Live data from Hacker News

1Password for Linux beta

blog.1password.com

111–120 of 254 posts

Re: 1Password for Linux beta

#111
post #81

I would like to throw out Bitwarden out there. Cross platforms, works on everything and can be self hosted if you so desire.

Bitwarden is great, but I'm getting frustrated at their ridiculous excuses for not implementing fixes. For the longest time bitwarden has been broken in the firefox's private browsing after mozilla deprecated some apis due to security concerns. They've given alternatives but they are just refusing to fix it, to the point of basically saying mozilla needs to fix the issue. What's sad is a similar mechanism is used in…

I guess if you take the long view, Bitwarden still might be better here. 1Password has been around for ages and people have been asking for a Linux client nearly since the beginning.

Re: 1Password for Linux beta

#112

The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…

I definitely have some password manager anxiety. I'm not too concerned about hacks or losing my password database. For me, it's more about the sense of independence, and being able to log in to my accounts using just my noggin. I might be able to remember one or two strong passwords, but not dozens, which is kind of the selling point of a password manager. I use KeePassXC with a password and key file. I sync the data…

The most important password is your e-mail. If you lose that then you can lose everything. It's the only password I don't save in a password manager.

Re: 1Password for Linux beta

#113

The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…

What's your baseline? While there are theoretically more secure alternatives to using a password managers, the vast majority of people don't have the discipline or skill to implement them effectively.

Password managers make security tradeoffs, providing a nice balance of convenience and defense against many of the most important attack vectors.

So while it of course possible to come up with basically endless possible attack vectors for password managers (and indeed all software), it is most likely not a productive exercise.

Also, a small tangent, but if someone compromises the play store and is able to install malicious software on your phone, there are plenty of ways for tmem to get your password that don't involve password managers.

Re: 1Password for Linux beta

#114

Earlier quoted context omitted.

You might want to look at KeepassXC.

That does not come with a simple way to have your passwords and automatically though. A better alternative in my opinion would be Bitwarden.

> That does not come with a simple way to have your passwords and automatically though.

I suspect a typo, but could you describe the problem in more detail? I'm using KeepassXC, and while there are a few challenges around workflow, there's nothing insurmountable.

Re: 1Password for Linux beta

#115
post #42

Earlier quoted context omitted.

Presumably the alternative to 'a password manager as a service' is 'a local password database and password manager which is not a service'. This can be something like password store, or keepass, where the attacker needs both your password database unlock key / gpg passphrase, but also needs access to the database / gpg keys, which means either physical access, or at least access to your local files. I think there is…

I've never used 1Password, but both LastPass and Bitwarden support hardware tokens like Yubikey for two-factor authentication. Keeping the encrypted store locally might give you some edge, but I personally need to be able to access secrets from more than one device, and once you allow external access then the advantage of your solution compared to hosted services disappears.

I don't think the advantage completely disappears.

Let's look at one possible attack: the attacker knows all my passwords, and they manage to steal my laptop from my car. What can they do in each scenario?

In the case of lastpass, bitwarden, or keepass, the attacker now has all my passwords. The 2fa token was used once in the past, so all the passwords are stored on the device, protected only by a password at most.

In the case of password-store with my gpg-private-key on the yubikey, the attacker still can't decrypt anything unless they also stole my yubikey, which I never leave unattended.

The fact that my private key on my yubikey isn't just required to sync or login (like it is for the 2fa case), but is rather where the actual decryption is done every single time I access a password, does have a difference.

I don't think the difference is very large though, no.

Re: 1Password for Linux beta

#116
post #108

Earlier quoted context omitted.

What if service goes away? Even if stand alone app vendor goes away, the app still works. There are things that I see are okay as a monthly service like Netflix or other content provider where the content is literally changing month to month. Stand alone software that rarely changes, like 1Pass, does not warrant a monthly service fee from me. I am self-hosting the content, so I don't need their cloud services.

Playing devil's advocate here, but the service fee (at least to my mind) is more for the maintenance & upkeep of the infra. I'd gladly move to self-hosting if it was only me. But after a few months, I was able to convince my wife to use it for convenience and security. So if there's an issue with the self-hosted version, it wouldn't just be me impacted, but my wife. And that's an SLA you don't wanna break. :D Also, w…

Haha, those are great points. However, if you make $50/hour and it takes any where close to an hour to install 1Pass, you're overpaid!! The install is super simple. Setting up the passwords is an ongoing thing and something I consider outside of the initial setup of the self-hosted version.

Re: 1Password for Linux beta

#117
post #34

I would like to throw out Bitwarden out there. Cross platforms, works on everything and can be self hosted if you so desire.

Agreed. I have been using Bitwarden for over 3 years now, paid premium user as well. No big issues, the odd bug a few times but all fixed promptly and didn't impact my ability to access my data. While the Bitwarden apps are not as "pretty" as 1Password's I find them a little simpler to use. Obviously UI design is highly subjective though so your thoughts may be very different :) Anyway yes I highly recommend Bitwarde…

While almost everything is great about Bitwarden, the 5-8 second delay when performing a search is ridiculous (considering I have about 100 records), and I'm considering paying for a better maintained alternative.

Re: 1Password for Linux beta

#118

The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…

It is a bit like eating self-made food or eat what others cook. You have chances to get poisoned in both ways. I would choose to eat food prepared by others if I am not confident in my cooking skills.

Re: 1Password for Linux beta

#119

The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…

> I also considered "offline" managers like KeepassXC, but synchronization gets way worse, and there's also the issue about trusting someone else with your mobile apps.

I'm using KeePassXC. Originally between three computers (Debian desktop, Debian laptop, and Microsoft laptop) where it was part of my git repo that I'd sync in between the machines as needed (git repo hosted within my own instance of gitolite, btw).

I've migrated more functionality into Syncthing - so now it's very rare that I ever need to do a manual merge within KeePassXC (which was always a robust operation anyway). KeePassXC has a setting to reload from disk if it sees that the password db file has changed, which makes this process seamless.

Part of my Syncthing setup is that I have a receive-only copy of my various repos on a Debian VM that runs a couple of archive tools (dirvish and borg) which provides for point-in-time restorations if needed.

So - I'm wondering what synchronisation problems you've had, and what you've tried. And what alternatives there are to trusting someone else's OS (replete with non-free components) on mobile, along with someone else's bundling of code into mobile packages?

There's a handful of keepass-compatible android apps, some of which are GPL, and Syncthing can keep a copy on Android easily enough, but ultimately there's a lot of trust in mobile land no matter how you slice it.

Re: 1Password for Linux beta

#120
post #94

Earlier quoted context omitted.

The only way to guarantee that your keyring is secure long-term is for the source code (and change history) of your password manager to be inspectable and verifiable. A promise made by a corporation is not sufficient. You can pay a corporation to buy a product with more features or better service. But you can't pay a corporation to hold or maintain a principle. There will always be someone who can offer them more mon…

And what makes you think that Jason or Raymond won't wake up one day and decide they had a change in principles? Just like people, companies have reputations and values. Individuals are not immune to malevolence.

Companies swap out their internal functionaries regularly, and regression to the mean suggests that as an organization they're likely to lose any principles they may have started with.

People can certainly lose their principles, but from observing past behavior (e.g. the number of times Raymond has told moneyed interests to fuck off), I believe that certain people are capable of holding certain principles for longer than a corporation would be able to.

Secondly, these individuals and communities recognize the inherent problem with needing to trust them, so they jump through hoops to make sure that publicly available binary builds are reproducible and verifiable. They publish their open-source software in a way that doesn't require you to trust them as much as you would need to trust a corporation with a closed-source product.

Not only do many corporations not bother doing this, many corporations that maintain open source products deliver binaries that obviously have more stuff baked in than their source code would suggest. For some categories of product, like a password manager, open source with reproducible builds is table stakes, not an optional feature.

Post reply on HN