"1Password Has Raised $620M" Ah fuck. They now need to grow at any cost to earn all that money back. And they'll throw their users under the bus, if they have to, because it's either grow like a unicorn or go bust. Also, I sincerely have no clue how a password manager could be so expensive. Last time I checked, the excellent KeePassXC was still free open source and developed by volunteers in their free time. How come…
1Password Has Raised $620M
391–400 of 723 posts
Re: 1Password Has Raised $620M
#392Earlier quoted context omitted.
Maybe you can't. Everybody has their own risk tolerance, but at some point, everybody's going to have to draw a line. Maybe you're only storing passwords for local services, but almost all of the credentials in my password manager are for services run on some cloud. Even then, did you evaluate all of the code for each of those services? How about the compiler code or the chips? Dell shipped out machines with a hardwa…
> Maybe you can't. Everybody has their own risk tolerance, but at some point, everybody's going to have to draw a line. I'm in agreement with parent, I think putting your passwords in the cloud is a wild single point of failure. Even if you can tell a compelling story about how they carefully encrypt everything right now, you're always a silent update away from it all being dumped on the internet. I think people (in…
This is also true for your operating system updates, browser, browser extensions, compilers, the infrastructure for your email service provider, any libraries those things use etc. Not to mention your local password manager. Even if you don't accept push updates, do you evaluate the code? What if the vulnerability was timed to pop a few weeks after release? What if it was included in an update that patched a major vulnerability so you went faster than your normal process afforded? Even if you have a local firewall that stops external connections from unrecognized programs— what if it's a whitelisted program or the operating system or the firewall itself?
Why would you a password manager's encryption less than you would trust your email service's encryption? I'd bank on the password managers' being a lot more robust.
What about RATs that could access your local password database? RATs are a lot more common than cloud service breaches.
And as I mentioned previously, Dell shipped a hardware trojan in 2010.
There are tons of single-point attack vectors in this chain. I'm not a security expert, but storing encrypted data in cloud storage seems less likely than others be a viable target.
> Having your main email account compromised seems like an absolute nightmare where you potentially lose control of every single service that you subscribe to (banking, utilities, cell phone (so maybe 2fa is even broken), medical portals, social media, etc). > Having your entire set of passwords compromised is like that on steroids. Rather than your attacker having to use your email to get to each of those services one at a time, they just have them immediately. And who says you'll even know that your stuff was compromised?
Let's say they did compromise your email account. Since only a few of your accounts are genuinely consequential to nefarious criminals, the number of password resets they'd need to execute might set them back, what— 5 minutes if it's not scripted? And all of it is moot if you use a 2FA method aside from email? Beyond that, considering how much more frequently email accounts get compromised, singling out the storage location for password manager databases seems pretty arbitrary.
I just don't see how the opposition stands up to a comparison of attack vectors.
Re: 1Password Has Raised $620M
#393Earlier quoted context omitted.
Sounds like they've noticed both macOS and Windows getting integrated cloud-based password management capabilities and feel the need to branch out in order to stay one jump ahead of irrelevance. (Disclaimer: I'm a satisfied 1Password customer. Just noting that their competitive edge is wearing razor-thin these days.)
I long hoped Apple would buy out 1Password and include it in their iCloud+ subscription.
Re: 1Password Has Raised $620M
#394Re: 1Password Has Raised $620M
#395"1Password Has Raised $620M" Ah fuck. They now need to grow at any cost to earn all that money back. And they'll throw their users under the bus, if they have to, because it's either grow like a unicorn or go bust. Also, I sincerely have no clue how a password manager could be so expensive. Last time I checked, the excellent KeePassXC was still free open source and developed by volunteers in their free time. How come…
> And they'll throw their users under the bus Just as they did when all the snafu with Dropbox and the switch to a subscription based service. Before the subscription service, I had spent hundreds buying all their apps for me and my family. 1P wasn't cheap but it was worth it. They used the users' Dropbox to host the web based vault. Obviously one day Dropbox decided it was not ok to use the public folders to host we…
Re: 1Password Has Raised $620M
#396Earlier quoted context omitted.
I’m amused by the large portion of the Hackernews userbase that seems to view venture capital as an absolute evil, given that this is YCombinator’s forum. Can you really not think of any examples where VC capital has improved a company, product, or service?
> Can you really not think of any examples where VC capital has improved a company, product, or service? I honestly can’t, do you mind sharing a few examples to prove your point? I have a long list of “stopped using because went to shit after VC was injected” 1. WhatsApp and Facebook relation 2. Twitter and the loss of control over my feed 3. Spotify and the podcasts shenanigans 4. Dropbox and their assholery against…
https://techcrunch.com/2007/07/29/more-information-on-that-s...
Re: 1Password Has Raised $620M
#397Earlier quoted context omitted.
I've had the exact same experience. It took me about 5 minutes to teach my partner how to use 1Password and its been years since I had to help them use the app. I've stopped worrying about password re-use or compromise. Now I'm teaching my kids to use it and they love it b/c they dont have to make up or remember passwords. Yes there are other technically equivalent options but the fact I can get it setup on an iOS de…
My wife uses KeepassXC and KeepassAndroid now and syncs it with her own Dropbox. But yes, 1Password takes a lot less time for people to get used to. But to some extent it took her compromised passwords to finally start using everything.
Is there one which is best for most users?
Re: 1Password Has Raised $620M
#398Earlier quoted context omitted.
> Also, I sincerely have no clue how a password manager could be so expensive. Last time I checked, the excellent KeePassXC was still free open source and developed by volunteers in their free time. Because 1Password is easy enough to use that my wife and I can share a family plan without her getting frustrated. If one of us has a login the other needs, we can easily share it. When I evaluated KeePass, the Wife-Accep…
We use BitWarden and it is free. $620M for a password manager is nuts.
Re: 1Password Has Raised $620M
#399For some very rough context: - Duo was acquired for $2.35B - Ledger was valued at $1.5B - Dashlane was valued at $1B - Yubico was valued at $600M - LastPass was acquired for $110M - Trezor has an annual revenue of $5M - Authy was acquired after receiving investments of $3.8M
Hashicorp has an 11+B market cap Okta has a 30+B market cap
The view I keep seeing here of 1P as simply a 'password manager' is myopic... It's one of their products, and currently the most visible, but it's just 1 product.
Re: 1Password Has Raised $620M
#400Earlier quoted context omitted.
Bitwarden is free for individuals and couples. So, it's free user-friendly (WAF!!) wise [0] in comparison to 1pass [1]. But much more important thing is the fact that bitwarden is open source and 1pass not. Closed source is deal-breaker for me. [0] https://bitwarden.com/pricing/ [1] https://1password.com/teams/pricing/
Bitwarden free edition is free. The free edition is crippled and doesn't support Yubikey among other things.
Yubikey and its likes are advanced features that the overwhelming majority of regular users will never need.