Live data from Hacker News

1password is considering a self-hosted option to store vaults

1password.community

131–140 of 228 posts

Re: 1password is considering a self-hosted option to store vaults

#131
post #124
post #99

I've never understood why anyone who takes security seriously would even consider a non-self-hosted (and non-open-source) password manager, especially after the recent Apple shenanigans. If it's not open-source and self-hosted then your security is entirely dependent on the good will of your provider. If they decide to screw you, they can. And it's not just the good will of the people running your provider today that…

if it's not open-source and self-hosted then your security is entirely dependent on the good will of your provider. It's because neither of these conditions are really true - you'd have to assume that source code is only way to assess the security of software and that end-to-end encryption doesn't actually work.

That depends on what you mean by "end-to-end encryption doesn't actually work". Of course E2EE works in principle. The problem is: how can I know that the code I am running is in fact a properly implemented E2EE system if I don't trust the vendor and I can't audit the code?

Re: 1password is considering a self-hosted option to store vaults

#133
post #58

I've been self hosting 1Password for about a decade without any issues. There's always been a way around the subscription stuff. I honestly don't mind paying the subscription pricing, just didn't like the idea of storing my passwords on their service with everyone else's.

You don’t like the idea of storing opaque bits along with everyone else’s equally opaque bits? So long as the secret key to these bits is yours, not theirs, what’s the catch?

Defense in depth is a legitimate aspect of security. Would you rather keep your money in an unbreakable box on the sidewalk, in an unbreakable box in a stranger's shed three towns over, or in an unbreakable box bolted to the floor of your cellar with your dog sleeping by the stairs?

Re: 1password is considering a self-hosted option to store vaults

#134

Semi-related: this survey was announced alongside 1Password 8 for Windows early access. Apparently 1Password 8 for Windows uses Electron and there was some discussion about AgileBits wanting to move to the same architecture on all platforms. Does anyone know if 1Password 8 on macOS will also be an Electron app? Their Linux Electron app is pretty good and definitely much better than having no 1Password at all. However…

Good lord, it's like they're trying to ruin it.

Re: 1password is considering a self-hosted option to store vaults

#136
post #13

They made the standalone license almost impossible to find and get, forced a subscription on users, and made the password vault storage online for the subscriptions. Now this self-hosting survey comes as a surprise, and it would be of some relief if/when it’s implemented. I do wonder how the licensing and pricing will be handled though. Bitwarden officially allows self-hosting for the personal use tiers, but it seems…

> Is there any password management application out there that makes sharing passwords or password vaults easy but is also free? For members of a relatively well-paid profession earning good wages from creating software, I wonder if the reluctance to support others earning money for quality work isn’t some form of cognitive dissonance. // Pre-emptive “edit” before this comment has replies: Folks post a lot of argument…

> Not to mention the exercise of ethnocentric privilege implicit in demanding something of quality in exchange for nothing assured.

Whoa! Knowing nothing about the OP you assume that he is the member of the oppressing class clamoring for the output of his slaves? And, since you're writing this in English, I think it's safe to guess you're assuming the person you're attacking is a white, so you're basically accusing this guy of being an entitled white who can't give up his slave labor

I was with you on the rest of the post but charges of "ethnocentric privilege" are a weird, racist escalation hiding in academic terminology there bud

Occam's Razor applies here: everybody likes free shit. This isn't a property unique to the evil whites

Re: 1password is considering a self-hosted option to store vaults

#137
post #13

They made the standalone license almost impossible to find and get, forced a subscription on users, and made the password vault storage online for the subscriptions. Now this self-hosting survey comes as a surprise, and it would be of some relief if/when it’s implemented. I do wonder how the licensing and pricing will be handled though. Bitwarden officially allows self-hosting for the personal use tiers, but it seems…

> Is there any password management application out there that makes sharing passwords or password vaults easy but is also free? For members of a relatively well-paid profession earning good wages from creating software, I wonder if the reluctance to support others earning money for quality work isn’t some form of cognitive dissonance. // Pre-emptive “edit” before this comment has replies: Folks post a lot of argument…

I'm surprised by these sweeping assumptions of what the HN audience is.

> relatively well-paid profession earning good wages from creating software

AFAIK 1password doesn't practice location-based pricing, so how can you assume that "relatively well paid" people from different geographies of the world can all find it affordable?

Re: 1password is considering a self-hosted option to store vaults

#138

Earlier quoted context omitted.

> Is there any password management application out there that makes sharing passwords or password vaults easy but is also free? For members of a relatively well-paid profession earning good wages from creating software, I wonder if the reluctance to support others earning money for quality work isn’t some form of cognitive dissonance. // Pre-emptive “edit” before this comment has replies: Folks post a lot of argument…

I agree to the payment. I disagree to the subscription model. I absolutely would try to hook users on any SaaS. However, I go out of my way to avoid such products. If I can pay for them once, I much prefer it. (For something like jetbrains, I'm okay with a renewal fee because if I choose not to pay it, I can still use the older version.) I make an exception for Bitwarden because I like the idea of my password manager…

> For something like jetbrains, I'm okay with a renewal fee because if I choose not to pay it, I can still use the older version.

110% agreement.

Further, the only thing I like less than subscriptions is IAP not of new feature sets but ‘pay-to-play’ where the mechanics of use are negatively distorted to gamify purchase impulse.

I’ve argued — here, since inception of IAP on Apple’s app store — that the worst thing Apple has done to consumers was normalize removing the ability to show only single purchase paid apps in the app store. An vast class of less fortunate consumers either resign to less utility or waste time on an artificial “grind”, to encourage another class of “whale” to drive corporate revenues.

I don’t mind extracting cash from whales who can afford it. I do have a problem inflicting artificial digital scarcity of utility or enjoyment on the masses to create the ‘hook’ for whales.

As for subscriptions, it’s not clear to me that the treadmill of software/hardware upgrades is benefiting core use cases.

I like paying for generational or disruptive change, “voting with my wallet” on what’s of worth to me, but after a couple decades of purchasing generations of Adobe software only when the features mattered to my work, I moved from Adobe to e.g. Affinity and feature sets I own instead of rent when these recurring subscriptions don’t appear to meaningfully benefit my productivity or output.

For instance, it’s remarkable to me how similar the principles are between today’s (re-)emergence of Markdown for document composition and the early WordStar / WordPerfect / AppleWriter tools of the 80’s. I also like the experimentation by these Makers in ability to purchase a ‘pinned’ feature set, or support ongoing refinement. (Editors whether text or code, like JetBrains mentioned, seem to have a jump on this clever — and rare positive — use of IAP.) It’s difficult to show what increased utility of word processing has come from the most recent 20 years of paying for word processing upgrades. Today’s dev efforts suggest the sweet spot may be 30 years back.

The flip side of this, economic models are still dissatisfying for affordability of basic bricks and mortar world rights such as housing. The least worst answer appears to be rent (with a dystopian jag into ad-supported!), and it may be the least worst for software is rent as well.

Except when the ongoing annual software rents have risen to the same cost as one-time purchase (again, Adobe!), contrary to bricks and mortar where the over under is often 7 years of possession and use.

Back to artificial digital scarcity — I’m concerned that advertiser funded access to quality writing is losing ground to monthly subscriptions for content. Are less fortunate kids going to be able to subscribe to NY Times, WaPo, Atlantic, Guardian, National Review, American Spectator, and so on, for $5 a month each? (News aggregations such as Next Issue could resolve this, but even as Apple’s “News+” this struggles.) Even more dissatisfying when a print publication goes down the same path as cable, first charging for something that was free, then eventually layering in the same ad content as when it was free.

Artificial scarcity based IAP, data-broker supported (ad supported is fine, individual data for content is not), and the descent into the ironic sounding “gacha” model for software or content happy meals (utilities, clickers, news, etc.) — something thoughtful has to shift before we’re living in a future less Roddenberry than Idiocracy.

Re: 1password is considering a self-hosted option to store vaults

#139

Earlier quoted context omitted.

You don’t like the idea of storing opaque bits along with everyone else’s equally opaque bits? So long as the secret key to these bits is yours, not theirs, what’s the catch?

Defense in depth is a legitimate aspect of security. Would you rather keep your money in an unbreakable box on the sidewalk, in an unbreakable box in a stranger's shed three towns over, or in an unbreakable box bolted to the floor of your cellar with your dog sleeping by the stairs?

Or, you know, in an unbreakable box of a business whose reputation depends on keeping it safe. Like a security deposit box in a bank? That doesn't sound unreasonable to me.

In contrast, comparing 1password to "a stranger three towns over" or "the sidewalk" seems a bit unfair to me.

Post reply on HN