Live data from Hacker News

1Password 8 will be subscription only and won’t support local vaults

1password.community

211–220 of 685 posts

Re: 1Password 8 will be subscription only and won’t support local vaults

#211
post #3

I haven't had a single bad experience with Bitwarden. I even pay for it now and still run it locally just to support them. Highly recommended if you don't want to be forced into 1Password's service.

I'm also happy with Bitwarden--I switched from 1Password a while ago when 1Password started the push toward subscription (which involved dropping support for features that I used, and dark UI patterns around pushing the subscription version as well as getting and using the non-subscription version).

I had bought several versions and both the Mac and Windows editions of 1Password over time, none of which were what I would consider inexpensive for a password manager. I consider their treatment of me as a customer to have been terrible.

I wouldn't be so pissed off about it if they had just dropped the product and started a new one, but slowly turning something paid for, used regularly, and liked into something different that I didn't want at all tells me that they are absolutely not worth doing business with again. They're not trustworthy.

Re: 1Password 8 will be subscription only and won’t support local vaults

#212

I guess I’m the outlier in being very happy with 1Password and fine with paying for the subscription service. Not only is 1Password the best password manager I’ve used, but it makes it seamless to share stuff with my wife. I don’t care if 8 is an Electron app either, considering I usually interact with it via the browser anyway with their extension. (Also I know that the majority of what they wrote for it is Rust and…

I'd be ok with paying an annual fee for the app. What I have zero interest in is increasing my attack surface solely for their bottom line. I'm also increasingly uncomfortable with the company handling my passwords engaging in the sort of spin and dark patters we've seen from AgileBits in the past few years.

I'm curious about how you see the attack surface increasing when using 1Password. My knowledge of how it works is that it always stores your passwords in an encrypted blob that can only be decrypted with a combination of username, "master password", and vault password. So no matter if it's in Dropbox, 1Password's servers, or your own hard drive, if anyone obtains a copy of the password file they still have to crack it before they gain access to anything.

Also I see your reply has been downvoted enough to become grey. (EDIT: Looks like between starting writing this and submitting it, you're no longer in the gray from downvotes!) I imagine it's because you made a blanket claim about spin and dark patterns without any supporting evidence. I'd be curious to know what you're referring to since I don't really keep an eagle eye on this stuff, I just use their product.

The one thing I do remember in the vein of "dark patterns" is how they effectively hid the method of doing a one-time payment for 1Password where you have to manage syncing and backing up the password file yourself. Seeing as I have no reason currently to do anything but make a charitable read of that situation which has been decried more than once on HN, I'd be willing to bet they did so for the following reason: They have had many problems in the past where a customer has lost a password file because they were not a power user and did something such as keep it on one hard drive in their only computer. (reinstalled windows, hard drive died, etc.) So they wanted to make something that would prevent that from happening for the vast majority of their customers that don't really understand stuff like backups, or don't have Dropbox, or who aren't part of Apple's ecosystem and have iCloud, etc. so that their passwords will remain safe and secure. So they made their own sync service and hid the version that would do local-only files so that only the dedicated users who really want to do that would find it and use it.

OR alternatively they're a bunch of greedy people that just want to hoover up dollars from our wallets, as people love to accuse them of here. Maybe a little of column A and column B, honestly. Something something needing to ensure they have a company that stays in the black without wanting to absolutely bloat up their own software so it becomes another useless Enterprise(TM) application with each passing paid version.

Also the only affiliation I have with 1Password is I have a friend I recently learned works for them, otherwise I'm just a customer. I just got into one of my little ADHD focuses where I really wanted to reply with something long and detailed, so please don't assume I work for them or something and am defending them because of that :)

Re: 1Password 8 will be subscription only and won’t support local vaults

#213
post #159

Earlier quoted context omitted.

I'm somewhere in between. I also paid for a non subscription version and I also feel like I was forced to upgrade to the subscription. Sadly switching password managers, especially if you share with a family, is really painful. We now pay the subscription, a tad begrudgingly, but I have to admit 1Password overall does a great job.

Bitwarden can 1-click import 1Password vaults.

I have done this, and it was horrible… for example I was missing all attachments (no notification or error messages). Also the fields are not properly converted 1:1. All in all, it was a big mess. This was about a year ago.

Re: 1Password 8 will be subscription only and won’t support local vaults

#214

What am I missing with these paid/subscription services? I personally use KeepassXC (Linux/Android). It's shared via cloud, I have a keyfile off device so I'm satisfied it's pretty much completely locked down. Is it browser integration? Genuinely have no idea why I'd pay for this, or why I'd trust a company with my passwords especially when it's not local.

I wouldn't use any password manager without browser integration. It's the single most critical feature to me in a password manager (ok, beyond secure storage/access). I haven't looked at Keepass lately, but unless it has a browser plugin and automatic sync between all devices (multiple computers, phones, tablets) without me having to roll my own sync solution, it's a non-starter for all but the most hardcore geeks.

Re: 1Password 8 will be subscription only and won’t support local vaults

#215

Earlier quoted context omitted.

Yeah, and there are dozens of us -- DOZENS! -- who continue to happily use SublimeText because VS Code feels so sluggish in comparison.

And that’s a completely valid choice to make! Some people use vim and emacs because they find Sublime too sluggish. But that doesn’t make VS Code “shit”. It’s pretty much the shining star of Electron done right.

> Electron done right

that is a very low bar. VS code is still slow and eats up a ton of resources. not to mention I don't trust anything from microsoft. OP said electron = bad and you should be ashamed of using it because its helping propagate it's usage when its a cancer.

Re: 1Password 8 will be subscription only and won’t support local vaults

#216
post #178

Also a stand-alone user since 1pw4. This news finally got me to try pass, the command-line utility. https://www.passwordstore.org/ The format is plain text. You can git control your password repo. You can organize into directories, etc. It has an extension architecture; you can have it generate otps, for example. You can have specific passwords unlock with more than 1 key, if you want to do eg. family or business sha…

I was reading through the comments wondering why so many technically capable people are paying for a password store service when passwordstore works nicely in the space and gives you some comfort in knowing how it works. I highly recommend pass. My set up is as follows: - setup the key, share the private key to other devices who are going to use the same pass store; - use syncthing to sync my passwords between device…

I really wish they'd offer other encryption backends than gpg. GPG is pretty long in the tooth. I never have problems with pass, all my problems are with gpg.

Re: 1Password 8 will be subscription only and won’t support local vaults

#217

I guess I’m the outlier in being very happy with 1Password and fine with paying for the subscription service. Not only is 1Password the best password manager I’ve used, but it makes it seamless to share stuff with my wife. I don’t care if 8 is an Electron app either, considering I usually interact with it via the browser anyway with their extension. (Also I know that the majority of what they wrote for it is Rust and…

I'm perfectly happy with paying a subscription, and think $4.99/month for 5 people is affordable. What I'm not happy with is the possibility of password access being limited or sync breaking if 1Password servers go down. At least with Dropbox (iCloud, wifi) sync, I have full control over the local vault file. Ultimately, it might be mostly about ownership and choice for me.

Also I think the "head" of the family can reset passwords of the other accounts...

Re: 1Password 8 will be subscription only and won’t support local vaults

#218
post #88

Earlier quoted context omitted.

FWIW, YNAB never receives or touches your bank credentials — sign-in happens through MX and Plaid, which hands back a token to YNAB to use[1]. For banks that support it, the process goes through OAuth and you sign in directly with your bank, so even MX and Plaid never see your credentials. The whole process is end-to-end encrypted, with no credentials stored at rest (unless necessary on the MX/Plaid side, but they ha…

Thanks for clarifying! I understand the architecture but perhaps didn't explain it properly in my comment. It does honestly strike me as the best approach given the constraints, but here in Canada almost none of my banks are supported with OAuth flow last time I checked so giving the 3rd party providers my credentials and having them log into the bank both violates the TOS of my bank and is also far less secure than…

Totally fair and reasonable! Too many banks here in the US too that both make it against TOS to get external access to your data and also refuse to offer anything secure like OAuth — extremely frustrating :/ At best you can try to pressure your bank to support OAuth but... we're just small fries.

Re: 1Password 8 will be subscription only and won’t support local vaults

#219

Earlier quoted context omitted.

As a Vim user I will happily admit that Sublime is significantly faster in some key areas of daily use.

But even then I'd assume it was more due to the workflow than the original complaint, which was essentially "Electron = bad, you should be ashamed for using it".

No, I have plugins for roughly the same feature set/workflow in both editors. Open and edit a huge file in both editors and Sublime is more responsive.

Re: 1Password 8 will be subscription only and won’t support local vaults

#220
> And now that we’ve started to roll out the next generation of 1Password apps, it’s time to say goodbye to standalone licenses.

Well, that's the end of my interest then. I had some curiosity after seeing the Rust integration, but I'm not going to pay a subscription fee to sync the smallest part of my day-to-day life. The convenience really just isn't there for me in a subscription. And no local vaults? Double no, please.

Post reply on HN