Live data from Hacker News

1Password for Linux beta

blog.1password.com

101–110 of 254 posts

Re: 1Password for Linux beta

#101
post #94

Earlier quoted context omitted.

Huh, you are saying that something that is so important you want for free, and that the company building this product for you should forgo money and work simply for free? Wouldn't the opposite make far more sense that something that is so important you should pay 'more' for? They are free options that you are welcome to, but for people who want more they pay for it.

The only way to guarantee that your keyring is secure long-term is for the source code (and change history) of your password manager to be inspectable and verifiable. A promise made by a corporation is not sufficient. You can pay a corporation to buy a product with more features or better service. But you can't pay a corporation to hold or maintain a principle. There will always be someone who can offer them more mon…

And what makes you think that Jason or Raymond won't wake up one day and decide they had a change in principles? Just like people, companies have reputations and values. Individuals are not immune to malevolence.

Re: 1Password for Linux beta

#102

The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…

[deleted]

Re: 1Password for Linux beta

#103

It blows my mind how you can be smart enough to use Linux and still use a proprietary closed source "password manager" on it. If it was something unimportant, like a game, ok. But a password manager? The key to all your digital life and secrets... And in addition from an American company that will upload your (encrypted) passwords to a cloud in US? And in addition, I find it deceptive that they try to confuse the pot…

> It blows my mind how you can be smart enough to use Linux

Please don't overstate the intelligence required to use linux. It's not that high.

> ...and still use a proprietary closed source "password manager" on it.

People run plenty of proprietary closed source software on linux. This can include password managers, because perhaps they prefer it. Also a password manager of all things is something most people will need to use cross platform, not solely on linux.

> If it was something unimportant, like a game, ok. But a password manager? The key to all your digital life and secrets...

Games being another proprietary closed source application people run on linux. Games still present meaningful risks to your computing and privacy.

> And in addition from an American company that will upload your (encrypted) passwords to a cloud in US?

AgileBits is a Canadian company.

> And in addition, I find it deceptive that they try to confuse the potential users by pretending to be somehow involved or concerned by open source.

A company can be involved and concerned with regards to open source without releasing a product that is open source. Microsoft releases and contributes to a lot of open source software but Windows and Office are both closed source.

Re: 1Password for Linux beta

#104
post #99
post #45

I have been using LasPass since many years ago. There's an extension for Chrome and for Firefox. On Android I use the app and even though experience is not that "automatic" it works. I am surprised nobody mentioned LastPass is there any reason I should know?

I moved from LastPass due to various security concerns, but in Chrome/Linux 1Password is a worse experience. LastPass is just smarter about creating accounts and assigning new passwords, or updating if you change them.

Can't talk about security concerns, but my experience is exactly opposite. Using LastPass is pain, while 1password works like a charm.

Re: 1Password for Linux beta

#105

The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…

Well, what do you use already? The same password everywhere? Passwords written/printed on paper? Stored in a file? I don't see how anything you have now could be better than e.g. Bitwarden

Re: 1Password for Linux beta

#106

The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…

Oh, I would not want to use any kind of password manager with built-in synchronization either; an integrated solution presents a much more attractive target for black hats. I've been using KeePassXC and its predecessors, and sync to other machines using Git+SSH (no third party hosting either) and to my phone using adb for a few years now. YMMV.

Re: 1Password for Linux beta

#107

The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…

You aren't the only one. Those "fancy" apps are too complex IMO to be trustworthy. Neither are other people's computers (aka clouds).

My secrets are stored in plain text files which are encrypted with GnuPG. Emacs (and vi too) can handle encrypted files easily, even on an Android device using the Termux (i.e. Debian) app. Syncing with rsync (even version control software is an option) works and with a bit discipline is not a major problem.

Re: 1Password for Linux beta

#108
post #68

Earlier quoted context omitted.

You still haven't substantiated your opinion in any way.

What if service goes away? Even if stand alone app vendor goes away, the app still works. There are things that I see are okay as a monthly service like Netflix or other content provider where the content is literally changing month to month. Stand alone software that rarely changes, like 1Pass, does not warrant a monthly service fee from me. I am self-hosting the content, so I don't need their cloud services.

Playing devil's advocate here, but the service fee (at least to my mind) is more for the maintenance & upkeep of the infra.

I'd gladly move to self-hosting if it was only me. But after a few months, I was able to convince my wife to use it for convenience and security. So if there's an issue with the self-hosted version, it wouldn't just be me impacted, but my wife. And that's an SLA you don't wanna break. :D

Also, while I know I could probably do a decent job securing the hosting server, I would rather not have that on my mind. That's not my day-job, so I'll leave it to a team of people who are paid to do that.

Lastly, the service fee is $60/yr, but for sake of argument, lets call it $100. That's 2hrs of my time at my hourly pay. If setting up a self-hosted version takes me more than 2hrs to get it running, it's not worth my time.

Re: 1Password for Linux beta

#109

The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…

I definitely have some password manager anxiety. I'm not too concerned about hacks or losing my password database. For me, it's more about the sense of independence, and being able to log in to my accounts using just my noggin. I might be able to remember one or two strong passwords, but not dozens, which is kind of the selling point of a password manager.

I use KeePassXC with a password and key file. I sync the database, but not the file, using Syncthing. On the whole a satisfied customer, although the browser integration isn't perfect.

Re: 1Password for Linux beta

#110
post #96
post #69

Earlier quoted context omitted.

Not knocking the project, which sounds cool, but the absolute last thing I want to self host is a password database exposed to the internet. Hard pass on that element. 1password used to have a peer to peer sync mode that I loved. No need for a server anywhere. You would open it on your Mac and then open it on your phone and if they were on the same network they would self discover. Too inconvenient, perhaps, for most…

Bitwarden only ever decrypts the password database on the client, and the login credentials you send to the server are only a hash of your actual encryption key. In principle, you could store your Bitwarden database on a public torrent at no risk to your security :) So, if you do trust the Bitwarden software in the first place, self-hosting it shouldn't be any more dangerous than using the managed service, because th…

> (Even though the worst a malicious server could do is delete your database).

Unless you use the web client, and a lot of Bitwarden's functionality is only available via its web client (including critical functionality like changing your master password).

Post reply on HN