Live data from Hacker News

1Password for Linux beta

blog.1password.com

241–250 of 254 posts

Re: 1Password for Linux beta

#241
post #208

Earlier quoted context omitted.

> Not knocking the project, which sounds cool, but the absolute last thing I want to self host is a password database exposed to the internet. Hard pass on that element. I have the exact opposite feeling. I would not selfhost email but I would selfhost a password manager and my files behind WireGuard, like many have said. I have almost moved from cloud hosting to home server. This perfectly reasonable for non critica…

I'm curious, how does syncthing and ios work for you? What kind of apps/settings do you use on the clients?

There is no support for syncthing on iOS. I managed to get it halfway working on ish, but it’s just not there, so as of now, I use the shellfish ssh app, that allows to sync folders, through WireGuard also.

Note that I use syncthing for the casual read only "important documents", such as ID copies, tax documents, ebooks, etc. I don’t sync photos, movies and such. Most editable documents are in git repos.

I sometimes work on my iPad, and then I use a ssh client or the ish app (a shell, with vim, etc).

I have used this setup for years, and it’s just low friction, low maintenance for me. I have thought about using an own cloud/nextcloud setup, but it’s just too much work for little value. Like running gitlab instead of ssh and git.

Re: 1Password for Linux beta

#242

Earlier quoted context omitted.

Because it's a service many things can happen. Hacking aside... these are many ways in which it can go wrong: - There can be an outage and you get locked out of your keys. You can have a connectivity issue to the service. - The service can be discontinued or they could randomly terminate your account based on some automated system decision by mistake, sometimes with no right to appeal... - They can change leadership…

Regarding outages, services such as 1Password allow you to locally save your keys. An outage might interrupt synchronization, but you won't lose access. As far as the other concerns, I'd say these concerns are all present in the 'single password re-use' strategy as well, except instead of choosing one single company to trust over your stuff, you now have to trust every single website you log into to safeguard your pa…

It still goes against the principle of defense in depth. You defeat one layer and you gain control over everything.

Even if that layer is composed of a password and MFA, it is still one layer.

And by using a SaaS password manager you would have also done another part of the job on behalf of the adversary: enumerate what they have access to.

If you are VIP, persistent adversaries will find a way somehow.

Re: 1Password for Linux beta

#243
post #119

The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…

> I also considered "offline" managers like KeepassXC, but synchronization gets way worse, and there's also the issue about trusting someone else with your mobile apps. I'm using KeePassXC. Originally between three computers (Debian desktop, Debian laptop, and Microsoft laptop) where it was part of my git repo that I'd sync in between the machines as needed (git repo hosted within my own instance of gitolite, btw). I…

Yeah, I find synchronization the least of my problems with the Keepass family. The file format uses GUIDs internally for most changes and most conflicts are easily merged/fixed. The fact that it is synchronized as files gives a lot of flexibility in options. You can use whatever cloud file sync provider you trust that month, and you have the flexibility to switch providers as your trust model and/or threat model change.

Mobile OSes are finally making it easier for arbitrary "file" sharing between such apps. (The iOS Files app is finally "decent" for this compared to just a few years ago.)

A similar file sync option to Syncthing I like to point out is Resilio Sync, a P2P device-to-device "torrent-like" sync tool. Among other things it also supports "encrypted shares" that cannot read inside the share but can still participate as a "seed" in the torrent-like share. Resilio Sync is relatively a lot more closed/commercial than Syncthing, but it's torrent-based underpinnings make it sometimes much faster with large shares. (As with everything, trade-offs to be made based on your personal threat model.)

Re: 1Password for Linux beta

#244
post #70
post #45

I have been using LasPass since many years ago. There's an extension for Chrome and for Firefox. On Android I use the app and even though experience is not that "automatic" it works. I am surprised nobody mentioned LastPass is there any reason I should know?

I've been using it for years ago. There are a few annoyances I have with it, mostly on mobile integration, but not enough for me to try to migrate to another platform. I'd be curious is someone could explain why it would be worth the effort to transition from LastPass to some other provider.

Been using it cross-OS for years.

I'm totally disinterested in wasting my time on finding something better that I don't even want to try even free alternatives. It just works and it's inexpensive.

Re: 1Password for Linux beta

#245
post #112

Earlier quoted context omitted.

The most important password is your e-mail. If you lose that then you can lose everything. It's the only password I don't save in a password manager.

Uhm, that's why you should have 2FA/MFA. Not having your password stored in a password manager doesn't make it bulletproof.

I use 2FA/MFA when I can but most sites don't support it.

Re: 1Password for Linux beta

#246
post #134

Earlier quoted context omitted.

I definitely have some password manager anxiety. I'm not too concerned about hacks or losing my password database. For me, it's more about the sense of independence, and being able to log in to my accounts using just my noggin. I might be able to remember one or two strong passwords, but not dozens, which is kind of the selling point of a password manager. I use KeePassXC with a password and key file. I sync the data…

password managers feel like vendor lock in. what happens if i need to move to another manager, or i need to sync everything to my phone. they go out of business, they decide to charge more. or if i pay for it and now i cant pay for it anymore. if i sound like an idiot, id love to hear why btw! heh

I started off with keepass, then moved to lastpass for better sync, then moved to 1password because I didn't like how lastpass works. Each of them support various forms of exporting/importing logins, so there's not much risk of vendor lockin with those. I'd assume it's the same for other managers, but you'd have to check.

My biggest issue has been that I only saved passwords when I started with keepass instead of username+passwords, which lastpass all imported as secure notes instead of logins.

Re: 1Password for Linux beta

#247

Earlier quoted context omitted.

I’ve been a happy one-password customer for several years and I switched to the family subscription model to get my parents away from their little notebook of passwords. I had self-hosted a PHP based password manager for a handful of years, before switching to 1P because I wanted a “real app” with tighter OS integration. I’ve had 3 gripes and this solved one of them. The other 2 are 1) Their insistence on 1PasswordX-…

As someone who can’t install 1Password many places where I have worked, 1Password X has been an amazing option.

I’m not saying it’s bad, it’s just grossly inferior to the native app on both macOS and Windows.

Re: 1Password for Linux beta

#248

Earlier quoted context omitted.

I’ve been a happy one-password customer for several years and I switched to the family subscription model to get my parents away from their little notebook of passwords. I had self-hosted a PHP based password manager for a handful of years, before switching to 1P because I wanted a “real app” with tighter OS integration. I’ve had 3 gripes and this solved one of them. The other 2 are 1) Their insistence on 1PasswordX-…

In defence of the notebook of passwords, there tends to be minimal overlap between opportunistic neighbourhood burglars and identity thieves.

Fair point- I guess digitization was somewhat selfish. A centralized DB makes it easier when I’m trying to help them with something remotely, and the “Shared Vault” facilitates easy communal logins (Netflix, Hulu, etc...)

Re: 1Password for Linux beta

#249
post #96
post #69

Earlier quoted context omitted.

Not knocking the project, which sounds cool, but the absolute last thing I want to self host is a password database exposed to the internet. Hard pass on that element. 1password used to have a peer to peer sync mode that I loved. No need for a server anywhere. You would open it on your Mac and then open it on your phone and if they were on the same network they would self discover. Too inconvenient, perhaps, for most…

Bitwarden only ever decrypts the password database on the client, and the login credentials you send to the server are only a hash of your actual encryption key. In principle, you could store your Bitwarden database on a public torrent at no risk to your security :) So, if you do trust the Bitwarden software in the first place, self-hosting it shouldn't be any more dangerous than using the managed service, because th…

Well that’s the thing. If I’m content to trust the client side hashing or encryption on the secrets why bother setting up my own server? Conversely, if there are nefarious things that can happen on the server to compromise the data without me knowing about it, then I trust neither myself (because I’d be a bad sysadmin) nor a third party (not knowing what they’re up to). Or if I do trust a third party just use 1Password.

Reading between the lines it sounds like being able to build from source or see and install the source gives some assurance you can’t get via third party and the strong files give some assurance over me being a bad sysadmin. That’s either a sweet spot or uncanny valley depending on your perspective. :)

Re: 1Password for Linux beta

#250

Earlier quoted context omitted.

In defence of the notebook of passwords, there tends to be minimal overlap between opportunistic neighbourhood burglars and identity thieves.

Fair point- I guess digitization was somewhat selfish. A centralized DB makes it easier when I’m trying to help them with something remotely, and the “Shared Vault” facilitates easy communal logins (Netflix, Hulu, etc...)

100% agree and I did the same with my own parents.
Post reply on HN