Why are Dropbox and iCloud preferable to 1Password sync?
1Password's proprietary sync isn't open source and isn't open standards. It is designed to lock me into reliance on a company that has inarguably demonstrated that it hates its users.
51–60 of 136 posts
Why are Dropbox and iCloud preferable to 1Password sync?
1Password's proprietary sync isn't open source and isn't open standards. It is designed to lock me into reliance on a company that has inarguably demonstrated that it hates its users.
Bitwarden can be self-hosted. $10/year subscription cost is well, well worth it. If you don't self-host, note that everything is encrypted before being stored at bitwarden. They don't have access to your passwords.
Import/export is irrelevant. I want to own my data, not just be able to check out a copy whenever I want.
Earlier quoted context omitted.
A few HN posts from the last week regarding LastPass: Ask HN: How did my LastPass master password get leaked?: https://news.ycombinator.com/item?id=29716715 LastPass users warned their master passwords are compromised: https://news.ycombinator.com/item?id=29716715
Note that master passwords were not compromised, the the warnings were triggered in error[1]. That's not to say that other concerns around security aren't valid. [1] https://www.theverge.com/2021/12/28/22857485/lastpass-compro...
Earlier quoted context omitted.
+1 Bitwarden. I wish they dog fooded more so they can see how bad their browser extension is though.
On firefox, their browser extension is excellent for me; what issues do you have?
* Android app logs itself out every time I use it.
* Lacked versioning of passwords (last time I checked).
* The workflow to add new passwords / reset passwords on websites is clunky. This hasnt improved for years.
Bitwarden can be self-hosted. $10/year subscription cost is well, well worth it. If you don't self-host, note that everything is encrypted before being stored at bitwarden. They don't have access to your passwords.
Bitwarden is just as user-hostile. They go out of their way to make it harder to own your data, when it should just be local-first vaults. Import/export is irrelevant. I want to own my data, not just be able to check out a copy whenever I want.
Earlier quoted context omitted.
I've been a happy 1PW user on Windows 10 for a few years, but admit I haven't paid a lot of attention. I haven't noticed any big changes. What are you guys referring to?
They made generating passwords more difficult. You can no longer tell it how many, e.g., special symbols to use, only to use them or not. This means regenerating new passwords over and over until one fits site requirements, and/or manual tweaking that might unintentionally reduce entropy. They stopped supporting the mobile extension. I can no longer invoke 1Password from Safari on iOS. If I'm lucky , then Safari's ow…
They did provide an alternative, to be fair -- they're shipping a Safari web extension that you can turn on, which gives you about the same behavior as in a desktop browser.
Honestly, I find that the built in iOS autofill stuff works fine for my purposes. I recognize that's probably very specific to the exact sites I'm using, though...
Earlier quoted context omitted.
On firefox, their browser extension is excellent for me; what issues do you have?
Not him, but: * Android app logs itself out every time I use it. * Lacked versioning of passwords (last time I checked). * The workflow to add new passwords / reset passwords on websites is clunky. This hasnt improved for years.
Lets take all of a user's credentials (mixing the critical and the trivial) and put them into a single database and then use Javascript-based browser extensions to control access to the DB. What could go wrong?
The LastPass communications brouhaha from last week was just a whiff of the total shit show we're going to see when the client code from one of these password managers is modified with trojan code and we realize that some group has been slurping up credentials by the billions over the course of a few months.
Seems like the charitable take is that password managers are maybe the best approach to a horrible idea, and the real solution is that we ought to be racing to abolish passwords altogether as soon as possible.
Earlier quoted context omitted.
On firefox, their browser extension is excellent for me; what issues do you have?
Not him, but: * Android app logs itself out every time I use it. * Lacked versioning of passwords (last time I checked). * The workflow to add new passwords / reset passwords on websites is clunky. This hasnt improved for years.
2) The older versions are available online if you click on the number to the right of "Password History"
3) Agree, that can use some polish
If you can handle what I call[0][1] "the KeePass way": on desktop, KeePassXC (Windows/macOS/Linux) on desktop; on mobile, KeePass2Android or Keepassium (iOS). [0]: https://www.brycewray.com/posts/2021/06/two-paths-password-m... [1]: https://www.brycewray.com/posts/2021/08/1password-hits-fan/