Live data from Hacker News

Getting 1Password 7 ready for the Mac App Store

blog.agilebits.com

321–330 of 484 posts

Re: Getting 1Password 7 ready for the Mac App Store

#322

Earlier quoted context omitted.

This is the big fallacy I see whenever someone uses open source just because the source code is public. Unless you're able to perform a full audit yourself, is it really any better than a closed offering like 1Password?

I suppose the theory is that open source is better (a) because you can audit it if you want to, and (b) it's more likely that someone out there has audited it. In practice, (a) falls apart if the user doesn't have the knowledge, experience, or time necessary to perform an audit, which is quite likely for security software. And I feel like (b) isn't great either, as there are plenty of examples of major flaws in open…

Stuxnet didn’t rely on open source software.

There are major unrevealed flaws in all software more complicated than “hello, world.”

Re: Getting 1Password 7 ready for the Mac App Store

#323
post #249

Earlier quoted context omitted.

There's no requirement whatsoever that 1Password X be exclusive to a privately-run cloud. Easier to build, possibly (though since it includes the difficulty of building the cloud service in the first place... oh hell no, 100x harder), but it could work just as well with manual syncing (point to a url -> download the backup, or just give it the file).

Implementing things is not the hardest part. Supporting customers is the hardest part. Things will break and with manual syncing support is going to be a nightmare. Also, syncing is never easy.

My point is that it doesn't need to sync. Ignore syncing. I'd even prefer to download and upload the backups by hand, rather than put it all in someone else's control in a browser environment.

Cloud password systems are like running all your security-sensitive code in an Electron app - an impossibly large attack surface with many significant flaws in some of your most-sensitive use. It doesn't make sense if you care about security at all. At least extensions are moderately well sandboxed compared to websites (since it'd be trivial to ship new javascript from their site).

Re: Getting 1Password 7 ready for the Mac App Store

#324
post #259

Earlier quoted context omitted.

The developer's comments on the article contradict what you're saying: > 1Password 7 from the Mac App Store will only support our hosted service, as that’s what you’re purchasing with a 1Password membership. If you install from our website, you’ll have to option to use a standalone vault synced via iCloud if you purchase a standalone license, or use our hosted service if you purchase a 1Password membership. > As it s…

It's super frustrating how vague and contradictory they're being about this :\ I understand why they're subscription-only for the mac app store, as a way around its insane lack of pricing flexibility. Makes sense, fully support, etc. But they seem to be continually pushing the non-cloud options further and further away from visibility :|

Late update: I asked on twitter, got an answer: https://news.ycombinator.com/item?id=17115334

Subscriptions will only support cloud sync, not local.

Re: Getting 1Password 7 ready for the Mac App Store

#325

I did not pay for a subscription software, I bought a password manager which stored password locally. I also don't want to pay for a upgrade just because apple upgraded the OS. I now only buy mac software on Mac App Store. Apps which I have not renewed include 1password, screenflow, textmate, vmware Fusion, Paid Products I wish were on Mac App Store with free updates. Sublime, Paragon NTFS , printopia

Textmate 2 is on Github. Was there ever a second paid update?

Re: Getting 1Password 7 ready for the Mac App Store

#327

Earlier quoted context omitted.

This is the big fallacy I see whenever someone uses open source just because the source code is public. Unless you're able to perform a full audit yourself, is it really any better than a closed offering like 1Password?

I suppose the theory is that open source is better (a) because you can audit it if you want to, and (b) it's more likely that someone out there has audited it. In practice, (a) falls apart if the user doesn't have the knowledge, experience, or time necessary to perform an audit, which is quite likely for security software. And I feel like (b) isn't great either, as there are plenty of examples of major flaws in open…

Agree, open source is rights for the users, no matter they have the ability to audit or not.

Re: Getting 1Password 7 ready for the Mac App Store

#328
post #119
post #42

Earlier quoted context omitted.

It's worth noting (and not super obvious because of their marketing) that "getting a subscription" and "using their cloud sync" are not a mutual requirement. You can pay via subscription and continue using local/Dropbox/etc vaults. This part was super confusing to me until I dug deeper when a friend upgraded. So the primary impact of switching from standalone license to subscription, if you're planning on using 1Pass…

> So the primary impact of switching from standalone license to subscription, if you're planning on using 1Password for a while, is that instead of paying a larger chunk of money every so often when they drop a new major version, you move to paying a flat couple bucks a month or larger chunk per year. One thing that is not clear to me is what happens with the subscription license if you go a long time without interne…

I'm surprised that no-one on this page has mentioned PasswordSafe (https://www.pwsafe.org). Open-source, supports cloud (Dropbox and iCloud sync) and local storage, available on Windows, Linux, Mac, iOS and Android, and has good pedigree (Bruce Schneier). Gets regularly updated.

I've been using this for years across multiple devices and O/S. A real lifesaver.

Re: Getting 1Password 7 ready for the Mac App Store

#329
post #305

Earlier quoted context omitted.

Removing the ability to get your own passwords out of your password management utility that you paid for would be corporate suicide.

Crippling it, not so much. I moved away from 1password at the time of the subscription palaver. I managed to move everything to Keepass but each entry has it's own folder. I don't blame 1Password for the state of my Keepass db (although they pretty much forced my hand) but the closed nature of 1Password does bite you in the arse when you decide to leave.

I switched from 1Password to LastPass last year and it was a smooth transition. If they’d had a Linux version I’d still be a customer right now.

Re: Getting 1Password 7 ready for the Mac App Store

#330

Earlier quoted context omitted.

If you are paying for a subscription there isn’t necessarily an incentive to provide security updates even more, since they have the functionality of your app hostage if you decide to cancel and the automatic monthly billing has no ties to the quantity or wuality of updates they push out. That being said, security updates shouldbe part of the price you already paid, since a security flaw is a flaw in their original s…

That being said, security updates shouldbe part of the price you already paid, since a security flaw is a flaw in their original software. Security vulnerabilities generally aren’t considers latent defects under warranty laws (at least not in NA). I’m not sure what the tech world would look like if it were - for one thing, software teams would probably need a P.Eng. on their teams to ship. For another, using open sou…

> That makes no sense - you have it completely backwards. Their incentive to provide me with timely security updates is my continued subscription fees

You pay one subscription fee for both "I can use my app at all" and "security updates" together. Once there is enough inertia for you to not want to switch off, you'll probably keep paying (to use the app at all) even if they don't provide security updates.

If there were two fees - #1 a one time lifetime usage fee and #2 a security updates subscription fee then maybe that would make sense, but I don't think so otherwise

Post reply on HN