Live data from Hacker News

On Password Managers

tbray.org

181–190 of 347 posts

Re: On Password Managers

#181
post #33
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

> I recommend 1Password, and there's currently no other commercial password manager that I recommend. Are there any open source password manager products that you would recommend?

As a 1Password customer who's been pretty unhappy with how the company took my money for a full version and has, since, been pushing me towards a subscription (making the non-subscription version/features harder to find, no Windows version, etc), I'm seriously considering switching over to Enpass [1]. The UI is pretty similar to 1Password and most of the features are there. It can sync with Dropbox and a few other cloud storage services and their monetization strategy seems pretty reasonable (desktop is free, mobile costs $9.99). I'd encourage any disgruntled 1Password users to give it a test drive.

[1] https://www.enpass.io/

Re: On Password Managers

#182
post #18

Earlier quoted context omitted.

Lastpass doesn't necessarily have the best track record, and you said you couldn't go into detail, but I'm curious so will ask - if you feel comfortable sharing, what securities issues do you see with lastpass besides storing secrets in some companies cloud?

By default the browser plugin is configured in such a way that 2FA is completely bypassed for a second when logging in. This is officially documented, so we can likely assume that it will never be fixed. https://lastpass.com/support.php?cmd=showfaq&id=2775

Well. Not to defend LP, but for those who don't click through, offline mode can (and should be?) disabled.

Perhaps this is a case where a feature that makes some sense in some cases was added, the problem is, outside that scope it's a really bad idea. But then someone said "We'll make it optional..." and the rest was history?

Re: On Password Managers

#183
post #180
post #100

Earlier quoted context omitted.

I use pass, written by zx2c4 of WireGuard fame: https://www.passwordstore.org/ My favorite thing about it is that it uses standard tools I understand, and I can back it up and version it with git.

It doesn't have a browser plugin and will not work with my iPhone... So it's a no-go for me and I guess many others.

pass has a variety of 3rd party browser plugins and phone apps that work with it. Admittedly, it's not a turnkey solution and so is unsuitable for a non-technical audience.

I recommend website-based password managers to my non-technical friends because they're easiest to use and therefore most likely to actually BE used, and the security vulnerabilities noted in the article are very small compared to not using a password manager at all.

Re: On Password Managers

#184
post #145

I've moved from LastPass to KeePass, but the biggest thing I miss from LastPass (other than the better browser integration) is a good CLI client. Lastpass-cli is great, and kpcli just isn't. Anyone have a recommendation for a good CLI client that isn't `pass`? (I don't want to deal with GPG)

Pick[1] is a CLI password manager that I've been working on for a couple years. There is no browser or mobile support, however. [1] https://github.com/bndw/pick

Nice! Looks similar to Seal [1] (also written in Go). I just added a link to Pick under related work.

[1] https://github.com/davidlazar/seal

Re: On Password Managers

#185

Just to be clear, it's still 100% possible to keep your 1Password vault in Dropbox etc and not use the SaaS version [1]. I felt like this fact was buried in the article. Edit: Here's the link to buy the standalone license [2] which is hard to find on the site now. In a post from the founder one week ago [3] he said, "We know that not everyone is ready to make the jump yet, and as such, we will continue to support cus…

On the other hand, the fact that they're saying not everyone is ready "yet" seems to imply that they expect to eventually migrate everyone off standalone vaults.

This is an important point. I think 1Password folks need to hear that for a lot of customers, it will never be the case. There are many of us that consider managing the storage of our vaults as a fundamental safety feature of a password manager and will never cede control over that function to the company behind our password manager. Moreover, subscription pricing is a no-go for many of us. The possibility that a company will cease operations and the software will cease to function makes this kind of pricing a non-starter for something as crucial as password management. I'm perfectly happy to continue paying for major releases and will always upgrade provided the added features are compelling. But every version I purchase should work in perpetuity and should come with bug fixes, especially if vulnerabilities in the product are found. I don't think I'm being unreasonable.

I love 1Password, but I hate their move towards being a service. There are alternatives that, while possibly not as good/polished, will allow me to continue to manage the password storage the way that I currently do and will continue to work, as is, for as long as I choose to use the software. Using them is a compromise I can make. Having a subscription password manager is not a compromise I can make.

Re: On Password Managers

#186

Earlier quoted context omitted.

Generally speaking, when a vendor want more money to do less, it's time to get a new vendor.

In what way are they doing less?

They are deprecating local vaults.

Given that vaults contain secrets, and data shared with third parties is not secret in any legally compelling way, that effectively neuters the product.

Re: On Password Managers

#187

Earlier quoted context omitted.

Generally speaking, when a vendor want more money to do less, it's time to get a new vendor.

In what way are they doing less?

Generally speaking, security solutions have (at least) two goals that are often at odds with each other: (a) Minimize the number of trusted third parties / components, (b) stay out of the way from a usability perspective.

Most negative comments here imply that 1password severely compromised (a), to the point of making it useless, in exchange for incremental-to-zero gains in (b). For most people here, using a third-party sync service is probably more convenient than avoiding whatever mass-market-cloud-thing 1password is trying to move everyone to.

(I haven't used 1password, but am planning to switch to some other password manager, and this article just knocked 1p off my list of candidates).

Re: On Password Managers

#188
post #33

Earlier quoted context omitted.

> I recommend 1Password, and there's currently no other commercial password manager that I recommend. Are there any open source password manager products that you would recommend?

As a 1Password customer who's been pretty unhappy with how the company took my money for a full version and has, since, been pushing me towards a subscription (making the non-subscription version/features harder to find, no Windows version, etc), I'm seriously considering switching over to Enpass [1]. The UI is pretty similar to 1Password and most of the features are there. It can sync with Dropbox and a few other cl…

Have you put much energy into making sure that Enpass is secure? Do you know who's reviewed it, and what their review looked like?

It bothers me when people point to other password managers as alternatives to 1Password because of packaging and pricing issues. It's easy to find other commercial password managers that have attractive packaging and pricing! That's not the hard part!

I happen to like 1Password as a product, but that's not why I recommend it.

Re: On Password Managers

#189
post #83
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

How do you feel about in-browser password managers--Chrome in particular?

The Chrome people, who I respect, recommend it.

But Steve Thomas, who I also respect, has a lot of specific bad things to say about it.

I don't think it will destroy you. But it is not my first choice.

Re: On Password Managers

#190
I've never seen a corporate post with more comments by employees than the one where 1Password tries to explain their subscription model [1]. It makes it looks like they want to bury non company comments.

And I am a current 1Password customer and had been for years, but that post doesn't inspire confidence in me.

[1] https://blog.agilebits.com/2017/07/13/why-we-love-1password-...

Post reply on HN