Live data from Hacker News

1Password for SSH and Git (Beta)

developer.1password.com

191–200 of 406 posts

Re: 1Password for SSH and Git (Beta)

#191

Earlier quoted context omitted.

Not really. Do you think the ssh client machine is easier to secure than the ssh server? (It isn't.)

It objectively is since I never transmit the private key bits to the server. Passwords usually require the whole secret be blasted about the Internet (albeit encapsulated in TLS, usually).

Hint, the server won't be the hostile party stealing your keys here. Neither will be your ISP.

Re: 1Password for SSH and Git (Beta)

#192

A huge problematic deficiency of 1Password is that it lacks literal multi-line text field types. The items in its database let you define custom fields for them, but there is no literal multi line text field. There's a "File" type, but you can't simply define fields with multi-line text values. However, every item has exactly one built-in "notes" field, but that's actually styled markdown text. And you only get one.…

Then why not file attachments? You may want to store a JPEG there too, for some reason.

Re: 1Password for SSH and Git (Beta)

#193

A huge problematic deficiency of 1Password is that it lacks literal multi-line text field types. The items in its database let you define custom fields for them, but there is no literal multi line text field. There's a "File" type, but you can't simply define fields with multi-line text values. However, every item has exactly one built-in "notes" field, but that's actually styled markdown text. And you only get one.…

A paying customer for 5+ years, still miss this feature daily.

Re: 1Password for SSH and Git (Beta)

#194

Ummm, no. No need for even more in-between software prompting for passwords. I’m sticking with certificate+publickey SSH

The point behind all ssh-agents is to prevent any application with access to ~ being able to read your ssh key and exfiltrate it somewhere, or simply using it to drop malware on hosts listed in your ~/.bash_history. If it's in an agent and that agent requires user interaction before it performs SSH logins, you'll be made aware of the malicious activity.

Re: 1Password for SSH and Git (Beta)

#195

Earlier quoted context omitted.

Could you share a little bit about what you'd want to use this for? (I'm part of the 1Password design team)

SSH keys have both a private and a public file. The private file is multi-line text. I don't like putting the private key in the notes field, because its name is still "notes" (but I'd prefer the label be the key's file name), it's actually markdown formatted text, not literal text, and what if I still want to write a note, but I've already used the notes field for the key? HTTPS certificates including multiple certi…

Maybe a solution would be to get inspiration from keepass(xc) attachement's feature. It allows you to save abitrary files as attachement to an entry (btw this is how keepassxc does ssh key managment). Other keys/ certs (like HTTPS certs) would be supported such a feature too.

The 'only' downside is the comparatively high increase in database size for the hoster.

Re: 1Password for SSH and Git (Beta)

#196

A huge problematic deficiency of 1Password is that it lacks literal multi-line text field types. The items in its database let you define custom fields for them, but there is no literal multi line text field. There's a "File" type, but you can't simply define fields with multi-line text values. However, every item has exactly one built-in "notes" field, but that's actually styled markdown text. And you only get one.…

Then why not file attachments? You may want to store a JPEG there too, for some reason.

I guess because you have to extract it to local file system in order to use it and that makes it exposed.

Re: 1Password for SSH and Git (Beta)

#197

Earlier quoted context omitted.

Memory is not a precious resource, this narrative needs to die an unceremonious death. This isn't the 90s, we live in the future.

Anyone with a system that is running full of Electron apps knows how awful it adds up and how slow they are. Sure just 1 app makes hardly a difference. But I have 16GB of RAM and it gets awfully slow very fast with all that electron mess.

Anyone? I am a member of that set and I will report it is not “awful” at all.

I use 5-7 Electron apps on a daily basis and not even once have I had anything resembling memory issues. Nothing gets slow, nothing becomes unusable.

Re: 1Password for SSH and Git (Beta)

#198

A huge problematic deficiency of 1Password is that it lacks literal multi-line text field types. The items in its database let you define custom fields for them, but there is no literal multi line text field. There's a "File" type, but you can't simply define fields with multi-line text values. However, every item has exactly one built-in "notes" field, but that's actually styled markdown text. And you only get one.…

Could you share a little bit about what you'd want to use this for? (I'm part of the 1Password design team)

I know HN probably isn't representative of the population, but I imagine we skew heavily on the technical side of this and I would echo OP's suggestion. It would be very helpful for many developer and potentially other use cases as others have made a case for.

Re: 1Password for SSH and Git (Beta)

#199
post #118
post #102

Earlier quoted context omitted.

I agree. They disabled 1Password for Firefox on iOS and force users to use safari with 1Password extension. Before you could access it through share menu and get forms filled out, but they removed that feature. Reached out to support regarding that and their answer was just to use safari.

I use iOS, Firefox and 1Password to fill out passwords regularly. I just logged out of HN and back in on my iPhone just to test. Is there certain versions that this affected?

Firefox for iOS apparently.

[UPDATE] although reading the replies, it looks like that appears to work. Can’t confirm as don’t use Firefox on iOS.

Re: 1Password for SSH and Git (Beta)

#200

Earlier quoted context omitted.

Memory is not a precious resource, this narrative needs to die an unceremonious death. This isn't the 90s, we live in the future.

Please elaborate to those of us who have actually experienced the “swap swamp” within the last year, in the 2020s, and who have enough systems knowledge to properly instrument this stuff. Are you gaslighting us?

No post body was provided.
Post reply on HN