Live data from Hacker News

1password is considering a self-hosted option to store vaults

1password.community

161–170 of 228 posts

Re: 1password is considering a self-hosted option to store vaults

#161
post #13

They made the standalone license almost impossible to find and get, forced a subscription on users, and made the password vault storage online for the subscriptions. Now this self-hosting survey comes as a surprise, and it would be of some relief if/when it’s implemented. I do wonder how the licensing and pricing will be handled though. Bitwarden officially allows self-hosting for the personal use tiers, but it seems…

> I’ve looked at KeePassXC and Bitwarden. The former isn’t easy to use for sharing and sharing permissions.

For a while, I used KeePassXC work my encrypted database file checked into my Dropbox storage. That allowed me to sync my passwords between devices but not give the cloud provider any way of knowing the passwords (since my KeePassXC master password was not stored anywhere besides in my brain). Unfortunately, Dropbox eventually changed their Android app so that synced files no longer were stored on the local filesystem, so adding a new password from Android or getting the new passwords from other devices would require manually uploading/downloading the file through the Dropbox app. I somewhat suspect this change was due to Dropbox eventually adding their own password management functionality to the app, but I didn't consider that until later, so I'm not sure how the timings lined up. In age case, after weighing my options I ended up deciding to just switch over to Bitwarden. (The migration was extremely easy; I was able to export the KeePassXC database file locally to XML file and then import that into my newly-creates Bitwarden account without any issues).

Re: 1password is considering a self-hosted option to store vaults

#162
post #161
post #13

They made the standalone license almost impossible to find and get, forced a subscription on users, and made the password vault storage online for the subscriptions. Now this self-hosting survey comes as a surprise, and it would be of some relief if/when it’s implemented. I do wonder how the licensing and pricing will be handled though. Bitwarden officially allows self-hosting for the personal use tiers, but it seems…

> I’ve looked at KeePassXC and Bitwarden. The former isn’t easy to use for sharing and sharing permissions. For a while, I used KeePassXC work my encrypted database file checked into my Dropbox storage. That allowed me to sync my passwords between devices but not give the cloud provider any way of knowing the passwords (since my KeePassXC master password was not stored anywhere besides in my brain). Unfortunately, Dr…

KeePass2android is a keepassXC client that supports the likes of Dropbox. It seems to fit what you need.

How does Bitwarden compare to Keepass?

Re: 1password is considering a self-hosted option to store vaults

#163
post #106

Earlier quoted context omitted.

> Is there any password management application out there that makes sharing passwords or password vaults easy but is also free? For members of a relatively well-paid profession earning good wages from creating software, I wonder if the reluctance to support others earning money for quality work isn’t some form of cognitive dissonance. // Pre-emptive “edit” before this comment has replies: Folks post a lot of argument…

Nope. "Password Storage" should not be a business that exists in the form of "if you don't pay for good password storage, you're not allowed to have it." Especially if it involves storing your password with a third party. The technology to store passwords safely has a marginal cost of zero (it's software). People storing passwords in third party places increases the threat surface, always. Finally, it's "ecological"…

What's your alternative?

Re: 1password is considering a self-hosted option to store vaults

#164
post #84
post #78

Earlier quoted context omitted.

Tavis Ormandy (of Google Project Zero) has a pretty convincing post arguing that relying on browser extensions that modify the DOM (which includes [almost?] all password managers) is a bad idea: https://lock.cmpxchg8b.com/passmgrs.html (he recommends using your browser's built-in password manager, which isn't as convenient but is much more secure)

I only open the webui, log in, copy paste my usernames and passwords. I don't trust that my passwords are safe otherwise.

I don't trust the safety of passwords going through my clipboard and me having to manually verify the URL.

Re: 1password is considering a self-hosted option to store vaults

#165
post #28
post #16

Earlier quoted context omitted.

You can self-host vaultwarden (formerly bitwarden_rs), which gives full enterprise functionality.

I do this, works perfectly for sharing common passwords among my family (streaming services and utilities mainly). I moved from 1Password, and my main gripe with Bitwarden are the apps aren't as polished. If it's not too expensive I'd consider switching back (1Password family is $60 per year, so I assume this will be less).

That lack of polish and lack of improvement over the couple years I used Bitwarden are why I switched back to 1Password. Being open-source is not a free pass to ignore issues like that.

Re: 1password is considering a self-hosted option to store vaults

#166
post #54

Earlier quoted context omitted.

There's a chance it's using Tauri (rust) https://tauri.studio/en/ if it's truly not using Electron but a similar concept. However WASM builds in Electron would make more sense if they use the term Electron.

No, it's definitely regular Electron: % tar ztf 1password-latest.tar.gz | grep "chrome" 1password-8.1.1.x64/chrome-sandbox 1password-8.1.1.x64/chrome_100_percent.pak 1password-8.1.1.x64/chrome_200_percent.pak

[deleted]

Re: 1password is considering a self-hosted option to store vaults

#167
post #54

Earlier quoted context omitted.

There's a chance it's using Tauri (rust) https://tauri.studio/en/ if it's truly not using Electron but a similar concept. However WASM builds in Electron would make more sense if they use the term Electron.

No, it's definitely regular Electron: % tar ztf 1password-latest.tar.gz | grep "chrome" 1password-8.1.1.x64/chrome-sandbox 1password-8.1.1.x64/chrome_100_percent.pak 1password-8.1.1.x64/chrome_200_percent.pak

yeah I'm aware it contains chrome, I mentioned that much of the functionality has been moved out and is actually implemented in rust, this is verifiable simply by running `1password --log trace`

EDIT: 168MiB resident memory on my system (just checked).

Though it malloc'd (but never used) 32G, that's worrying.

Re: 1password is considering a self-hosted option to store vaults

#168

Earlier quoted context omitted.

Enpass works nicely. I can freely share vaults and keep vaults backed up in anyway I prefer. Two downsides: 1. Mobile is paid I think 2. Not open source

Personally I don't recommend Enpass. They switched to a subscription model like every other password manager. They don't host your data so have no recurring expense, I don't understand how they can justify the subscription model. They have no real innovation, they added an "Audit Feature" for an additional €26.49 per year.

Sorry; I didn't know. I got the "pro" version long ago for iOS and they have basically retained that (kinda upgraded for free as now I can use on all devices). I think it cost me $10 or something. So amazing for me.

Now the same deal is $80 which I think is still ok but on the high side.

I like their hands off approach. Password autofill/save etc are also far better than most other password managers (esp bitwarden).

Re: 1password is considering a self-hosted option to store vaults

#169
Frankly, given all the major data leaks of recent years and months, and not to mention ransomware incidents against even large, supposedly well-secured organizations, I fail to see how anyone with a modicum of security awareness could recommend or use a centralized password manager platform of any kind for their own security. People mention "convenience" but i'd say fuck that. Convenience is also how many seem to justify the total sell-off of their digital and financial privacy.

Re: 1password is considering a self-hosted option to store vaults

#170
post #117
post #78

Earlier quoted context omitted.

Tavis Ormandy (of Google Project Zero) has a pretty convincing post arguing that relying on browser extensions that modify the DOM (which includes [almost?] all password managers) is a bad idea: https://lock.cmpxchg8b.com/passmgrs.html (he recommends using your browser's built-in password manager, which isn't as convenient but is much more secure)

It'd be ideal if browsers offered standard hooks into their password-filling mechanisms. Let the password managers volunteer "I know a password for this site!" and fill it through the browser's standard UI. Basically, I want the browsers to implement something close to what Apple has for password management on iOS. Ideally go a bit further and expose hooks for creating/saving a new login, too. Unless they already do…

That's an amazing idea! Do you know if any browser vendor has this concept even in the radar? It would be very cool that password managers were able to do that: manage passwords, and not have to deal with each browser's idiosyncrasies which if you think about it, is just a distraction from their actual mission of being a password storage.
Post reply on HN