile, so no?

Partly given 2FA, but more importantly the fact that I check my email pretty frequently (most of them will be like "hey, someone's trying to change your password, is it you?), I don't think that's a fair comparison.

Re: 1Password for Linux

#226

Earlier quoted context omitted.

We continue to sell licenses for each 1Password 7 for Mac and 1Password 7 for Windows. These licenses are available within the app when downloaded from our website. We would strongly recommend 1Password membership as that is going to provide the best experience, but if you’d prefer a license for one or both of those products they are for sale. We recommend memberships as they address a number of requests our customer…

As a standalone license customer for almost 10 years now, the constant responses like this and the deliberate non-answers on the forums really make me wonder how long I will continue to use 1password. I love 1password but I will not put my passwords in someone else's cloud. It's honestly pretty insulting that every time this comes up, someone from 1password pops in to talk down to your customers and push subscription…

Indeed. Stuff like this:

> We would strongly recommend 1Password membership as that is going to provide the best experience

is maddening. Do you guys really think we all just don't know what is going to provide the best experience? Because what will provide me the best experience is keeping it simple, not taking on an online dependency, and keep putting out standalone updates and platform ports, which I'd gladly pay for.

The condescension, evasiveness and dishonesty is just sad.

Re: 1Password for Linux

#227
post #180

Earlier quoted context omitted.

I think you might have a misunderstanding of how our browser extension works. Just like our desktop app, your password is only in memory if you copy it to the clipboard, fill it in the browser, or reveal it within the app. Your passwords are always stored encrypted on both the desktop app and browser extension, and we make an active effort to keep secrets out of memory. I hope this clarifies things. - Jackson Lewis,…

Turns out that yes, I thought that the vaults were encrypted as a whole, but according to the security white paper that changed at some point. So you can decrypt individual passwords.

Thanks for taking the time to check out the white paper!

- Ben, 1Password

Re: 1Password for Linux

#228
post #220

This is great. Is there any hope of having the possibility to export entries? Looks like it's missing compared to Windows and Mac.

Yup! Since the very beginning in 2006 Roustem and I wanted to make sure everyone used 1Password because they enjoyed doing so and not because of being locked in. File > Export is your friend. ++dave; 1Password Founder

Thanks, I use Ubuntu so I missed that there was a menu bar. It's hidden unless I hit "Alt".

Re: 1Password for Linux

#229
post #221

Earlier quoted context omitted.

Here's the mistake I made that made me decide to switch to 1password https://news.ycombinator.com/item?id=26801155 Also, depending on your phone, it might be significantly more secure against non-superpower actors.

Fair, but I just have them backed up to a non-encrypted USB key, offline.

If it works for you, that's good. It's less the specific issue and more it indicated to me I was rolling my own crypto and didn't know enough to avoid shooting my feet off.

Re: 1Password for Linux

#230

1Password looks cool and all, but I'm left wondering how it all works. Specifically their pricing[0]. So what happens if I just refuse to pay them when my subscription is up and I need another year/month/whatever? Do all my secrets & passwords become inaccessible? Because if I couldn't access my passes by merely not paying up, that's plain extortion. I didn't read their terms, hopefully someone here can enlighten me.…

The apps become read only. I don't know if you can access the web version.

You would also still have read-only access through the web app. :)

- Ben, 1Password

Post reply on HN