Live data from Hacker News

A command line interface for 1Password

github.com

11–14 of 14 posts

Re: A command line interface for 1Password

#12

Why would anyone trust 1password or any other closed source password manager at all?

It's a little excessive to say that closed source means it can't possibly be secure or trustworthy. It implies open source is a silver bullet for security, which just isn't true. I use 1Password and love it. I can tell after using other products that they have put a tremendous attention to detail into it. It is really easy to use and thoughtful in its design compared to the alternatives.

I said nothing about open source being a silver bullet. I only implied that it is better than closed source. The consensus has been that open source is more secure, especially with the bad behavior of corporations and government agency strong arm techniques in mind.

It just makes no sense to centralize your most important secrets into a single attack point for which you have no idea about its inner workings.

Re: A command line interface for 1Password

#13

Earlier quoted context omitted.

It's a little excessive to say that closed source means it can't possibly be secure or trustworthy. It implies open source is a silver bullet for security, which just isn't true. I use 1Password and love it. I can tell after using other products that they have put a tremendous attention to detail into it. It is really easy to use and thoughtful in its design compared to the alternatives.

I said nothing about open source being a silver bullet. I only implied that it is better than closed source. The consensus has been that open source is more secure, especially with the bad behavior of corporations and government agency strong arm techniques in mind. It just makes no sense to centralize your most important secrets into a single attack point for which you have no idea about its inner workings.

What consensus? All I'm seeing are assumptions that being able to read code easily means it is more secure. Someone can easily write an open-source project that looks like it is a secure project but can easily be misused to do bad things without people catching it in the act.

Look at Heartbleed and how lack of funding led to a horrible bug being missed. There has been other open-source projects hit by similar issues. Just as there are closed-source projects being hit with their own issues.

The nature of the code license does not, and I stress this strongly, lead to anything being more secure than other solutions.

A properly funded and talented team of developers working on an open source project is just as secure as a properly funded and talented team of developers working on a closed source project.

Re: A command line interface for 1Password

#14
Heh--I just spent the last few days going the opposite way, building a web interface for Pass for fun. Demo is up here: http://example.pw.less.sexy/ (the service and master password are both "pass") and source is here: https://github.com/johnswanson/pass-server

Nice job--I used to use 1Password and remember looking for a tool like this!

Post reply on HN