Live data from Hacker News

1Password Has Raised $620M

blog.1password.com

491–500 of 723 posts

Re: 1Password Has Raised $620M

#491
post #402

Earlier quoted context omitted.

I am using 6, and the classic extension still works for me on Firefox. It was only when they discontinued (and refused to port) the Safari classic extension that I couldn't use Safari anymore. [0]: https://support.1password.com/cs/1password-classic-extension...

Works for me on Chrome too, but not Brave (my browser of choice). Are there any security concerns holding on to 1p 6.0 ? I notice the mobile app still sees updates, but could there be in theory an unpatched security hold in the desktop app ?

That's part of the reason I am OK with just copying and pasting in firefox. It keeps the desktop app isolated from the browser.

Re: 1Password Has Raised $620M

#492
post #360

Earlier quoted context omitted.

Pretty typical for people here to be zoomed-in on the b2c side of a business because that's what they use, and fail to see the b2b side, the underwater mass of the iceberg.

I think people can see that this is targeting businesses, but they're not happy about that because they're non-business customers. It doesn't bode well for the future direction of what has up to now been a good consumer-focused product. Like how Dropbox has gone from "a folder that synchronizes your files" to "an electron app for having discussion threads about files" because that's what business customers want.

Hopefully the consumer marketshare has some influence on business decisions, which might make it worthwile for them to keep non-business customers. This kind of strategy certainly works for some professional software, which is often even free for students.

Re: 1Password Has Raised $620M

#493
post #85

Earlier quoted context omitted.

I mean... that seems fine? Taking a consumer product and making a business version of it feels like a totally ok way to grow a company that already has a stable product that people like. Them making new features you don't use doesn't mean they're going to break or diminish the stuff you do use. Sure, they could mess it up, but any company or open source project can mess everything up.

I can't remember a company that has served individuals and enterprises simultaeneously without one side getting a compromised offering. One of the things I like about Apple is they don't really pander to the enterprise. They won't turn the business away but you can see it isn't a priority.

Microsoft does decently well here, and you can navigate this if you basically give individuals enterprise software.

The problem comes in when you try to cripple the home version so that small businesses, etc don't just use that.

Re: 1Password Has Raised $620M

#494
post #477

Earlier quoted context omitted.

> Because much like privacy, password security shouldn't always be only a premium option. So then who foots the bill? Password managers are the duct tape used to protect a user because we don't inherently trust application providers. > proprietary code is a deal break for lots of people Sort of. First, "lots of people" seems like "lots of people" because we're on HN. The wider population doesn't care whether your app…

Bitwarden does charge for certain features like TOTP support, organizations, and enterprise features. They manage to have subscription income while remaining open source, whereas 1Password chooses to keep its code closed source. If you are saying that Bitwarden is worse because it offers a free plan, I disagree. It's nice that Bitwarden offers a security-audited* password manager to those who can't afford a subscript…

> Unlike 1Password, Bitwarden is not pressured to deliver high returns to venture capital firms, and Bitwarden can focus on providing its product to its users at superior price points

Well said - and this is the important part of the 'non-proprietary' argument of mine (above) - right now I consider 1Password's real customers being their shareholders/investors, not its users - the users are just another tool they use to bring value to their real customers (investors,etc.).

BitWarden's customers are their actual users.

Re: 1Password Has Raised $620M

#495
post #365

Earlier quoted context omitted.

Well, Hashicorp stands on many legs and they don't have much competition in many areas as theirs solutions are pretty unique...

Their solutions are unique but the problems they are solving are not, they are in direct overlap with where 1P is going.

Cue 1P - Hashicorp merger conversation

Re: 1Password Has Raised $620M

#496

Eh. I used to use 1Password long ago, when it was still a "normal" app (one-time payment, not trying to become a unicorn). It was easy for me to switch password managers (my needs are modest, and I generally like to break my app habits once in a while). My journey included (1) self-written manager; (2) LastPass; (3) pass CLI, and (4) Bitwarden (free tier). I'm now a happy Bitwarden user. It's ugly, and I'm a UX desig…

1Password is vastly superior to Bitwarden from a UX perspective, and considering that's literally the only reason I have a password manager, that is, by far, the most important thing.

If you think "security" is the reason you have a password manager, how come all of your accounts are tied to your email address? If you just wanted security, there are, by far, more secure tools and practices you could employ than Bitwarden (among them keeping a notebook of passwords on your person at all times).

Your comment reads, to me, as a signaling effort. "I'm aware of bad corporations and I don't support them!" is less strong of a signal than you may think.

Re: 1Password Has Raised $620M

#497
Regardless of the TAM of secret management and the enterprise market for it.. this is a ton of money. I don't fault 1Password for taking it if it was offered, but I personally find it off-putting. How can the market opportunity be so compelling to justify that level of investment, but at the same time require that much capital infusion to chase? If there is enough demand it should be possible to balance funding from external investment and cash flow. They've been around 17 years, so my hope is it is just early investors cashing out on a $7B valuation, which seems doesn't seem unreasonable. It is hard to know without more details.

Re: 1Password Has Raised $620M

#498
post #113

Earlier quoted context omitted.

But 1Password previously had the option to _not_ use their cloud, and they deliberately killed it to push people onto their subscription offering. So I think in the context of a conversation about how financial conditions will force changes which change the customer experience, I think it's entirely fair to compare them to a non-cloud option.

>they deliberately killed it to push people onto their subscription offering There are things available via the Cloud version that aren't available with local vaults and, in order to maintain those, they decided not to put the time into implementing those changes for local vaults. Local vault users are less than 1% of their user base.

How is that not deliberately pushing people to move to a subscription model?

Re: 1Password Has Raised $620M

#499

I really wish they weren't doing away with 1password classic and the native mac app. I like the fact I bought a license, that I can store the data on dropbox or icloud, and it works just fine. Yes, this is old news and sour grapes on my part. I just don't yet feel like migrating to bitwarden. I've been using 1password for 12 years since I saw it on a tutorial on peepcode.com. I actually taught my mother how to use it…

Migrate to Bitwarden. I owned a 1 password 6 license and hung onto it for dear life until last year. I technically had a 1 password subscription from work, and when that ended last year, my password experience hit a brick wall. I couldn’t add passwords from Windows. My Mac client refused to work, I had to uninstall multiple times and delete a data directory to erase any sign that 1 password subscription was on the sy…

Same made the switch to bitwarden this year.

Re: 1Password Has Raised $620M

#500

Earlier quoted context omitted.

> Even if you can tell a compelling story about how they carefully encrypt everything right now, you're always a silent update away from it all being dumped on the internet. This is also true for your operating system updates, browser, browser extensions, compilers, the infrastructure for your email service provider, any libraries those things use etc. Not to mention your local password manager. Even if you don't acc…

> This is also true for... Agreed, those are already risks, and ones that are a lot harder to mitigate (though I do try where I can). Does that mean I should add another one that I can easily avoid? There are risks in both local and cloud password managers. Maybe those risks seem equivalent to some folks, and the cloud features are useful enough for it to be a no brainer for them. For me, I don't at all mind manually…

Hey— whatever works for your setup. Especially for those who don't use a smart phone and have one machine, it's probably a minimal loss in functionality.

> Does that mean I should add another one that I can easily avoid?

All other things being equal? Avoid it, of course. I firmly oppose letting perfect be the enemy of good in the sense that more secure is better than less secure even if it's not perfectly secure. But I also oppose it in the sense that rejecting beneficial functionality because it's not perfectly secure, especially when it's not close to the biggest or most attractive attack surface, doesn't make sense. Even when password managers' servers were compromised— LastPass, for example— I don't think anybody ever got ahold of passwords. KeePass OTOH was broken with KeeFarce and RATs are a lot more common than cloud service server breaches.

> This seems focused on the case of a dedicated attacker focused on you specifically. Id think each of us is more likely to be affected by various automated attacks that are backed by large dumps of account credentials.

Nope— If it was automated the distinction is even less significant. A script would only need to search your email for whatever specific types of logins it supported and fire off password resets. Non-email 2FA becomes even more of a hurdle without the option of social engineering it or some other human-touch fix.

Consider this. (very) Roughly, this is the market penetration for these products:

* computer: 90%+

* smart phone: 85%

* tablet: 50%

* computer, smart phone and tablet: 40%

Most people (in this country, at least,) have multiple devices. Most people have internet access. Most people aren't going to be able to manage storing and sharing passwords among their devices at all, let alone more securely than cloud storage would do it. So for most people's use cases, it would be like citing health when refusing to put a teaspoon of sugar into the cup of tea they're having with cake and ice cream.

So like I said, avoid it if it doesn't improve your life— I have no stake in your password management choice— but I will actively butt in to qualify the sentiments expressed in this thread because, a) many users, even on this site, aren't sophisticated enough to engage in the sort of cost/benefit analysis that we are, and b) to them, this conversation is unintentional FUD. Cloud-based password management is vastly superior to regular folks' existing methods. If they're put off by technically savvy people saying they're fundamentally insecure, that is the embodiment of perfect defeating good.

Post reply on HN