I’d ultimately prefer to host my own 1Password server at home if there was an option though, data ownership is an increasingly difficult thing to achieve.
1password is considering a self-hosted option to store vaults
211–220 of 228 posts
Re: 1password is considering a self-hosted option to store vaults
#212Semi-related: this survey was announced alongside 1Password 8 for Windows early access. Apparently 1Password 8 for Windows uses Electron and there was some discussion about AgileBits wanting to move to the same architecture on all platforms. Does anyone know if 1Password 8 on macOS will also be an Electron app? Their Linux Electron app is pretty good and definitely much better than having no 1Password at all. However…
Re: 1password is considering a self-hosted option to store vaults
#213Earlier quoted context omitted.
Nope. "Password Storage" should not be a business that exists in the form of "if you don't pay for good password storage, you're not allowed to have it." Especially if it involves storing your password with a third party. The technology to store passwords safely has a marginal cost of zero (it's software). People storing passwords in third party places increases the threat surface, always. Finally, it's "ecological"…
What's your alternative?
Though there's enough potential public harm such that looking at "public health" models is not a bad idea. Most places you don't have to pull out your wallet to get a Covid vaccine, you shouldn't have to pull out your wallet to get good password safety, for roughly the same reasons -- the harm from one "infection" can spread quickly.
Re: 1password is considering a self-hosted option to store vaults
#214Earlier quoted context omitted.
You can self-host vaultwarden (formerly bitwarden_rs), which gives full enterprise functionality.
You can indeed, but only if you accept what follows. You will be in charge of maintaining critical infrastructure, as well as keeping it safe from attackers. My biggest complaint about the 1Password8 situation is that i've been "self hosting" version 7 for years using iCloud sync, and it has worked perfectly. I have my 1Password vault on every device for "free". With family sharing in iTunes, i had it for every famil…
Having said, I'm all for self-hosting and I hope it continues to become prevalent.
Re: 1password is considering a self-hosted option to store vaults
#215They made the standalone license almost impossible to find and get, forced a subscription on users, and made the password vault storage online for the subscriptions. Now this self-hosting survey comes as a surprise, and it would be of some relief if/when it’s implemented. I do wonder how the licensing and pricing will be handled though. Bitwarden officially allows self-hosting for the personal use tiers, but it seems…
Re: 1password is considering a self-hosted option to store vaults
#216Earlier quoted context omitted.
> If you don't trust the vendor, don't let them handle your passwords, obviously. The problem is you not only have to trust your vendor today , but you also have to trust them tomorrow . Every vendor is one acquisition or compromised senior executive or engineer [1] away from becoming untrustworthy even if they started out being perfectly trustworthy. Assessing present trustworthiness is hard enough. Assessing future…
Right, but this applies to big piles of security-critical software in general - a near tautology. It's really an argument in favour of my position that neither open-sourcedness nor hostedness are useful criteria in evaluating the security and fitness-for-purpose of a password manager.
Re: 1password is considering a self-hosted option to store vaults
#217Earlier quoted context omitted.
I don’t really think $8/user/mo for Business is overcharging compared to Slack which quickly gets into $30+ per user per month in larger shops where Enterprise Grid is required for its features. By your argument why can’t I buy that and self-host it too, decide if I want to upgrade for more features myself? I also think $5/mo for 1Password for Families is incredible value. Zero regrets on paying for this because it m…
Can you elaborate on: >enabling TOTP (sharing of code generation) on many sites we use Are you generating TOTP codes via 1Password or something? That seems like a degradation of security. I did a cursorary search and didn't find mention of 1Password providing such a "service".
It isn’t a degradation of security, in my opinion, it’s an upgrade, when certain accounts are involved.
For these shared accounts, such as those used by my family, and on services which don’t support account-per-person in an “organization” or “household” sense, this still provides for TOTP in a way my spouse and I can both login. Ensuring just the loss of the password isn’t enough to compromise the account is an upgrade vs. not having TOTP enabled.
Where we can both have our own accounts and use U2F tokens that’s a better story, clearly, but 1Password having this functionality is great!
Re: 1password is considering a self-hosted option to store vaults
#218I've never understood why anyone who takes security seriously would even consider a non-self-hosted (and non-open-source) password manager, especially after the recent Apple shenanigans. If it's not open-source and self-hosted then your security is entirely dependent on the good will of your provider. If they decide to screw you, they can. And it's not just the good will of the people running your provider today that…
Because they put their effort for their reputation and pays millions to hire people to look after their security. If the "good will" is making them money, I guess you can count on it. And you think your own hosted version that you're only looking after is that much better?
On that view, they should be willing to sell your passwords to anyone willing to pay them more than you are.
> And you think your own hosted version that you're only looking after is that much better?
Yes. Because I know that I won't sell to the highest bidder.
Re: 1password is considering a self-hosted option to store vaults
#219Earlier quoted context omitted.
It'd be ideal if browsers offered standard hooks into their password-filling mechanisms. Let the password managers volunteer "I know a password for this site!" and fill it through the browser's standard UI. Basically, I want the browsers to implement something close to what Apple has for password management on iOS. Ideally go a bit further and expose hooks for creating/saving a new login, too. Unless they already do…
That's an amazing idea! Do you know if any browser vendor has this concept even in the radar? It would be very cool that password managers were able to do that: manage passwords , and not have to deal with each browser's idiosyncrasies which if you think about it, is just a distraction from their actual mission of being a password storage.
Re: 1password is considering a self-hosted option to store vaults
#220Earlier quoted context omitted.
You can indeed, but only if you accept what follows. You will be in charge of maintaining critical infrastructure, as well as keeping it safe from attackers. My biggest complaint about the 1Password8 situation is that i've been "self hosting" version 7 for years using iCloud sync, and it has worked perfectly. I have my 1Password vault on every device for "free". With family sharing in iTunes, i had it for every famil…
Totally agree, and I notice a lot of people just blindly go down the hosting Vaultwarden route. There's a trade-off that everyone needs to consider, and much of it depends entirely on their skill level. Having said, I'm all for self-hosting and I hope it continues to become prevalent.
Most people have no clue about the amount of work required to runs things in a secure, redundant and resilient way. And no, a RaspberryPi in the corner, running on your LAN probably won't cut it. At least not for me.