Live data from Hacker News

1Password for Linux beta

blog.1password.com

191–200 of 254 posts

Re: 1Password for Linux beta

#191
post #81

I would like to throw out Bitwarden out there. Cross platforms, works on everything and can be self hosted if you so desire.

Bitwarden is great, but I'm getting frustrated at their ridiculous excuses for not implementing fixes. For the longest time bitwarden has been broken in the firefox's private browsing after mozilla deprecated some apis due to security concerns. They've given alternatives but they are just refusing to fix it, to the point of basically saying mozilla needs to fix the issue. What's sad is a similar mechanism is used in…

Just so you're aware, it's a limitation within Firefox and Private mode - not Bitwarden.

```

The Bitwarden browser extension does not completely function in Firefox’s private browsing mode. This is a known issue specific only to Firefox. You will see a message indicating so when you try to open the Bitwarden popup window in a private window. We have discussed the problem with Mozilla, however, they seem unable to fix it so that extensions like Bitwarden can function entirely in private mode. ```

https://bitwarden.com/help/article/extension-wont-load-in-pr...

Re: 1Password for Linux beta

#193
post #114

Earlier quoted context omitted.

> That does not come with a simple way to have your passwords and automatically though. I suspect a typo, but could you describe the problem in more detail? I'm using KeepassXC, and while there are a few challenges around workflow, there's nothing insurmountable.

Yeah, I wanted to write that it does not come with a simple way to sync passwords. Simple as in you type a password and it is synced, instead of having to manually copy the file to each location. Definitely not insurmountable and I used that system for a while as well, but something like Bitwarden, which I now use, is just easier.

Gotcha.

I guess for most of us on HN the big delineation is -- can you sync your password store easily (and exclusively) to your own systems, vs can you sync easily with a remote managed service.

I'm very much in the camp that eschews the latter.

As per my comment elsewhere in this thread, I've got a reasonably robust arrangement using a combination of Syncthing and KeePassXC, which so far has worked well for me.

Re: 1Password for Linux beta

#194
post #182

> A true Linux app Electron apps are not true Linux apps, maybe for ChromeOS they can be considered as such.

When I read that I had a suspicion that it was going to be electron. It takes some gall to write that heading. Disappointing, 1Password!

I already have a browser installed and WebWidgets support on Gtk and KDE, no need for having a bundled browser with each application.

Want to do a native Linux app with Web stack? Easy, do it like in the old days, start a daemon and use the local browser.

Naturally this makes it harder, because now they would need to worry about Web standards instead of ChromeOS APIs.

Re: 1Password for Linux beta

#195
post #126

I've been using gnupass for a few years after using LastPass. I couldn't be happier. I control the codebase and all changes made to my password store via my gpg key. It's easy to use, easy to store on multiple repositories.

I have been using lastpass for more than 10 years and honestly I do enjoy the ease of use. for example biometrics on the phone. Should I switch? is it worth the time investment.

Re: 1Password for Linux beta

#196
post #36

Uses Electron. What a shitshow. Edit: I checked: neither the macOS nor Windows version uses it. So it's not even that they think Electron is acceptable for high-quality desktop apps. They just don't consider Linux important enough to make a high-quality app for it.

Out of curiosity, what are the aspects of quality you'd be missing out on in an Electron app that you would find in a fully native app?

Re: 1Password for Linux beta

#197
post #69

I would like to throw out Bitwarden out there. Cross platforms, works on everything and can be self hosted if you so desire.

Not knocking the project, which sounds cool, but the absolute last thing I want to self host is a password database exposed to the internet. Hard pass on that element. 1password used to have a peer to peer sync mode that I loved. No need for a server anywhere. You would open it on your Mac and then open it on your phone and if they were on the same network they would self discover. Too inconvenient, perhaps, for most…

> Not knocking the project, which sounds cool, but the absolute last thing I want to self host is a password database exposed to the internet. Hard pass on that element.

I have the exact opposite feeling. I would not selfhost email but I would selfhost a password manager and my files behind WireGuard, like many have said.

I have almost moved from cloud hosting to home server. This perfectly reasonable for non critical services that don’t require more than 90% availability. The simplicity of such a setup nowadays is a breeze of fresh air. Debian stable, WireGuard, syncthing, ssh, git, ... all are low maintenance and works fine with Linux and iOS clients.

Re: 1Password for Linux beta

#198
post #119

Earlier quoted context omitted.

> I also considered "offline" managers like KeepassXC, but synchronization gets way worse, and there's also the issue about trusting someone else with your mobile apps. I'm using KeePassXC. Originally between three computers (Debian desktop, Debian laptop, and Microsoft laptop) where it was part of my git repo that I'd sync in between the machines as needed (git repo hosted within my own instance of gitolite, btw). I…

Yes I always wonder why keepassxc does not get mentioned more when password managers come up. It's really an excellent piece of software. Some of the features that are crucial for me: 1. ssh-agent support 2. Browser plugins 3. Can provide secret service (i.e. be a substitute for gnome-keyring and kwallet) 4. Excellent oss android client 5. Absolutely snappy, starts in an instant, compared to electron apps it's like d…

What Android client do you use if you don't mind me asking?

Re: 1Password for Linux beta

#199
post #81

Earlier quoted context omitted.

Bitwarden is great, but I'm getting frustrated at their ridiculous excuses for not implementing fixes. For the longest time bitwarden has been broken in the firefox's private browsing after mozilla deprecated some apis due to security concerns. They've given alternatives but they are just refusing to fix it, to the point of basically saying mozilla needs to fix the issue. What's sad is a similar mechanism is used in…

Just so you're aware, it's a limitation within Firefox and Private mode - not Bitwarden. ``` The Bitwarden browser extension does not completely function in Firefox’s private browsing mode. This is a known issue specific only to Firefox. You will see a message indicating so when you try to open the Bitwarden popup window in a private window. We have discussed the problem with Mozilla, however, they seem unable to fix…

"By contrast, I was a 1Password customer at the time this change got introduced, and they'd pushed out a fix not long after."

Re: 1Password for Linux beta

#200
post #94

Earlier quoted context omitted.

The only way to guarantee that your keyring is secure long-term is for the source code (and change history) of your password manager to be inspectable and verifiable. A promise made by a corporation is not sufficient. You can pay a corporation to buy a product with more features or better service. But you can't pay a corporation to hold or maintain a principle. There will always be someone who can offer them more mon…

You can absolutely pay a company to hold a principle. Consider the number of companies now who are promoting sustainability as a core value, because it gives them an edge up on competition in big government tenders. More common than you'd think, especially in physical product supply!

> who are promoting [...] as a core value

> because it gives them an edge up on competition

That's... literally the opposite of holding a principle. They're doing a thing that they don't otherwise care about because it results in an advantage today. What happens when the money runs out? When the fad shifts? When someone offers them more money to do something that conflicts with this principle?

You hold a principle because you believe (logically, axiomatically, morally, etc.) that it is correct, regardless of all other incentives that might pull you towards or away from it.

If the only reason that someone claims to hold a principle is because you're paying them, they're not actually holding that principle.

Post reply on HN