Live data from Hacker News

1password is considering a self-hosted option to store vaults

1password.community

221–228 of 228 posts

Re: 1password is considering a self-hosted option to store vaults

#221
post #90

I used 1password for about ten years. Every interaction I had with the developers was pretty hostile. Even if they encouraged self-hosting and version-based upgrading instead of a SaaS, I'd still stick with a competitor. At this point I'm irrationally bothered by the fact that it's a 100+ staff company just to make a product that's no better than it was when they had 10 staff and is now more expensive.

What are the good competitors you recommend? Dashlane?

I didn't want to respond while the thread was active because I didn't want to seem like I was advertising anything. I switched to BitWarden, personally. I am not saying it's better than 1Password (in fact, it's a little less slick in my opinion) but I was able to switch for free upfront, it works on all my devices, and overall the community of users seems much happier with the developers. This is not me saying "you should use it", just me saying "I ended up choosing it".

My wife's boss uses Dashlane, and I got the impression that was a pretty good choice if you were looking for ease of use for non-technical personnel.

Re: 1password is considering a self-hosted option to store vaults

#222

I am still on 1Password 6 because it is the last version with the self-hosted vault.

If that doesn’t show how well they’ve hidden the IP7 self-hosted version behind dark patterns! A loyal user had no idea it existed and stayed on 1P6 because of it.

You have to upgrade from within the IP7 app but only if you downloaded from their site, not appstore.

Re: 1password is considering a self-hosted option to store vaults

#223

Earlier quoted context omitted.

Can you elaborate on: >enabling TOTP (sharing of code generation) on many sites we use Are you generating TOTP codes via 1Password or something? That seems like a degradation of security. I did a cursorary search and didn't find mention of 1Password providing such a "service".

Yes. https://blog.1password.com/totp-for-1password-users/ It isn’t a degradation of security, in my opinion, it’s an upgrade, when certain accounts are involved. For these shared accounts, such as those used by my family, and on services which don’t support account-per-person in an “organization” or “household” sense, this still provides for TOTP in a way my spouse and I can both login. Ensuring just the loss of the…

I don't understand how it's not a security degredation. The point of TOTP is to make access of the service dependant on something you must have phsyically (and isolated from the internet) on you. An attacker that manages to exfiltrate 1Password data has everything they need to access the service if TOTP is part of their offering. Where as all users with TOTP on their phone would have an additional layer of protection.

Even by that blog post, they have to go out of their way and clarify that using this feature means you are not longer using two-factor authentication.

Re: 1password is considering a self-hosted option to store vaults

#224
post #36

Earlier quoted context omitted.

Thanks for the warning about this. I was already disappointed in the direction 1Password has been taking, and moving to Electron would certainly be the last straw. It’s totally reasonable that they want to cheap out on the actual software and expand their business into more lucrative services, but it’s not what I personally want in a password manager. So hopefully someone else, maybe a lone develop that doesn’t need…

Looks like you’re looking for a reason but none of that was announced or even hinted as happening on macOS. They have one of the best Mac native app, I doubt it’s part of their plan.

Well that was fast![0]

[0] https://news.ycombinator.com/item?id=28143563

Re: 1password is considering a self-hosted option to store vaults

#225

Earlier quoted context omitted.

You know, I bought 1Password version 3 licence. There’s the support. Fast forward some time and the software started recommending that I uograde to version 4. After installing it, the software told me that it requires subscription from here on. It was almost impossible to roll back to version 3. I ended up switching to Unix pass.

Similar story here. Slowly moved over to Bitwarden. UX almost as good and works well enough on all platforms. Chose Bitwarden for the company afterwards as well, only positive feedback.

I would have moved from 1Password to Bitwarden as well, but I stayed on the 1Password ship for its native app. May reconsider now, as they are moving to electron.

Re: 1password is considering a self-hosted option to store vaults

#226
post #67
post #62

Earlier quoted context omitted.

I'm paying for a Bitwarden subscription because I want to support their product and their vision. But I don't know, time passes and some much needed improvements don't seem to arrive. The most glaring issue (for me, anyway; I fully understand I'm just a sample size of 1!) they have is relying on the pop-up UI of the browser, which I guess is stateless (state is lost when the popup closes, it seems?). The decision of…

It gets worse. Their browser extension doesn't work when using a private window in Firefox. The GitHub issue[0] around it was raised in 2017. They've been blaming Mozilla for deprecating and subsequently removing an API. It's pretty ridiculous. [0] https://github.com/bitwarden/browser/issues/136

I thought it was just me where Bitwarden didn't work on the private window.

Re: 1password is considering a self-hosted option to store vaults

#227

Earlier quoted context omitted.

I agree to the payment. I disagree to the subscription model. I absolutely would try to hook users on any SaaS. However, I go out of my way to avoid such products. If I can pay for them once, I much prefer it. (For something like jetbrains, I'm okay with a renewal fee because if I choose not to pay it, I can still use the older version.) I make an exception for Bitwarden because I like the idea of my password manager…

You know, I bought 1Password version 3 licence. There’s the support. Fast forward some time and the software started recommending that I uograde to version 4. After installing it, the software told me that it requires subscription from here on. It was almost impossible to roll back to version 3. I ended up switching to Unix pass.

(disclamer, I work for 1Password)

I can tell you a "secret" you can download any version of 1Password, including version 3 from this website: https://app-updates.agilebits.com/

Re: 1password is considering a self-hosted option to store vaults

#228
post #53

Earlier quoted context omitted.

If you stop paying them, you stop being able to update your passwords. Also if you can't connect to their servers, you can't synchronise your passwords between devices. Also non-US companies will have a concern about storing sensitive material on US-based services given the powers the US is giving itself regarding intercepting communications or seizing data centres.

You are not storing passwords in plaintext on their servers. They are very open and document on how it works. Basically you give them fully encrypted information they can‘t use for anything

"Fully encrypted" doesn't matter if an attacker finds a vulnerability in 1Passwords encryption, or simply gets hold of the cipher text and has time and money on their side.

This is pretty fundamental security practise: don't give people stuff they don't need to have, and that means you face less risk of that stuff being lost or misused.

Post reply on HN