Earlier quoted context omitted.
> Enterprise features on the other hand, that's not something that OS vendors are likely to ship. Maybe not on Mac, but MS will probably try.
If anything I'd bet on MS sticking it into their Office subscription, not Windows itself. So 1Password will be up against iCloud Keychain from Apple and Microsoft Passwords 365 on the enterprise front.
1Password Has Raised $620M
711–720 of 723 posts
Re: 1Password Has Raised $620M
#712Earlier quoted context omitted.
> Just 3 dollars a month… if every piece of software I use on a daily basis cost me a few dollars then the usage cost would spiral out of control. This sounds so much pithier than it actually is, but of course every reply will say it. Does 1Password asking for 3 dollars make every other app on your computer suddenly need 3 dollars a month? Every piece of software needs its own plan for continued development. Some sof…
> People are allergic to upfront payment. What? People in general are clamoring and highly prefer one-time payment. Approximately nobody wants a recurring charge every month. Companies are pushing and forcing subscriptions only because the recurring revenue stream is what investors want to see. People don't want it.
IME most people don’t want to pay for anything at all. Which is partly why the subscription model works — try it for free for a month so you can understand the value proposition. Afterward, you’re more willing to pay for it.
Re: 1Password Has Raised $620M
#713You'd think with $620M they'd be able to continue to develop native applications and not 'have' to move to a javascript react monstrosity.
Re: 1Password Has Raised $620M
#714I can see the use case for these online password apps. But I can't for the life of me understand why KeePass isn't the defacto gold standard. It's secure, open source and you have control over the data. I would never for the life of me think of storing my important passwords with a company ever. Am I over reacting?
Re: 1Password Has Raised $620M
#715You'd think with $620M they'd be able to continue to develop native applications and not 'have' to move to a javascript react monstrosity.
Yay the kind of « monstrosity » that all apps are moving to because that’s objectively what 90% of users prefer.
Re: 1Password Has Raised $620M
#716Earlier quoted context omitted.
Yeah but the chrome plugin still works at full functionality.
Yes but I don't want to use chrome, especially after they break ad blocking. To answer your question about the security: I don't know. I don't audit it, and copying and pasting lets me not really have to worry about the security of the browser extension.
Ublock Origin still works for me, what are you referencing ?
Re: 1Password Has Raised $620M
#717I can see the use case for these online password apps. But I can't for the life of me understand why KeePass isn't the defacto gold standard. It's secure, open source and you have control over the data. I would never for the life of me think of storing my important passwords with a company ever. Am I over reacting?
Re: 1Password Has Raised $620M
#718Earlier quoted context omitted.
Hey— whatever works for your setup. Especially for those who don't use a smart phone and have one machine, it's probably a minimal loss in functionality. > Does that mean I should add another one that I can easily avoid? All other things being equal? Avoid it, of course. I firmly oppose letting perfect be the enemy of good in the sense that more secure is better than less secure even if it's not perfectly secure. But…
> I don't think anybody ever got ahold of passwords. KeePass OTOH was broken with KeeFarce and RATs are a lot more common than cloud service server breaches. Can we actually know this? We only know about the breaches that we're told about, or that are found and disclosed by researchers. I'm not familiar with KeeFarce, but presumably attackers need local access, in which case you're boned anyway. > ... many users, eve…
Can you ever actually prove a negative?
> I think we're in a bit of an age of innocence with everything moving to the cloud, where everyone still believes that all of these services are going to be well meaning, competent, capable stewards for your bits.
> Once any info gets to the cloud, its out of your control forever.
You're propping up a straw man using a hyperbole.
> But for someone not tech savvy, I'd probably recommend a pen and paper with memorable (long) pass phrases before I'd recommend a cloud solution[...]
And then presenting your original assertion without any more evidence.
But that's all nearly beside the point.
The most difficult factor to wrangle is human psychology. Without intervention, phishing attacks just work. People re-use passwords. People switch from redox1 to 1redsox1 when forced to change them. They do this all to avoid having to think about it.
The entire point of password managers is to mitigate this. You need to compete with the psychological ease of re-using the same password repeatedly because that's the only way regular users will use it. Then, you can warn them when they're entering credentials into a site where they don't belong. You can warn users if a service they use was breached. You can warn users that their password is weak or reused or old and give them a quick solution rather than leaving them to figure it out. You're making it easy for them because that's the only way it works. If you draw two barely kissing circles on a sheet of paper, that's the Venn diagram of users who care enough about electronic security to deal with the extra irritation of using strong unique passwords but won't use an automated system to do it.
So maybe the second-weakest link is the credentials themselves, and the third weakest link is the collection of websites users submit their credentials to that don't store the passwords in AES-256 encrypted vaults with no local master password storage, like password managers do, and the fourth is probably the browser, etc.
Everything we know about the actual empirical risk of these components points to password managers, in general, being close to the bottom of that list. Prioritizing anything but the most blatant password manager security flaws over even minor user convenience will have a negative net effect. When it's a risk so obscure that we have no documented instance of it occurring among thousands of documented instances of breaches occurring in other services, I'd argue it's less safe.
If you're going to base your security strategy on intuition about our relationship with cloud services, go for it. Personally, I'll leave the faith to the priests and stick to attack vector analysis and balancing limiting attack surfaces with solutions that work most easily for most people, because that's the only way they'll use them.
Re: 1Password Has Raised $620M
#719Earlier quoted context omitted.
> I don't think anybody ever got ahold of passwords. KeePass OTOH was broken with KeeFarce and RATs are a lot more common than cloud service server breaches. Can we actually know this? We only know about the breaches that we're told about, or that are found and disclosed by researchers. I'm not familiar with KeeFarce, but presumably attackers need local access, in which case you're boned anyway. > ... many users, eve…
> Can we actually know this? Can you ever actually prove a negative? > I think we're in a bit of an age of innocence with everything moving to the cloud, where everyone still believes that all of these services are going to be well meaning, competent, capable stewards for your bits. > Once any info gets to the cloud, its out of your control forever. You're propping up a straw man using a hyperbole. > But for someone…
> Can you ever actually prove a negative?
Does that mean that you agree that we can't know the extent to which things have been exposed? Cause that's part of my point. Of course you can flip that around and say well you can't prove that nobody compromised your local machine, but one of those things is open to attack from many orders of magnitude more attackers by virtue of being on the open internet and in a physical space that you don't control.
> You're propping up a straw man using a hyperbole.
You're cooking up a tasty word salad there, chef. Can you give me a little more meat here? I don't quite follow. Have you never heard people say that you shouldn't write an email or send a picture that you wouldn't want to see in the newspaper? Its a similar concept. Once you send something out over the wire, your power to make decisions over what's done with it is gone. You have to hope that whatever was listening on the wire is (and will continue to be) benevolent. How do straw men and hyperbole apply here?
> The most difficult factor to wrangle is human psychology. Without intervention, phishing attacks just work. People re-use passwords. People switch from redox1 to 1redsox1 when forced to change them. They do this all to avoid having to think about it.
> The entire point of password managers is to mitigate this.
I agree. That's part of why I use a password manager, and recommend that others do so too. We just disagree on whether or not its advisable to cede control over that kind of tool to a third party.
It feels a lot like the argument that your money is safer in a bank than in your mattress, which is an argument I agree with. Except replace all the banking regulations and security with a ToS that can change anytime and emails about how very deeply we care about your security. I'll keep my cash in my safe at home in that scenario. Maybe there are some people who'd still be better off using that bank. I wouldn't feel good giving that recommendation though.
Re: 1Password Has Raised $620M
#720Earlier quoted context omitted.
> Can we actually know this? Can you ever actually prove a negative? > I think we're in a bit of an age of innocence with everything moving to the cloud, where everyone still believes that all of these services are going to be well meaning, competent, capable stewards for your bits. > Once any info gets to the cloud, its out of your control forever. You're propping up a straw man using a hyperbole. > But for someone…
> Can we actually know this? > Can you ever actually prove a negative? Does that mean that you agree that we can't know the extent to which things have been exposed? Cause that's part of my point. Of course you can flip that around and say well you can't prove that nobody compromised your local machine, but one of those things is open to attack from many orders of magnitude more attackers by virtue of being on the op…
https://en.wikipedia.org/wiki/Russell%27s_teapot
https://en.wikipedia.org/wiki/Straw_man
I have better things to do.