Live data from Hacker News

1Password for SSH and Git (Beta)

developer.1password.com

391–400 of 406 posts

Re: 1Password for SSH and Git (Beta)

#391

Earlier quoted context omitted.

Could you share a little bit about what you'd want to use this for? (I'm part of the 1Password design team)

Thanks for replying! As long as I have your ear, I've got another question about the 1Password command line tool, "op": https://1password.com/downloads/command-line/ I am trying it out, and hope it will be as useful for cases like using the Google Cloud CLI's secrets command to retrieve secrets in automated scripts, like "gcloud secrets versions access latest --secret=wildcard_foo_com_pem". https://support.1password.…

Thank you, Don!

Did you have a chance to look at CLI 2.0 and 1Password 8 integration: https://developer.1password.com/docs/cli/use-biometric-unloc...

Re: 1Password for SSH and Git (Beta)

#392

Earlier quoted context omitted.

We added spellcheck and text transformations options recently. Our team contributed a few patches to Electron to enable better macOS integration. For example: https://github.com/electron/electron/pull/32024 I believe the UX performance in 1Password 8 is better than any other app we built in the past: https://twitter.com/mitchchn/status/1491253916004147203?s=20 Would love to learn more about the standard shortcuts tha…

I have filed a couple of issues on the community board, but there are two things which are dealbreakers to me (most of the rest of the issues — including the attachment data leak — have been resolved). 1. I despise the binding of ⌘- and ⌘+ to zoom, and even more ⌘0 to zoom reset. I know that those are standard Electron things, but there’s absolutely no reason to make them priority bindings for 1Password. Beyond the z…

Thank you so much for the feedback!

2. It might look silly but we actually had an internal debate about making the preference for floating preference window. I personally do not mind the single window approach because it makes things easier for the non-experienced users. I watched my mother-in-law losing the preferences window when she tried to configure 1Password 7. I know there are certain articles claiming that all Mac apps must have a floating Preferences window but there are quite a few counter-examples as well. Anyway, that preference might still happen.

1. I certainly relate to the pain about muscle memory when it comes to the keyboard shortcuts. At the same time, having an option to easily adjust the zoom settings for an app is such a great feature. I used 1Password on a 13" laptop and on Pro Display HDR and I love the ability to change the zoom factor. I now wish I could do this in every app. Perhaps a solution could be to make all keyboard shortcuts customizable?

Re: 1Password for SSH and Git (Beta)

#393

Earlier quoted context omitted.

I have filed a couple of issues on the community board, but there are two things which are dealbreakers to me (most of the rest of the issues — including the attachment data leak — have been resolved). 1. I despise the binding of ⌘- and ⌘+ to zoom, and even more ⌘0 to zoom reset. I know that those are standard Electron things, but there’s absolutely no reason to make them priority bindings for 1Password. Beyond the z…

Thank you so much for the feedback! 2. It might look silly but we actually had an internal debate about making the preference for floating preference window. I personally do not mind the single window approach because it makes things easier for the non-experienced users. I watched my mother-in-law losing the preferences window when she tried to configure 1Password 7. I know there are certain articles claiming that al…

On the pseudo-modals:

The preferences is small enough that I don’t care about that as much. It’s symptom as much as anything else.

The pseudo-modal for collection management is painful.

I never want to open that pseudo-modal _again_ because it’s so awful. It’s narrow, it doesn’t let me look at the vaults while I’m working through what should be in a collection, etc.

This is a problem because it’s a major feature and someone who has used 1Password from the days when it was 1Passwd and you ran the Switcher’s blog…that’s bad news for the success of the feature. Never mind that this is the only way to get to the previous behaviour of "all vaults" meaning "all vaults that have been selected to show in all vaults" and that so that you’re not constantly getting shown things that you don’t want to see by default because the collection you have the old "all useful vaults" is on ⌘5 instead of ⌘1 or (better yet ⌘0).

On the zoom:

Keep the zoom, if you must. But for the love of Jobs, don’t bind it to ⌘-, ⌘0, and ⌘=. ⌘0 should be _either_ "show preferred collection or account" or "show main window" (leaving ⌘1 for "show preferred collection or account"). Seriously, that binding is the absolute #1 thing that I hate about the Slack app, and there are _legions_ of things to hate about that. Leave the zoom options in the View menu, because your mother-in-law, if she wants to zoom in isn’t going to remember ⌘= to zoom in. She’ll look in the menus.

1Password 8 is _much_ better than it was when I started using it in July. But these two things actively make me _angry_ about using it because: (1) the pseudo-modal, especially for collection management, makes me not want to use something that looks much better than previous mechanisms, and (2) the zoom gets in the way. I’m using 1Password on a single monitor (14" MBP, previously 13" MBP) and I want to set my zoom _once_ and never think about it again, especially if I hit ⌘0 (thinking "show main window" or "show preferred collection or account") but it resets my zoom. Having the zoom bound is a papercut that happens to me multiple times a week because it makes no sense in anything except a web browser.

Re: 1Password for SSH and Git (Beta)

#394
post #369

Ahh, this is such a nice improvement over literally anything i've used for agent key management on Windows or Linux, and easily competes with using the Keychain integration available on OSX; It sucks that I can't really use the functionality due to the v8 requirement, and am once again in the position of paying for something where I don't get to actually use new and useful features due to really aggressive ( if not o…

I’m not sure your critique of v6 to v7 migration is fair. Im sure v6 continued to work fine on that old version of chrome. But it seems perfectly reasonable for developers to be compensated for writing new code to work with new versions with new requirements. I also feel I should be realistic about the incentive structure. I want 1password to continually work on security, additional features, and quality of life stuf…

> I’m not sure your critique of v6 to v7 migration is fair. Im sure v6 continued to work fine on that old version of chrome. But it seems perfectly reasonable for developers to be compensated for writing new code to work with new versions with new requirements.

I don't disagree that they should be compensated for new versions, however, I think we have a difference of opinion on what qualifies as a patch; I'm not intrinsically against upgrading license types ( though I don't like the move to subscriptions-only ), but I also expect the software I've already paid for to be updated when a major selling point feature ( browser integration ) breaks, especially if it's only the previous version ( in spirit or in practice ).

To be honest, though, I don't really expect they'll have a similar situation in the future now that they're actively maintaining all platform versions ( and with a unified core! ), so I'm being bitter over the past and letting it seep into how I feel about v8, local vaults, and control of my data.

Re: 1Password for SSH and Git (Beta)

#395
post #23

Earlier quoted context omitted.

There is a slight risk - if someone has your public key they can setup a MITM server and pretend to be the one you’re expecting - and watch what you’re doing, or redirect test to production or similar. It’s really very minor and ssh itself should warn that the servers fingerprint changed.

Public keys are identity, so, a remote server can (and a famous one does: https://github.com/FiloSottile/whoami.filippo.io ) tell you if e.g. you connect to it while offering to prove your identity with keys github knows about, because github provides a list of those keys. That's the extent of the interesting consequences of knowing your public keys. You can't realistically MITM SSH because you will have a session mi…

Well, there is a non-negligible chance that the client has agent forwarding turned on, in which case the MiTM box could splice the connection to the real some.machine.example.

Re: 1Password for SSH and Git (Beta)

#397
post #271

And here I am, logging into Linux boxes without entering passwords nor SSH keys thanks to the magic known as Kerberos. Open up my corporate laptop and login with my smart card and username/pass combo, then I can just log into any Linux machine I have authorization (group permissions) to. Been doing it this way for over a decade at this rate. It's like all of these password manager tools were created by people who've…

> It's like all of these password manager tools were created by people who've never seen nor used these existing solutions. Maybe, but it sounds like your comment was written from a place where you've never had to actually implement one of those existing solutions. Kerberos is great. It's also a holy terror to implement properly, especially cross-platform, and especially if you need to federate identity. I've been do…

>Maybe, but it sounds like your comment was written from a place where you've never had to actually implement one of those existing solutions.

I absolutely have implemented the aforementioned solution. Used to be a right of passage for middling UNIX syaadmins.

>Kerberos is great. It's also a holy terror to implement properly, especially cross-platform, and especially if you need to federate identity.

Not really, especially not really if you Active Directory.

>SCIM combined with modern cloud SSO makes life much easier than trying to support Kerberos.

SCIM with Active Directory (AKA Kerberos) works well.

Re: 1Password for SSH and Git (Beta)

#398
post #331

Earlier quoted context omitted.

I find it to be a decent experience (and use it for exactly what you mentioned). Comparing the two methods I've personally used to store my insurance card below. What are you comparing to? 1Password: - Search - Click on the relevant entry - Click "Quick Look" - Click down menu - Click show in Finder - Drag onto upload form field Google Drive: - Search - Right click - Download - Right click on downloaded file botton -…

Ideally I should be able to copy things directly out of 1PW. right click, copy. Or the app should use a widget that supports click/drag. It took me a while just to DISCOVER the steps to getting a file out of 1pw, which involved a lot of false starts into different menus/screens that allow you to view the file's metadata (or preview) without actually getting the file. Considering "copy field" is THE main functionality…

Agreed it could be a bit quicker or more intuitive, but this seems to be a use-case I don't need to work with too often, so it's not bothered me.

I'm guessing there's a mix of performance concern and privacy concern. They want to make sure you're intentionally revealing the secret (image) and they want to hold off on decrypting the file until needed. It feels like decrypting a file is a fairly slow operation (although I'm not really sure why).

I just don't think comparing to the file in your local files is quite the same, since it's not encrypted / behind password protection. If you did this sort of thing a lot, you'd probably have it optimized down to a very accessible shortcut, after all.

Re: 1Password for SSH and Git (Beta)

#399
post #157

Earlier quoted context omitted.

Did you mistype $2.99? Because it's $2.99 for one person. The $19.99 is for ten team members using the business product. A family of 5 gets it for $5 per month.

yes, sorry my bad. It is $2.99. By default pricing page goes to "Team & Business" tab. I need to select "Personal & Family" for the price I was looking for my use case. Thanks!

It's 100% worth it in my opinion. I've been using it for 8 years now.

Re: 1Password for SSH and Git (Beta)

#400
post #379

Earlier quoted context omitted.

We didn't store keys in the AMI. We added the public half to EC2 then attached that key to the launch configuration where it gets added to the VMs authorized_keys on startup. I don't think running a Userify daemon on the server is better than a private key in 1Password. At least with the private key approach, you can layer on network access restrictions (firewall rules or VPN). Userify would need to create an outboun…

The Userify daemon in this case is just a shell or python script ( https://github.com/userify/shim ) so pretty simple to audit.

Sure but it's still reaching out to a cloud service for auth info.

You swap "someone could steal my private key from SaaS" with "someone could upload an additional key to SaaS" which I guess just helps if you're reusing keys for unrelated systems?

I think Userify could potentially increase auditability by limiting key sharing but I don't see it actually increasing security assuming you can revoke/rotate shared keys.

Post reply on HN