Live data from Hacker News

1Password 8 will be subscription only and won’t support local vaults

1password.community

341–350 of 685 posts

Re: 1Password 8 will be subscription only and won’t support local vaults

#341

Earlier quoted context omitted.

Not sure why I'm being downvoted...: https://support.1password.com/recovery/ Ps. They can delete accounts too: https://support.1password.com/add-remove-family-members/

> Ps. They can delete accounts too: https://support.1password.com/add-remove-family-members/ This makes losing local vault support an even bigger cause for alarm: > After you remove a family member’s account, they can’t sign in to 1Password, which means: > They lose all the items in their Private vault. Because the items weren’t shared with any other family members, no one will be able to access them. Imagine: the ac…

So don't use the family plan?

Re: 1Password 8 will be subscription only and won’t support local vaults

#342
post #99

Earlier quoted context omitted.

What caused me to not consider Bitwarden was the way it handled iframes. It could send the parent sites credentials to an iframe even if the iframe was on a different domain. This is a big no-no in my book. This was a discovery in a security review they did and choose not to change. This was some time ago so things may have changed. But, that red flag kept me away.

Most likely because credit card forms are very often served in iframes. 1Password fills iframes too (though maybe only for cards, not sure).

1Password fills iframes based on their domain rather than the parents. If you have an entry in 1Password it will use the value for the domain of the iframe.

I’ve gone so far as to test this.

In my opinion this is the right security model

Re: 1Password 8 will be subscription only and won’t support local vaults

#343
I am a 1PW subscription user and am happy with the product (however, seeing they are moving to Electron means that is very subject to change...)

but

Saying that "customers voted with their wallet" and chose subscriptions is disingenous

Ever since they've had subscriptions they've made the standalone license page extremely difficult to find on their site. They really didn't give regular users a "choice"- they dark-patterned them into thinking subscriptions were the only option

As forthcoming / down-to-earth as these posts from the company seem- they are full of spin. Their impossible-to-find standalone license page is a topic they seem to be avoiding.

Edit to add this small addendum: It just really bothers me on an emotional level to constantly run into this juxtaposition as a user of software/hardware: liking a product but being extremely disappointed in the company offering it.

Re: 1Password 8 will be subscription only and won’t support local vaults

#344
post #142

I know what 1Password is but haven't used it. Are there advantages of using it over Apple's built in keychain? Would appreciate if someone who has used/uses 1Password could comment on this.

Keychain is not quite a password manager. It has a field for user name and password, both mandatory. A password manager offers a lot more, including a field for notes or credit card numbers.

FWIW, Keychain Access supports secure notes as well.

Re: 1Password 8 will be subscription only and won’t support local vaults

#345

Earlier quoted context omitted.

Hi. I'm a feature developer for 1Password, and I want to clarify a few things. First of all, our decision to built the macOS app in Electron was absolutely not driven by VC money. For the past few years, we've been working on consolidating 1Password's business logic into a single Rust-powered core that could be shared across all our apps. This has many advantages: feature consistency across platforms, faster developm…

This would be an appropriate riposte to [1], a vitriolic comment that draws the line between VC money and Electron, but not to parent. Parent makes a lot of sense, actually, in context of the submission headline. There was no misinformation here at all. [1] https://news.ycombinator.com/item?id=28145755

Thank you for pointing me to that thread. I'll make sure to respond there as well.

I did (incorrectly) assume that the parent was talking about Electron, so that's my bad. That being said, our decision to move away from licensing is absolutely not being driven by VC funding, so the parent comment is also spreading misinformation. We were building a subscription-based model all the way back in 2014, and we're phasing out licenses for the host of reasons that were mentioned in the original article.

Re: 1Password 8 will be subscription only and won’t support local vaults

#346

Earlier quoted context omitted.

> $4.99/month for 5 people is affordable. I’m glad you find it affordable but these nickle and dime things add up. Especially when the product fits into $0 software so $4.99 is infinitely higher than $0. I feel like these small, “affordable,” services are just whittling away the Unix philosophy of do one small thing well. Layering on unnecessary crap just to charge a fee eventually comes home to roost. Also, password…

> Especially when the product fits into $0 software so $4.99 is infinitely higher than $0. What is the competition that costs $0? Bitwarden is $3.33/mo for equivalent functionality to the $4.99/mo plan from 1Password.

KeePass ( https://keepass.info/ ) with something like Nextcloud ( https://nextcloud.com/ ) or any other solution for syncing password databases across devices.

Let's Encrypt SSL/TLS certificates are free, as is Apache/Nginx/Caddy to reverse proxy Nextcloud or any other solution (if a web based interface is needed). You might also need something like ngrok ( https://ngrok.com/ ) for publically accessing the instance if you're behind NAT and are hosting it on a homelab, or alternatively just put it on one of the VPSes that you're using, if you have any.

Personally i'm using a similar setup (a WireGuard VPN tunnel or two in there as well) on my pre-existing VPSes, so the effective costs are 0$ for me. And the file based approach is actually superior to any (possibly) dubious browser plugins in my eyes.

Re: 1Password 8 will be subscription only and won’t support local vaults

#347
I've been a happy user of the same version of 1Password 6 for many years, the last non-subscription version. It still works on MacOS Big Sur, and the classic extensions work in Firefox and Chrome (though not safari on the mac). When it stops working, I guess I'll have to look elsewhere.

Re: 1Password 8 will be subscription only and won’t support local vaults

#348

I think one of the best things the U.S. government could do would be to buy and nationalize 1password and give everyone a license. Canadians too, since it was one of your companies :-) I am being intentionally outrageous but do genuinely feel that a good password manager is foundational to good digital security and I find it baffling that it does not come bundled with operating systems or in some other way offered fo…

>or in some other way offered for free

bitwarden is free (and open source) and it has just about every feature that the paid ones have. Sync across devices, desktop and mobile clients, notes etc. One of the best pieces of open source software of the last few years and I have no idea why people are paying subscription fees.

Re: 1Password 8 will be subscription only and won’t support local vaults

#349

I guess I’m the outlier in being very happy with 1Password and fine with paying for the subscription service. Not only is 1Password the best password manager I’ve used, but it makes it seamless to share stuff with my wife. I don’t care if 8 is an Electron app either, considering I usually interact with it via the browser anyway with their extension. (Also I know that the majority of what they wrote for it is Rust and…

I've been using 1Password for 3 years now. Been paying $35/year and I'm with you on this one. I really like their service. The integrations are great. I rarely use their Mac app. I use my Apple Watch to unlock 1Password in my browser. That for me, is a game changer. It's such a seamless experience. I'm a happy customer and I love the service.

I didn’t know this is a thing… I’ll have to look into it - thanks

Re: 1Password 8 will be subscription only and won’t support local vaults

#350

Earlier quoted context omitted.

I am cognizant of this risk, and assume it, because security is always a spectrum between Secure and Convenient. If I had to pull out my phone every time I wanted to use 2FA, I for sure would not be so liberal to turn it on for all the "low value" properties the way I do now I have never even _heard_ of someone having their 1P master password compromised and the vault(s) exfiltrated (although I grant you it could be…

> I am cognizant of this risk, and assume it, because security is always a spectrum between Secure and Convenient. Absolutely. But also, in such setup, the security benefit of 2FA/OTP codes are negligible at best since there are no conditions under which only one factor could be compromised without also having the other factor leaked (assuming you're using unique passwords for each identity, which is the entire point…

> (assuming you're using unique passwords for each identity, which is the entire point of a password manager)

If you're doing this there's a very limited benefit to TOTP anyways.

Post reply on HN