Live data from Hacker News

On Password Managers

tbray.org

311–320 of 347 posts

Re: On Password Managers

#311

This is only tangentially related, but I believe it's time to have a unified login standard for the web. Not in the OAuth sense, as that's hard to do, but just a small, machine-readable file that tells your password manager "to log this user in, just submit credentials to /whatever/url/". That way, your password manager would show a "login" button on the browser's toolbar when you visited any page in a site, you'd cl…

> just submit credentials to /whatever/url/". No, No. We shouldn't send credentials to anywhere. We should be using things like client certs or SRP. We need to solve the UI and UX problems and actually create better systems, not keep patching over the same broken system.

Do you want a marginal improvement that many people might use, or a perfect system that nobody will?

Re: On Password Managers

#312

This is only tangentially related, but I believe it's time to have a unified login standard for the web. Not in the OAuth sense, as that's hard to do, but just a small, machine-readable file that tells your password manager "to log this user in, just submit credentials to /whatever/url/". That way, your password manager would show a "login" button on the browser's toolbar when you visited any page in a site, you'd cl…

It's been tried in various flavors of that. The one I liked the best was OpenID. You designate who you trust to actually log you in, which could even be localhost if you set your redirects right, then provide a URL as your "login." There was a somewhat standardized set of data that could go back and forth, and if a specific site needed more, it could ask for it on it's own. The problem, I think, is that every site wa…

Those are all centralized login systems. I'm talking about just making password managers smarter.

Re: On Password Managers

#313
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

I changed from LastPass to 1Password for big part because it was "pay once, use forever" instead of LastPass' subscription service. It hasn't even been 3 years since I switched and I paid what felt like a lot of money, but I figured that it would still be less over all in comparison. Now I can't get my vault to sync on my Windows machine and last time I reinstalled my Mac it was a hunt for the right executable. I've…

LastPass Premium is $1/mo and your password vault is exportable. It's a pretty cheap service to be locked into.

Re: On Password Managers

#314

Earlier quoted context omitted.

Have you used KeepassXC. I am panning to move to it from lastpass, and want to make sure I am making the right choice.

I've used KeePassXC, and I think it's the best KeePass variant. I don't like stock KeePass because it's horribly slow under Mono (Linux/OS X). And I like but am not as satisfied with KeePassX because it lacks some features I like. From what I recall, the maintainers of KeePassXC got frustrated with the feature set and development pace of KeePassX, so they made their own fork. And they added nice things like TOTP code…

With KeePass you create a new entry for the domain, then make it refer to the original to avoid duplication of user/password. But yes: allowing one single entry to be used for multiple domains would make much more sense.

Re: On Password Managers

#315

Good security hygiene is like a diet or exercise plan: the most effective one is the one you will stick with. Most users don't follow good habits because its a giant pain for non technical users to get set up. 1p's subscription plan is aimed squarely at those people and I think its a great idea. It's reasonably secure and easy to set up everywhere. That is a big deal in my mind. Yes, its not bullet proof but its a 10…

You don't have to "manage your own password vault" thought. I sync my 1Password vault via iCloud. It's like two clicks to turn it on. And surely Apple have an even bigger and better team dedicated to keeping my data safe?

Sure. If you only use mac/iOS then that's a perfectly valid strategy. I use a windows machine at my job, Apple/Linux for my personal projects so no dice. I would imagine that's not a super uncommon scenario outside of the SV bubble where Mac is the only thing people use (not throwing shade, it's just kind of the thing there). To me, a valid password management strategy MUST be cross platform. Also keep in mind that 1p can store more than just logins. It can do SSH creds, software licenses, secure notes, you name it.

Re: On Password Managers

#316
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

[deleted]

Re: On Password Managers

#317

Earlier quoted context omitted.

> just submit credentials to /whatever/url/". No, No. We shouldn't send credentials to anywhere. We should be using things like client certs or SRP. We need to solve the UI and UX problems and actually create better systems, not keep patching over the same broken system.

Do you want a marginal improvement that many people might use, or a perfect system that nobody will?

I don't consider something that remember the login URL for a site (which most password managers can store) a marginal improvement at all.

Also, "marginal improvement that many people might use, or a perfect system that nobody will?" is a false dichotomy. I'm saying we should make better systems (not perfect ones) easier to use.

Re: On Password Managers

#318
post #39
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

"1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords" That's true - but playing hide and go seek with the non-subscription version is uncool.

I was using an old version of 1Password, it stopped working for me on Sierra so I went to upgrade and the upgrade page had broken images and talked about working on El Capitan. I sent a support ticket (in February) in to make sure the upgrade would work on Sierra and had a back and forth where they ultimately said, "Like you saw, that web page hasn't been updated in awhile as Sierra is the latest macOS. Knowing that there is a better way to do things, in good faith we couldn't continue to sell a lesser product like the stand-alone license. Due to this, we are moving away from the stand-alone license and heading to higher and better pastures."

I got a marketing email about a week later from Dave Teare and replied expressing my disappointment that publicly they're saying the stand-alone model will continue indefinitely but privately, they're "moving away" from the "lesser product" that they couldn't in good conscience sell me any longer. No reply.

The actions of Agile Bits are not matching the words in my experience and that's a big deal given the type of software they sell.

Re: On Password Managers

#319

Earlier quoted context omitted.

Will continue to be supported for 6 and 7. Nothing beyond that.

To be fair 7 is not even out yet. I don't know many companies that talk about product releases more than one version in the future before release.

Sure, but when we're talking about a core foundational feature, they do. Richard Stallman would absolutely be willing to say, "We 100% guarantee that gcc will never become non-free software" instead of "we realize that not all gcc users are ready to move to non-free software yet, and we promise that versions 7 and 8 will continue to be free software".

For a lot of people here, not remotely storing the vault is such a core foundational feature.

Re: On Password Managers

#320

Earlier quoted context omitted.

Do you want a marginal improvement that many people might use, or a perfect system that nobody will?

I don't consider something that remember the login URL for a site (which most password managers can store) a marginal improvement at all. Also, "marginal improvement that many people might use, or a perfect system that nobody will?" is a false dichotomy. I'm saying we should make better systems (not perfect ones) easier to use.

> I don't consider something that remember the login URL for a site (which most password managers can store) a marginal improvement at all.

Me neither, that's why I proposed a system that will allow your password manager to log you in automatically with a single click instead, with a trivial change to the server (a file with some information).

> I'm saying we should make better systems (not perfect ones) easier to use.

Having seen how little adoption Persona, which was pretty much perfect, got, I don't think the problem is usability.

Post reply on HN