I believe you can still self-host if you want. I don't understand how can you be disturbed by offering a cloud service to host your passwords could be bad to switch. I'm happy sub of 1Password and i self-hosted my passwords before for a long time.
This is the kind of thing where more paranoia is better. Their service is a big fat target. I don't understand how you can't be disturbed by that.
All the encryption happens client-side. For this to be a problem you not only have to gain access to the blobs stored on their service, but you also have to be able to decrypt them.
I expect they probably pay more attention to abnormal access than most self-hosted users would as well, so you'd actually know about a data leak faster so you could rotate your passwords.
I believe you can still self-host if you want. I don't understand how can you be disturbed by offering a cloud service to host your passwords could be bad to switch. I'm happy sub of 1Password and i self-hosted my passwords before for a long time.
This is the kind of thing where more paranoia is better. Their service is a big fat target. I don't understand how you can't be disturbed by that.
Personally, I'm more comfortable with a service that has entire teams whose entire job is finding and fixing holes in the service than I am with something I toss on a server somewhere and forget about for months at a time.
Realistically, which is more likely? 1) That 1Password gets breached and loses their customer information, or 2) that I install Bitwarden on my server, somebody discovers a hole in it, I don't hear about it for a while (or do but don't have time to update), and get all my passwords stolen?
For me, the second seems more likely, so I'm happy to stick with 1Password.
There are also advantages for the user. For example, new features arrive for all platforms at the same time; there is no prioritization of platforms or such. Same for bugs - apart from issues stemming from Electron itself, they're likely to appear on all platforms and therefore likelier to get fixed. In essence, the old "only X% of our users use platform Y, it's not worth it to make this feature/fix this bug for them…
> For example, new features arrive for all platforms at the same time That (and everything else you said) is true for any cross-platform framework, not just Electron.
None of this is even relevant in this case, since they use (I hope) Cocoa/UIKit/whatever it's called on macOS, so there's anyways not _one_ framework used everywhere.
This comment is like a canonical example of why a company would choose not to develop for Linux. 1Password puts real resources and risk into supporting a platform that may not pay off, but it’s Not Good Enough for much of the community because: -The client is not open source -the backend is not open source -it’s not “a first class citizen” right away (the Windows port is by all accounts improving) I’m not trying to p…
My takeaway of the grandparent comment is that 1Password squandered much of its customer goodwill, missed the opportunity to move into the Linux market, and their current attempts to build Linux support is too little too late. If this story came out in 2015, I think the response would be a lot more favorable. At this point Bitwarden checks all those boxes and costs nothing, so it's hard to compete.
Yeah, I would note that not only is the Bitwarden code Open Source (if you want to self host), the commercial service has a free account option, and the pay options are about $1 per month per person:
Woah! I think a lot of people in the free / open source community might have a problem with such a statement. However, I do pay for a password manager because I recognise their importance and view them in a slightly different, almost unique way. I'm not averse to paying for software and services online, too.
What problems do you think they have?
Software is moving away from the classic buy-model and into a subscription/rent based model.
>Why the hate for electron? Because it's terrible. It's slow and ponderous. I have yet to use something built on it that wasn't awful, and that INCLUDES VSCode.
Have you tried 1Password for Linux? - Ben, 1Password
No reason to. I don't use desktop linux.
I'm also actively looking to move away from 1P period because I don't want or need a subscription for every little app.
Developing for every platform has unique properties. Every platform has its own native UI toolkits and look-and-feel; try to release an Electron app, and people complain. Write a great iOS app, but no iPad port, or be a couple months late with support for The Notch, people complain. Linux's main difference is that, with so few users, when their priorities are disrespected by Big Corporate, the populace sides with Big…
The Linux priorities I outlined are fundamentally different. It’s a demand that the maker of the software alter the core of their business model. This is very different from asking for a native UI or to use a core OS API, etc. Again, it’s fine to ask for a radical business change or require it but the frequency of this as a demand does help explain why few companies go down this path. (As for 1Password abandoning one…
They've absolutely crippled 1password to make local vaults as difficult to buy and use as possible. They don't roll out updated versions as often, many versions don't get support for local vaults for years, they make it nearly impossible to buy the non-subscription version, and you can no longer upgrade older licenses to use new versions. Their entire business model is really sleazy and they've gone out of their way…
> Every company that has moved to a subscription and cloud-based product has essentially traded a one time $30-50 license to getting that (or more) every year, and the product is usually inferior from my experience. Two mild counterpoints: (1) While "from my experience" is always definitionally anecdotal, most applications that I'm aware of that have moved to (or started with) a subscription-based model have released…
I really don't think I could've said it better myself. Thanks for the comments. - Ben, 1Password
* I will never buy a subscription from you but I've been happily paying to upgrade every time you release an upgrade to the regular software.* So you are a subscriber in reality, it's just your payments a slightly lumpy.
A subscription implies you lose access to the software when you stop paying the subscription. Buying a license implies you own it and are entitled to use it indefinitely. You might not get any updates but you also aren’t losing access to what you already paid for. Very, very big difference.
While I understand where you're coming from, I think "indefinitely" is a fairly impractical viewpoint in the sense of modern computing, particularly in the context of 1Password. Presumably you'll continue to update your web browser and your OS, which will at some point necessitate updates to the 1Password apps. For example, with Safari 13, which came baked in with macOS 10.15, Apple changed their entire extensions framework and retired the old one. 1Password 6 was built around the old one. So even if you have a license, and could theoretically install 1Password 6, if you're a Safari user it doesn't do you much good. Membership on the other hand would've included 1Password 7, where we implemented a Safari App Extension for Safari 13+ support. Just a counter-point for consideration. Also, for what it's worth, 1Password memberships become read-only when your subscription lapses, but you don't lose access. - Ben, 1Password