Live data from Hacker News

On Password Managers

tbray.org

321–330 of 347 posts

Re: On Password Managers

#321

Earlier quoted context omitted.

Will continue to be supported for 6 and 7. Nothing beyond that.

To be fair 7 is not even out yet. I don't know many companies that talk about product releases more than one version in the future before release.

I did read the blog post you referenced, and that's exactly why I believe they intend to go cloud-only.

Saying something like "we will never force users into cloud storage and sync" when talking about a product like this just isn't that hard, unless that's exactly what you plan to do. Many software vendors have corrected misperceptions when changes seem to point in a direction some users don't want to follow.

This is not a case of misperception. The way they've talked about this make it quite plain that's where they want to go, and the careful phrasing ("at this time", "yet") makes it obvious that they intend to.

Re: On Password Managers

#322
post #243

Earlier quoted context omitted.

It would appear making a password store on Windows would be rather simple, wrapping DPAPI: https://msdn.microsoft.com/en-us/library/ms995355.aspx At that point you should probably be about as (in)secure as access to the platform is. I don't know how you could improve much on that (assuming secureboot and bitlocker encrypted disk). Is there some magic going on the MacOS side that somehow improves on this?

Yes! The actual encryption of passwords is not the hard part of a password manager (though, of course, commercial password managers seem plenty capable of screwing that up!) The hard problem is getting the passwords out of the encrypted store and into form fields in your browser.

Would you consider the KeePassHTTP solution to be adequate (they have a browser plugin that acts as a password manager using the browser's APIs and the passwords are retrieved after authenticating the plugin with the KeePassXC server -- which prompts the user each time and only entries that match the URL are sent).

They also support copying the password to your clipboard (which they then clear after a few seconds). There's also the automated entry system which basically emulates keystrokes.

Re: On Password Managers

#324
post #49
post #33

Earlier quoted context omitted.

> I recommend 1Password, and there's currently no other commercial password manager that I recommend. Are there any open source password manager products that you would recommend?

Total aside here, because I know what you mean, but it's interesting that many people include open source software in their definition of "commercial" software, the DOD and other government agencies, for example. https://www.dwheeler.com/essays/commercial-floss.html

A very large number of free software projects are commercial (either because distributions sell support for them, or the project itself costs money). The license for a piece of software has nothing to do with whether you sell it or give it away for free. Richard Stallman used to sell copies of GNU Emacs back in the day.

Re: On Password Managers

#325
post #324
post #49

Earlier quoted context omitted.

Total aside here, because I know what you mean, but it's interesting that many people include open source software in their definition of "commercial" software, the DOD and other government agencies, for example. https://www.dwheeler.com/essays/commercial-floss.html

A very large number of free software projects are commercial (either because distributions sell support for them, or the project itself costs money). The license for a piece of software has nothing to do with whether you sell it or give it away for free. Richard Stallman used to sell copies of GNU Emacs back in the day.

Very true. But what's interesting and non-obvious about the way the DOD defines "commercial" is that it doesn't depend on money exchange (or lack of money exchange) at all, and that's what that article by David Wheeler is trying to say.

The DOD defines software commerce as anything available to the public and used for any non-government purposes.

http://dodcio.defense.gov/Open-Source-Software-FAQ/#Q:_Is_op...

So to take your comment one step further, for some organizations, the definition of commercial also has nothing to do with whether you sell it or give it away for free, even though many people reasonably assume commerce==sales.

Re: On Password Managers

#326

Earlier quoted context omitted.

As a 1Password customer who's been pretty unhappy with how the company took my money for a full version and has, since, been pushing me towards a subscription (making the non-subscription version/features harder to find, no Windows version, etc), I'm seriously considering switching over to Enpass [1]. The UI is pretty similar to 1Password and most of the features are there. It can sync with Dropbox and a few other cl…

I don't understand this mentality of getting angry that a company wants to migrate to a subscription fee so they can have sustainable income. You have a full version, so continue using it, but it's not fair to expect updates for free in perpetuity across platforms and browsers in today's churning software ecosystem. 1Password is an incredibly complex, solid and polished suite of software products that provides an ess…

Did I ever say that I expected "updates in perpetuity"? I said (in another comment from the one you replied to) that I expect the software to "work in perpetuity." That's a very different requirement that requires AgileBits to do absolutely nothing except not tie it to their own cloud services. But I did pay them over $60 a little over a year ago, so I think it's fair to expect a few bug fixes. And it's fair to expect them to not hide the download link for when I need to install it, since that's explicitly allowed by the license I purchased. And, since the software auto-updates, I think it's fair to expect them to not push out updates that make it harder to use the software or otherwise push me towards a subscription model that I'm never going to accept.

It boggles my mind that people are so quick to support a company that's making changes solely for their own benefit to the detriment of their customers. I want AgileBits to succeed too. That's why I bought the software despite having access to a license from work. But try this for math...if they release a major update to their software every year and charge, say, $36 to update, it costs the same exact amount to stay on the latest version. As a bonus to them, they get the money all up-front and get to collect what little interest you can get these days. The main difference is that I don't have to worry about their company imploding and taking all my passwords with it. My software will work in perpetuity without any cloud service they provide. That's piece of mind that I need when it comes to my passwords.

Re: On Password Managers

#327
post #193

Earlier quoted context omitted.

> Additionally, managing your own password vault is a lot like managing your own email server. As someone who actually does both, this is IMHO backwards. My "password vault" is a GPG file I open in emacs and cut and paste from. It's trivially copied and maintained, extends cleanly to "non-password" secret info (e.g. credit cards, my kids' SSNs), involves no third party systems beyond the operation of the software, is…

Nothing wrong with what your are doing if it works for you, but I wouldn't describe your workflow as trivial, and I wouldn't call using Password complicated. The value to me of 1Password is: Go to Website, Right click 1Password, enter password, logged in. No copy paste, no switching windows, no launching emacs, no searching through a list. Even the added friction of 1Password took a few starts and stops to get throug…

Have you tried the 1password share-menu charm on iOS? No more app switching! I don't remember what if any setup I had to do to get it there.

Re: On Password Managers

#328
post #187

Earlier quoted context omitted.

In what way are they doing less?

Generally speaking, security solutions have (at least) two goals that are often at odds with each other: (a) Minimize the number of trusted third parties / components, (b) stay out of the way from a usability perspective. Most negative comments here imply that 1password severely compromised (a), to the point of making it useless, in exchange for incremental-to-zero gains in (b). For most people here, using a third-pa…

> For most people here, using a third-party sync service is probably more convenient than avoiding whatever mass-market-cloud-thing 1password is trying to move everyone to.

Using 1Password's service is actually far more convenient. It Just Works™, whereas other solutions like Dropbox are prone to creating conflicts.

TBH I don't know why anyone who was using a third-party sync service like Dropbox would dislike the 1Password sync service (beyond the fact that it's subscription pricing instead of a one-time license fee). It's only the small subset of users who used Wi-Fi sync that seem to have a legitimate complaint here.

> this article just knocked 1p off my list of candidates

Why? Unless you were planning on using Wi-Fi sync, then you shouldn't have a complaint. Tim Bray makes a lot of noise about web sites being insecure, but you don't need to use the web interface for 1Password (well, until today you needed to use it to create new vaults, but 1Password 6.8 can now create cloud vaults directly in the app). And his comment about if you use Dropbox all they have are the encrypted password file applies just as well to AgileBits, because you need the combination of your secret key + account password to decrypt anything, and at least the secret key (and maybe the account password too, not sure) is never sent to AgileBits.

If you're interested, they also have a white paper on their security, which you can find linked at the bottom of https://1password.com/security/.

Re: On Password Managers

#329
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

The 1Password situation is complicated because the people who run the company make it so. There's always been a push to get more income with less effort, not that that's wrong. But what frustrated me, and finally moved me off of 1Password, are the instances where the founders and staff responded in an obstinate way that "this is just how we're going to do it, and we've decided not to hear anyone, however loud you may be." Then after sometime when the noise seems high enough to cause damage, they backtrack (like it happened with the MAS-only decision). The only word I can use to describe AgileBits is "disingenuous". It sounds harsh, but it has a history of being so.

AgileBits has also used dark patterns, if I may call them so, on the website to hide or obscure what's available but not considered favorable by the company, and prominently push what's considered favorable by the company as if that were the only option available (one visit to the home page in the last couple of years is adequate to get this). This ought to be shameful for any software company, especially one that claims to care about the users.

When it was originally created and stabilized, 1Password was a great solution, almost like Dropbox in simplicity and value. But the focus has been sorely lacking on other platforms, like Windows (and of course, nothing on Linux). There doesn't seem to be a lot nowadays to justify what the end user gets from the subscription when there are other options out there (that didn't exist several years ago).

Ever since I started using Linux, I've looked for solutions and have been trying Enpass once in a while. [1] It's free on all desktop platforms and has browser integration.

Edit: Of course, it's also been quite sometime since I started using Keychain Access and Safari on OS X/macOS/iOS.

[1]: https://www.enpass.io/

Re: On Password Managers

#330

I'm a 1Password user, and have synced my vault between devices through both Dropbox and iCloud at various points. I can't help but feel like either there's something I'm missing or something everyone else is missing, which statistically means that it's most likely me. But: When I sync with iCloud, Apple can't read my vault--even though it's on their servers, it's strongly encrypted with my passphrase, and the encrypt…

When I store my password DB in Dropbox, Dropbox treats it like any other file: it's completely agnostic to the content. But the sync component of an online password manager knows what it's storing, and the storage and access are provided by the same people.

It's true that you still have to trust the software vendor with your data -- that they won't just send themselves your secrets in the clear -- but I think the secrets are safer if the software isn't supposed to send _anything_ to the vendor than if you have to rely on what it does send being properly secured.

Post reply on HN