Live data from Hacker News

Introducing 1Password for Teams

blog.agilebits.com

131–140 of 151 posts

Re: Introducing 1Password for Teams

#131

Earlier quoted context omitted.

It's more of a threat to us than you describe. If a potential team of N people have k members who need a Linux client, then that might cost us N customers, not just k.

Yes. We are a team of 3 and one of us uses Linux. What is missing when using the web app? Is there a feature comparison I can look at?

There's a fair bit missing. For now, the web client is read-only but we have full intention to make it able to edit, it just wasn't something we had time to do before the public beta.

The app also includes filling directly into webpages (via a browser extension) so you don't need to copy and paste. This also includes the ability to save new logins as you create accounts. Filling Credit Card and Address information as well.

Those are the two big features I think. The editing will show up on the web side but the filling part won't since it relies heavily on the client applications to do a great deal of the grunt work.

We're well aware of the demand for a Linux client though. I think all of us on the team would love to see a Linux client, but "love to see" isn't enough to make it happen right now.

I have most certainly written about this in my report I hope to send up the chain today so your voices aren't going unheard.

Kyle

AgileBits

Re: Introducing 1Password for Teams

#132

How does revocation happens? What happens if I remove a user from the team?

When you remove a user from a team (or even a vault) the vault or team is effectively removed from the user's computer. The account will still "exist" in the preferences but it'll be suspended and their only option is to delete the account or have the admin restore the account.

Given the nature of passwords, if you've removed someone from the team you'll still want to change passwords for any items they have had access to if that's a concern.

Does that help answer your question? I'm happy to give you more information if you have more questions or if I somehow misunderstood your question. Just let me know!

Kyle

AgileBits

Re: Introducing 1Password for Teams

#133
post #74

Earlier quoted context omitted.

Sorry you were less than impressed. We can't really discuss future plans, but we are working to mature the 1Password for Teams web client into a fully functional client that can add, edit, and delete items. The whole thing is still in beta right now, but it's definitely on our must-do list. The web client runs in Chrome, Firefox, and Opera, so Linux users will definitely be able to access it there. That's our immedia…

Actually, now that I think about it, why on earth can't you discuss future plans?

Duncan, the reason we try not to discuss future plans is because until something ships we can't 100% for sure it'll make it into the wild. We've had instances in the past where we discussed future plans and due to unforeseen issues couldn't follow through with them.

The mantra is more "under promise and over deliver" when it comes to these types of things. One of the sayings that has lived long in AgileBits (at least since I've joined nearly 4 years ago) is that no decision is ever final. So we might tell someone "nope, sorry won't happen" but then it could later, or vice versa.

So, future plans are something we try very hard not to discuss, and if they're ever discussed it's often by our CEO or founders :)

It's because we respect our customers that we do this. We don't want to lead someone on or misrepresent our intentions. Though, I can certainly understand how it might feel like we are avoiding the issue, we're not, we'd love nothing more than to tell everyone "yup, that's coming!" but reality is much different so we want to make sure we do our best by coming in level headed about things.

Hope that helps explain things a little at least.

Kyle

AgileBits

Re: Introducing 1Password for Teams

#134
post #132

How does revocation happens? What happens if I remove a user from the team?

When you remove a user from a team (or even a vault) the vault or team is effectively removed from the user's computer. The account will still "exist" in the preferences but it'll be suspended and their only option is to delete the account or have the admin restore the account. Given the nature of passwords, if you've removed someone from the team you'll still want to change passwords for any items they have had acce…

Thanks for the explanation!

While in theory the passwords should be changed, but shouldn't a new vault key also get generated/encrypted and the existing passwords get re-encrypted with the new vault key?

The case I was thinking about is: If for whatever reason that revoked user got access to an encrypted password that got added after he was revoked, he can still use the same vault key to decrypt it.

On a different note, I was trying to understand the granting access part and so far (correct me of I am wrong :)) I think it has to be done in a 3-stage process. 1. invite user, 2. user accepts and generates priv/pub and pushes encrypted priv + pub to 1password, 3. admin confirms the grant by encrypting the vault key with the new user's public key. Did I get it right?

Lastly, would it be more secure if instead of using a master vault key just rely on priv/pub key of each user. When one member adds a new password, they encrypt it with each user's public key and provide it to them (can be considered as a big disadvantage to this approach). I think it makes revocation easier and denies access to future passwords since the user will be out of the team and won't receive new passwords created. But I am not a security expert, so I won't claim anything. :)

Re: Introducing 1Password for Teams

#135
post #129

Earlier quoted context omitted.

I was thinking tighter integration than that. Imagine if ssh private keys could be stored inside 1Password. It would become a ssh-agent replacement. No real reason to leave ssh private keys scattered on different user directories anymore.

I actually had this idea back when I first started at AgileBits and had to really start maintaining ssh keys for work purposes. Prior to that it was mostly just side projects and my own personal stuff. Maybe we'll have to kick this one in the pants and see what we can do. No promises of course but I'll be passing this along again since I have a personal investment in that idea :) Kyle AgileBits

=)

I'm the technical head for our cloud business so I've got some pretty specific ideas on how to make this more useful from a day to day operational standpoint (multi-tenant infra support has lots of interesting use cases).

Feel free to ask if you want more input.

Re: Introducing 1Password for Teams

#136
post #39

Earlier quoted context omitted.

Not really a threat -- if they don't provide Linux support, then they know and accept already that people running Linux won't buy or recommend it.

It's more of a threat to us than you describe. If a potential team of N people have k members who need a Linux client, then that might cost us N customers, not just k.

In fact, probably the guy responsible for storing most passwords is your friendly sysadmin, and a lot of them won't get caught using a GUI on Mac or Windows ;)

Re: Introducing 1Password for Teams

#137
I work for a password manager that has had teams for a while. We have an encryption key per record with fast search. An open source command line SDK and Java desktop client which is great for linux. A great Android app with autofill, material design UI (more to come), which has been in the Google Play store since day 1, etc.

I'm obviously biased especially about the Android client :) but IMHO great iOS (and SDK), Android, Web Vault, browser plugins, Windows Phone, Surface, etc.

Re: Introducing 1Password for Teams

#138
post #69

Maybe I'll be the only 1Password fanboy in here. I use 1pw personally and LastPass for work (shared between team of a dozen or so technicians). To compare the two - 1pw is basically one of my favorite programs. LastPass is um... adequate? We have a lot of items in our LastPass vault and anytime we search it, add or change an item there is a 5-10 second lag. This according to LastPass support is unavoidable. Something…

Unfortunately 1pw is absolutely terrible on Android. So I was forced to switch to Lastpass even though 1pw is generally superior because I need something that works on all my devices.

Hi - have you tried Keeper? We have 9M users - and as a benefit for someone like you we're platform-wide with native apps across all OS's, devices and browsers - our users love our Android experience. www.keepersecurity.com

Re: Introducing 1Password for Teams

#139
post #25

Interesting - lack of active directory integration, and lack of on-prem solution is disappointing though. Edit: since someone is apparently upset over my comment - those two features are absolutely mandatory in almost all corporate environments. If you have a comment to the contrary, feel free to share it. Don't just downvote my comment because you don't personally need the features.

Have you tried Keeper Enterprise? We have AD/LDAP integration - it was a mandatory feature for us too. In regards to on-prem, Keeper uses zero-knowledge encryption - which means the encryption keys are stored locally on the end-user device. We have over 3k businesses signed up, many of them in the Global 2000 (and 9M consumer users). Our enterprise customers are happy with our cloud architecture because of the zero-knowledge encryption and regular SOC-2 audits.

Re: Introducing 1Password for Teams

#140

Earlier quoted context omitted.

Ah, that is better. No promises (and nothing in the immediate future), but this does certainly remain in the realm of possibilities. I don't want to speak for the down-voters (I'm not one of them and I think your comment is was a valuable contribution), but when I first saw AD integration requests I assumed that people wanted AD managed Kerberos authentication to 1Password for Teams; and so imagined delegating 1Passw…

No, not delegated auth although 2 factor might be nice. Delegated user admin/sync would be what I'm looking for. Centralized user management along with RBAC makes it much easier to set policy.

Check out Keeper Enterprise. We have delegated auth, 2 factor, AD/LDAP sync and centralized user management with a policy engine. And much more :)
Post reply on HN