Live data from Hacker News

1Password for SSH and Git (Beta)

developer.1password.com

311–320 of 406 posts

Re: 1Password for SSH and Git (Beta)

#311

Earlier quoted context omitted.

What you have here is not a controversial claim. It's also not what you've been arguing until this moment, but for whatever reason you've softened your position substantially, now to the point of (IMO) banality. What's controversial (because it's false) is the claim that, "Memory is a precious resource." That is not a true statement.

We call memory a "precious resource" because it is often a fixed quantity in a given computer, and often the most expensive component after the display unit. Many laptops these days do not offer upgradeable memory, and even when they do, they often have very few slots in which to add it. So for many people, an upgrade involves an entire unit replacement at significant cost. I think most people understand this, so aga…

Humans are not limited to one computer in their lifetime, so the resources of one computer at one moment in time are not relevant to this discussion.

Additionally, your own citation shows that at this moment in time a vanishingly small number of computers have an amount of memory that would result in any kind of performance degradation due to the use of one or a few Electron apps.

Therefore, Moore's Law applies, and we can safely say that resources which double every two years are not scarce.

Your continued insistence on a false fact will continue to be "controversial".

Re: 1Password for SSH and Git (Beta)

#312
post #99

I'd rather use Secretive ( https://github.com/maxgoedjen/secretive ), to be honest. I've stopped using 1Password everywhere I can due to their product "focus", and am working my way through a set of alternatives (currently using Secrets on the Mac and looking at the KeePass ecosystem, which keeps improving monthly): https://taoofmac.com/space/apps/1password Edit: It's been fun watching this get upvoted and downvoted…

Secretive doesn’t work if you have existing keys that you want to use from an agent, and it can’t act as a regular agent. It _also_ does not work for Git signing via SSH key, if I remember correctly.

If _those_ issues could be fixed, I’d probably use Secretive. Unfortunately, it broke almost all of my workflows when I installed it and it appears that the choice to use Secretive is all-or-nothing.

Re: 1Password for SSH and Git (Beta)

#313

Earlier quoted context omitted.

We call memory a "precious resource" because it is often a fixed quantity in a given computer, and often the most expensive component after the display unit. Many laptops these days do not offer upgradeable memory, and even when they do, they often have very few slots in which to add it. So for many people, an upgrade involves an entire unit replacement at significant cost. I think most people understand this, so aga…

Humans are not limited to one computer in their lifetime, so the resources of one computer at one moment in time are not relevant to this discussion. Additionally, your own citation shows that at this moment in time a vanishingly small number of computers have an amount of memory that would result in any kind of performance degradation due to the use of one or a few Electron apps. Therefore, Moore's Law applies, and…

This discussion has never been about whether the aggregate amount of computer memory in the world is a fixed quantity. (At least, that's not what I meant to discuss, or how I think most people would interpret my claim.) It's about the impact on real people who have laptops with fixed amounts of memory in their hands today.

Re: 1Password for SSH and Git (Beta)

#314

Earlier quoted context omitted.

Humans are not limited to one computer in their lifetime, so the resources of one computer at one moment in time are not relevant to this discussion. Additionally, your own citation shows that at this moment in time a vanishingly small number of computers have an amount of memory that would result in any kind of performance degradation due to the use of one or a few Electron apps. Therefore, Moore's Law applies, and…

This discussion has never been about whether the aggregate amount of computer memory in the world is a fixed quantity. (At least, that's not what I meant to discuss, or how I think most people would interpret my claim.) It's about the impact on real people who have laptops with fixed amounts of memory in their hands today.

The impact on real people who have laptops is low because the aggregate amount of computer memory in the world is doubling every two years.

It doubled, people bought new laptops, and reaped those benefits by running multiple Electron apps seamlessly on those new laptops.

So it remains a false statement to say, "Memory is a precious resource."

Re: 1Password for SSH and Git (Beta)

#315
post #95

Earlier quoted context omitted.

What is the benefit over ssh-agent?

Other commenters have mentioned sync, which is absolutely nice, but one other advantage is shared keys. Obviously it's not ideal to share SSH keys, but lots of teams will share the default EC2 keypair for example. This makes it much easier to pop that key into 1Pass, share it with the team, and easily get everyone into the box. And, frankly, 1Password gui is much more user-friendly than other SSH agents. Personally,…

Point of order: afaict currently keys can be put in a shared vault but only keys in a private vault can be accessed by the agent. So the workflow would be everyone copies the shared keys into their private vault.

Re: 1Password for SSH and Git (Beta)

#316

Earlier quoted context omitted.

I definitely understand the aversion to trusting 1password's cloud service, but it's worth noting that their security model is such that it requires minimal/zero trust of the server. Your vault is only ever decrypted on the client side, and the 1password service only ever stores/syncs the encrypted vault. This is why if you lose access to your secret key, your vault can never be decrypted, even by 1password - your se…

> I definitely understand the aversion to trusting 1password's cloud service, but it's worth noting that their security model is such that it requires minimal/zero trust of the server. It just requires absolute blind trust on their client apps... > Your vault is only ever decrypted on the client side Which is a closed source blob, so, again, requires absolute blind trust.

Yup completely valid. In the context of the original post I was replying to, trust of the closed source client code was always required and that hasn't changed, so it didn't feel relevant to mention. I agree with you that there is significant merit in choosing an open source solution for passwords/secrets management.

Re: 1Password for SSH and Git (Beta)

#317
post #283

I've been using 1Password for years now, the auto-fill always works. I don't use their command line stuff much, and I have some read some legitimate criticisms about how they communicate secrets on unix-like systems. Apart from that, I'm not sure I understand the dissatisfaction in the comments. Can someone enumerate what's wrong with 1Password? Are tools like BitWarden any better?

I think the majority of it is down to the pre-SaaS customers of the product. 1Password used to have a life time license and would work without any need for 1Password servers. You could backup your vaults anyway you wanted and the various clients would work with a variety of methods for syncing etc. A lot of long term 1Password users bought this and still use it, but the company no longer really do much to support it…

Ah, that makes sense honestly. I bought their lifetime license and I'm a subscription user. Kinda sounds like the right thing to do is refund the lifetime license holders if they've changed architecture and direction that drastically.

Re: 1Password for SSH and Git (Beta)

#318

I have used 1pass for years. I think I bought my lifetime license sometime in 2014? I loved it and even advocated for our 2000+ company to adopt it back in 2018. I would say in the past 2-3 years it has slowly become an absolute nightmare. I do not recommend it to anyone anymore. They have somehow screwed up the very basic functionality of filling in passwords on any browser I try. They continue to shift features aro…

> I have to go to the Desktop app, search, find, and copy Agreed, the Chrome browser extension and the Safari inline menu are garbage. Fortunately the classic extension is still available and still works great for me, as well as Safari with the inline menu option disabled. Same for the iOS extension, garbage. But luckily the classic password autofill on iOS still does work great.

I use the Firefox extension on desktop and have no issues. But the iOS one, I have to agree with you, is pretty garbage. It only works half the time for me. It doesn't prompt when I'm in a username field consistently, and sometimes doesn't fill the password on the first time, forcing me to hit it again or copy paste. I find myself more often having to physically navigate to the app, type in my username, and copy paste my password.

If you are using the classic autofill don't you have to maintain your password in keychain as well as 1Password?

Re: 1Password for SSH and Git (Beta)

#319
post #101

How does it work with with `~/.ssh/config`? Mainly, say I have keys in the vault for many machines, if they all get added to the 1password ssh-agent sock, won't you get "Too Many Auth failures", unless there is a way to pair the key to a `Host`? Maybe `~/.ssh/config` can pair keys to a `Host` by fingerprint instead of file?

The documentation covers that. tl;dr: you can pin public keys to hosts https://developer.1password.com/docs/ssh/agent/advanced#ssh-...

Ahh, well that's still an improvement, but it would be nice to not have to download anything.

Re: 1Password for SSH and Git (Beta)

#320

Earlier quoted context omitted.

Could you share a little bit about what you'd want to use this for? (I'm part of the 1Password design team)

SSH keys have both a private and a public file. The private file is multi-line text. I don't like putting the private key in the notes field, because its name is still "notes" (but I'd prefer the label be the key's file name), it's actually markdown formatted text, not literal text, and what if I still want to write a note, but I've already used the notes field for the key? HTTPS certificates including multiple certi…

Thank you for the feedback!

We spoke about it internally many times in the past but couldn't get the solution implemented because there was always something in the way. After reading your comments and I talked to the team and we just merged a change that should appear in the nightly build and make the handling of the multi-line fields better. Having a single core in 1Password 8 makes things so much easier when it comes to implementing changes across all platforms.

Also, there is a new SSH Key item type that might help in this particular case.

-- Roustem 1Password Founder

Post reply on HN