Live data from Hacker News

1password is considering a self-hosted option to store vaults

1password.community

101–110 of 228 posts

Re: 1password is considering a self-hosted option to store vaults

#101
post #99

I've never understood why anyone who takes security seriously would even consider a non-self-hosted (and non-open-source) password manager, especially after the recent Apple shenanigans. If it's not open-source and self-hosted then your security is entirely dependent on the good will of your provider. If they decide to screw you, they can. And it's not just the good will of the people running your provider today that…

Convenience.

A self-hosted password manager really shouldn't be exposed to the internet. If you are making it accessible over the internet, it's a far greater security threat imo. You're just not going to be able to keep it up to the same security standards as a large production install, like what the Bitwarden folks have going.

Needing to VPN or SSH tunnel into my home network each time I need a password is far too inconvenient.

Not to mention the spared effort in not needing to regularly back up your vault or worrying about keeping the service available.

Re: 1password is considering a self-hosted option to store vaults

#102

Earlier quoted context omitted.

> Is there any password management application out there that makes sharing passwords or password vaults easy but is also free? For members of a relatively well-paid profession earning good wages from creating software, I wonder if the reluctance to support others earning money for quality work isn’t some form of cognitive dissonance. // Pre-emptive “edit” before this comment has replies: Folks post a lot of argument…

For me it’s the feature tiering and price discrimination that turns me off. I end up paying too much (total cost over 5 years) for too little. If you look at the business pricing it’s even dumber. The $2 billion valuation of 1password tells the entire story. They’re overcharging for what they’re providing and I think tech people can “feel” that which is why tech communities hate the subscription BS.

I don’t really think $8/user/mo for Business is overcharging compared to Slack which quickly gets into $30+ per user per month in larger shops where Enterprise Grid is required for its features.

By your argument why can’t I buy that and self-host it too, decide if I want to upgrade for more features myself?

I also think $5/mo for 1Password for Families is incredible value. Zero regrets on paying for this because it meaningfully enhances my families personal security posture through elimination of reused credentials and enabling TOTP (sharing of code generation) on many sites we use, that it is cross-platform so no excuses for everyone to not use it, and the UX is so simple you don’t need to be “tech people” to succeed.

How much you charge and how you charge is definitely divisive, but 1Password feels very much on the cheaper end of the spectrum, not “overcharging”, heck Discord Nitro is $5 (Classic) or $10 and gets you very little by comparison IMO.

Re: 1password is considering a self-hosted option to store vaults

#103
post #58

I've been self hosting 1Password for about a decade without any issues. There's always been a way around the subscription stuff. I honestly don't mind paying the subscription pricing, just didn't like the idea of storing my passwords on their service with everyone else's.

You don’t like the idea of storing opaque bits along with everyone else’s equally opaque bits? So long as the secret key to these bits is yours, not theirs, what’s the catch?

For a whole class of potential (if unlikely) situations, it shifts from me potentially being caught up in a mass hack, response to an overly broad warrant, etc to needing be targeted specifically.

Passphrase compromised? If they're hosting, you know exactly where to go to access my passwords. If I'm hosting, I can tell you that I use 1Password and my master password and I'm still _relatively_ safe in that you don't even know where to find a copy of my password database.

Encryption broken (whether algorithm or implementation)? If they're hosting, they've now become an _extremely_ valuable target as they're holding a bunch of paid-for accounts, credit cards, banking details, personal identity documents, etc. Not necessarily super-valuable in a one-off situation, but if you could grab a million password databases at once... Which wouldn't include mine, because it's off on my own server.

Legal abuse? An overly broad warrant could vacuum up every database in their possession. Presumably the government can't open the vaults, but if they _really_ cared how sure are you? Would you be comfortable not changing all of your passwords (but can't change your identity documents...) if the NSA asked for a copy of your database? If my data's never in their possession, then I'd need to be targeted specifically with a warrant.

For something I'm using to store all of my accounts, banking details (both logins as well as account and routing numbers), personal identity documents, MFA backups, key backups, software licenses, and more... my question for you would be more "Why would I take any additional risk when I don't have to?" I'd rather not be within the same blast radius as all the other 1Password users.

Edited to add: Also, outside of the "why don't I want my data sitting beside everyone else's", more generally with regards to a hosted option is where my data goes if I have any payment problems, and availability of my data being within my control (if my server goes down, I can fix it--if they have a massive week long outage I just need to twiddle my thumbs potentially without access to... anything).

Re: 1password is considering a self-hosted option to store vaults

#104
post #37

Earlier quoted context omitted.

I had the exact same experience. I don’t want to care about the app UI etc but when you use a password manager as often as you do it really matters. Not to mention selling the idea to less tech-savvy family members, it really does have to be as simple as can be.

I self-host Bitwarden_rs and use the client apps on Windows, Linux, and MacOS. To me, the UI seems very usable, polished and attractive. It doesn’t seem that different from 1Password, which I switched from a few years ago. What exactly about the UI needs improvement?

I'm a 1Password user right now, but I've tried self-hosting Bitwarden_rs and like it very much.

The one killer feature which is preventing me from switching is the ability to use multiple self-hosted servers at once (so I can separate family vaults from business) [1], but "client profiles" are likely to be implemented some time soon [2].

Now that I've learnt that local vaults are going away in 1Password 8 [3], I'll probably make a move to Bitwarden sooner rather than later.

[1] https://community.bitwarden.com/t/log-in-with-multiple-bitwa...

[2] https://community.bitwarden.com/uploads/default/original/2X/...

[3] https://news.ycombinator.com/item?id=28107225

Re: 1password is considering a self-hosted option to store vaults

#105
post #101
post #99

I've never understood why anyone who takes security seriously would even consider a non-self-hosted (and non-open-source) password manager, especially after the recent Apple shenanigans. If it's not open-source and self-hosted then your security is entirely dependent on the good will of your provider. If they decide to screw you, they can. And it's not just the good will of the people running your provider today that…

Convenience. A self-hosted password manager really shouldn't be exposed to the internet. If you are making it accessible over the internet, it's a far greater security threat imo. You're just not going to be able to keep it up to the same security standards as a large production install, like what the Bitwarden folks have going. Needing to VPN or SSH tunnel into my home network each time I need a password is far too…

If it's properly encrypted you should be able to publish it on github and still be more secure than entrusting it to a third party.

Re: 1password is considering a self-hosted option to store vaults

#106
post #13

They made the standalone license almost impossible to find and get, forced a subscription on users, and made the password vault storage online for the subscriptions. Now this self-hosting survey comes as a surprise, and it would be of some relief if/when it’s implemented. I do wonder how the licensing and pricing will be handled though. Bitwarden officially allows self-hosting for the personal use tiers, but it seems…

> Is there any password management application out there that makes sharing passwords or password vaults easy but is also free? For members of a relatively well-paid profession earning good wages from creating software, I wonder if the reluctance to support others earning money for quality work isn’t some form of cognitive dissonance. // Pre-emptive “edit” before this comment has replies: Folks post a lot of argument…

Nope. "Password Storage" should not be a business that exists in the form of "if you don't pay for good password storage, you're not allowed to have it." Especially if it involves storing your password with a third party.

The technology to store passwords safely has a marginal cost of zero (it's software). People storing passwords in third party places increases the threat surface, always. Finally, it's "ecological" in that safety/security of this sort needs to be evenly distributed to work its best.

I'm not saying we shouldn't pay people to make things safer, we absolutely should. But this is a bad model for it.

Re: 1password is considering a self-hosted option to store vaults

#107
post #62

Earlier quoted context omitted.

I'm paying for a Bitwarden subscription because I want to support their product and their vision. But I don't know, time passes and some much needed improvements don't seem to arrive. The most glaring issue (for me, anyway; I fully understand I'm just a sample size of 1!) they have is relying on the pop-up UI of the browser, which I guess is stateless (state is lost when the popup closes, it seems?). The decision of…

I use Bitwarden in the Firefox sidebar. That provides a persistent state experience.

Which also doesn't work when using a private window.

Re: 1password is considering a self-hosted option to store vaults

#108
post #105
post #101

Earlier quoted context omitted.

Convenience. A self-hosted password manager really shouldn't be exposed to the internet. If you are making it accessible over the internet, it's a far greater security threat imo. You're just not going to be able to keep it up to the same security standards as a large production install, like what the Bitwarden folks have going. Needing to VPN or SSH tunnel into my home network each time I need a password is far too…

If it's properly encrypted you should be able to publish it on github and still be more secure than entrusting it to a third party.

Publishing your vault of passwords on a public GitHub repository seems like a pretty bad idea, no matter how well you trust the client-side encryption code.

I'm no expert on the subject, but I suspect these password managers use a sophisticated mechanism of authentication (for accessing the vault) as well as encrypting of the actual contents of the vault.

The effect of this means that Bob's encrypted vault cannot be downloaded by an attacker without the attacker first authenticating to the server.

Re: 1password is considering a self-hosted option to store vaults

#110
post #101
post #99

I've never understood why anyone who takes security seriously would even consider a non-self-hosted (and non-open-source) password manager, especially after the recent Apple shenanigans. If it's not open-source and self-hosted then your security is entirely dependent on the good will of your provider. If they decide to screw you, they can. And it's not just the good will of the people running your provider today that…

Convenience. A self-hosted password manager really shouldn't be exposed to the internet. If you are making it accessible over the internet, it's a far greater security threat imo. You're just not going to be able to keep it up to the same security standards as a large production install, like what the Bitwarden folks have going. Needing to VPN or SSH tunnel into my home network each time I need a password is far too…

That is why the local vault option was the best in my mind, and then using DropBox/Resilio/etc to sync. It is very unfortunate that they are no longer supporting local vaults in the next version.
Post reply on HN