Live data from Hacker News

1password is considering a self-hosted option to store vaults

1password.community

191–200 of 228 posts

Re: 1password is considering a self-hosted option to store vaults

#191

Earlier quoted context omitted.

For me it’s the feature tiering and price discrimination that turns me off. I end up paying too much (total cost over 5 years) for too little. If you look at the business pricing it’s even dumber. The $2 billion valuation of 1password tells the entire story. They’re overcharging for what they’re providing and I think tech people can “feel” that which is why tech communities hate the subscription BS.

I don’t really think $8/user/mo for Business is overcharging compared to Slack which quickly gets into $30+ per user per month in larger shops where Enterprise Grid is required for its features. By your argument why can’t I buy that and self-host it too, decide if I want to upgrade for more features myself? I also think $5/mo for 1Password for Families is incredible value. Zero regrets on paying for this because it m…

Can you elaborate on:

>enabling TOTP (sharing of code generation) on many sites we use

Are you generating TOTP codes via 1Password or something? That seems like a degradation of security. I did a cursorary search and didn't find mention of 1Password providing such a "service".

Re: 1password is considering a self-hosted option to store vaults

#192
post #173
post #171

Earlier quoted context omitted.

If you don't trust the vendor, don't let them handle your passwords, obviously. But the security properties non-open-source code are routinely analyzed and vulnerabilities found, etc. Plus the track records of the various solutions, a cartesian product of open/closed source, 'hosted' or not, etc speak for themselves.

> If you don't trust the vendor, don't let them handle your passwords, obviously. The problem is you not only have to trust your vendor today , but you also have to trust them tomorrow . Every vendor is one acquisition or compromised senior executive or engineer [1] away from becoming untrustworthy even if they started out being perfectly trustworthy. Assessing present trustworthiness is hard enough. Assessing future…

Right, but this applies to big piles of security-critical software in general - a near tautology. It's really an argument in favour of my position that neither open-sourcedness nor hostedness are useful criteria in evaluating the security and fitness-for-purpose of a password manager.

Re: 1password is considering a self-hosted option to store vaults

#193
post #13

They made the standalone license almost impossible to find and get, forced a subscription on users, and made the password vault storage online for the subscriptions. Now this self-hosting survey comes as a surprise, and it would be of some relief if/when it’s implemented. I do wonder how the licensing and pricing will be handled though. Bitwarden officially allows self-hosting for the personal use tiers, but it seems…

When looking into KeePassXC, did you specifically look into the KeeShare[1] feature? As long as you have some common place to read/write a file, you can share a subset of your credentials. I agree this is not as easy as hosted solution like Bitwarden, but KeePass was always designed to be a non-hosted solution, so I think this is about as good as they can do. 1 - https://keepassxc.org/docs/KeePassXC_UserGuide.html#_d…

GP here. Yes, I did look at the KeeShare feature, and that's what I had in mind when I said seemed not as easy to use. I'll have to read more and try it out practically.

Re: 1password is considering a self-hosted option to store vaults

#194
post #13

They made the standalone license almost impossible to find and get, forced a subscription on users, and made the password vault storage online for the subscriptions. Now this self-hosting survey comes as a surprise, and it would be of some relief if/when it’s implemented. I do wonder how the licensing and pricing will be handled though. Bitwarden officially allows self-hosting for the personal use tiers, but it seems…

Are you saying there is as standalone version of 1Password 7? Does it support vault sync via iCloud?

GP here. Yes, there is a standalone version, but you'd have to know specific incantations and rituals to find out how and where to get it. It's purposely hidden away from the homepage and other pages about the product and pricing.

Re: 1password is considering a self-hosted option to store vaults

#195
This would make me consider upgrading to 7/Pro. I’ve resisted to do so because I am fundamentally opposed to the way they are centralizing the product and selling it in a subscription model, but a private vault server I could share inside a small business (or family) would be something I would buy.

Re: 1password is considering a self-hosted option to store vaults

#196
post #13

They made the standalone license almost impossible to find and get, forced a subscription on users, and made the password vault storage online for the subscriptions. Now this self-hosting survey comes as a surprise, and it would be of some relief if/when it’s implemented. I do wonder how the licensing and pricing will be handled though. Bitwarden officially allows self-hosting for the personal use tiers, but it seems…

> Is there any password management application out there that makes sharing passwords or password vaults easy but is also free? For members of a relatively well-paid profession earning good wages from creating software, I wonder if the reluctance to support others earning money for quality work isn’t some form of cognitive dissonance. // Pre-emptive “edit” before this comment has replies: Folks post a lot of argument…

$36 a year for 1Password is perhaps the best value/$ I get out of any software I pay for.

Re: 1password is considering a self-hosted option to store vaults

#197
post #13

They made the standalone license almost impossible to find and get, forced a subscription on users, and made the password vault storage online for the subscriptions. Now this self-hosting survey comes as a surprise, and it would be of some relief if/when it’s implemented. I do wonder how the licensing and pricing will be handled though. Bitwarden officially allows self-hosting for the personal use tiers, but it seems…

I've been using psono for a few months now https://psono.com/ .

Thanks a lot for this suggestion. It looks like what I need.

Re: 1password is considering a self-hosted option to store vaults

#198

Semi-related: this survey was announced alongside 1Password 8 for Windows early access. Apparently 1Password 8 for Windows uses Electron and there was some discussion about AgileBits wanting to move to the same architecture on all platforms. Does anyone know if 1Password 8 on macOS will also be an Electron app? Their Linux Electron app is pretty good and definitely much better than having no 1Password at all. However…

Well, if 1Password switches to Electron on the Mac, then I’m not moving away from 1Password 6…

Re: 1password is considering a self-hosted option to store vaults

#199
post #13

They made the standalone license almost impossible to find and get, forced a subscription on users, and made the password vault storage online for the subscriptions. Now this self-hosting survey comes as a surprise, and it would be of some relief if/when it’s implemented. I do wonder how the licensing and pricing will be handled though. Bitwarden officially allows self-hosting for the personal use tiers, but it seems…

I would consider Bitwarden if it synced via iCloud with my phone. Relying on any other service would be a step back for me.

Re: 1password is considering a self-hosted option to store vaults

#200
post #170
post #117

Earlier quoted context omitted.

It'd be ideal if browsers offered standard hooks into their password-filling mechanisms. Let the password managers volunteer "I know a password for this site!" and fill it through the browser's standard UI. Basically, I want the browsers to implement something close to what Apple has for password management on iOS. Ideally go a bit further and expose hooks for creating/saving a new login, too. Unless they already do…

That's an amazing idea! Do you know if any browser vendor has this concept even in the radar? It would be very cool that password managers were able to do that: manage passwords , and not have to deal with each browser's idiosyncrasies which if you think about it, is just a distraction from their actual mission of being a password storage.

iPhone does this already. You can choose from different password managers (I use built inn and and old version of 1P). So works on safari, but also other apps that I assume use some standard password field.
Post reply on HN