Live data from Hacker News

On Password Managers

tbray.org

171–180 of 347 posts

Re: On Password Managers

#171
I'm glad to see this getting more attention because it has been brewing for months and 1Password is essentially doing what they promised they wouldn't - forcing users to the subscription/online model my phasing out support for local vaults.

I'm not mad at the subscription. I'd pay them the few bucks a month happily for what is an excellent application cross-platform. I AM mad at the forced cloud sync.

My current plan is to keep using 1PW 4 on Windows as long as possible and then re-evaluate when I absolutely have to. KeePass is a close alternative, but nowhere near as polished at this point.

Re: On Password Managers

#172
post #157
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

> 3. They're promoting cloud vaults and hiding local vaults, and the Windows version of 1Password has apparently never used local vaults. Windows had local vault, I used the local vault version synced via dropbox for years.

[deleted]

Re: On Password Managers

#173
post #161

Earlier quoted context omitted.

How could that possibly happen? Local vaults can't just silently turn into cloud vaults, Why not, all they'd have to do is copy the local vault to their cloud service and you'd never notice until you discover that the local file you're syncing somewhere else no longer contains your new passwords. I'm not saying they've done this, but they could.

You have to explicitly sign up for their subscription service, so no, it can't currently be done silently.

You're confusing "they don't do that" with "they can't do that".

Their terms of service appears to specifically allow this:

You agree to grant AgileBits, Inc. a license to store, retrieve, backup, restore, and otherwise copy Your Data so that we may provide you with the Service.

Re: On Password Managers

#174
post #75

Earlier quoted context omitted.

No. The alternative sync options are for "If you don’t want the benefits of a 1Password membership", and a "team" or "family" account is by definition a 1Password membership.

Is 1Password membership not inclusive of advanced sync options? edit: I thought it was, but not sure.

Yes, you can make/use local vaults (and sync them e.g. using Dropbox) on iOS/macOS with a membership. Open 1Password, then "Preferences -> Advanced -> Allow creation of vaults outside of 1Password accounts".

Also see: https://discussions.agilebits.com/discussion/comment/316463/...

Re: On Password Managers

#176

I'm a 1Password user, and have synced my vault between devices through both Dropbox and iCloud at various points. I can't help but feel like either there's something I'm missing or something everyone else is missing, which statistically means that it's most likely me. But: When I sync with iCloud, Apple can't read my vault--even though it's on their servers, it's strongly encrypted with my passphrase, and the encrypt…

I think there are two concerns: 1. Accessing 1password.com's from a browser is less secure than using an app. You can choose never to log in but it makes it harder to recommend 1Password to journalists, political dissenters, etc. The most paranoid people need a local vault option. 2. The 1password.com can change to work differently from Dropbox at any time. 1Password for teams already allows recovery without your mas…

The other major concern would be that you are moving your trust in the security of your data from very large companies that have staff in place to maintain such security as well as an established track record of offering service in the wild to a much smaller company with much less of a track record.

Re: On Password Managers

#177
post #22

Just to be clear, it's still 100% possible to keep your 1Password vault in Dropbox etc and not use the SaaS version [1]. I felt like this fact was buried in the article. Edit: Here's the link to buy the standalone license [2] which is hard to find on the site now. In a post from the founder one week ago [3] he said, "We know that not everyone is ready to make the jump yet, and as such, we will continue to support cus…

Given the change to their business model I am concerned they can push an update, where the next time I unlock my vault it syncs my master password and/or decrypted vault to their cloud. Maybe time for an open source password manager?

There are lots of them out there to choose from. And being able to audit the secure portions is great, but a password manager is the perfect example of what free solutions often don't do well— you need to have a seamless experience across multiple platforms including mobile, and you need to have fairly deep integrations into multiple web browsers, which are notoriously fickle and need to be tracked closely.

The killer feature of 1Password (on Android at least) is that it comes up as a keyboard and can type long passwords into any apps. That seems like exactly the sort of fussy integration that would be really hard to build and maintain in something without commercial backing.

Re: On Password Managers

#178
Question: When you add additional hardware (e.g., Yubikey) how does that effect the integrity (?) of your PWM (e.g., LastPass)?

I'm comfortable (in a I have no choice sorta way) that there is always some risk. Therefore, my next best choice is to mitigate that risk as much as possible. Obviously nothing is perfect, but it seems that using a Yubikey (or similar) raise the bar pretty high.

Yes? No?

p.s. Does anyone know of the legal implications of a Yubikey? That is, can a court order you to turn it (and PW) over? Or is there some protection from such things?

Note: I'm not doing anything nefarious. I'm just wanting to lower my sec risks, as well as maintain a respectable level of digital liberty.

Re: On Password Managers

#179

Earlier quoted context omitted.

Keepass and its various forks are open source. Keepass itself uses dotNet so Linux guys need mono which not all people like. Those people use KeepassXC (a fork of KeepassX which is Keepass in C++ and is unmaintained). I use Keepass. Reasonable security but ugly gui in linux due to mono. Has plugins. Completely offline.

Have you used KeepassXC. I am panning to move to it from lastpass, and want to make sure I am making the right choice.

What's making you want to move?

Re: On Password Managers

#180
post #100
post #33

Earlier quoted context omitted.

> I recommend 1Password, and there's currently no other commercial password manager that I recommend. Are there any open source password manager products that you would recommend?

I use pass, written by zx2c4 of WireGuard fame: https://www.passwordstore.org/ My favorite thing about it is that it uses standard tools I understand, and I can back it up and version it with git.

It doesn't have a browser plugin and will not work with my iPhone... So it's a no-go for me and I guess many others.
Post reply on HN