Live data from Hacker News

1Password for Linux beta

blog.1password.com

41–50 of 254 posts

Re: 1Password for Linux beta

#41
In my opinion, it should be a bare minimum for something as important as a password manager to be free software. Others have mentioned Bitwarden and Keepass in this thread, both of which meet that criteria, but personally I'll stick with pass since I don't need a GUI.

Re: 1Password for Linux beta

#42
post #8

Unpopular opinion: using a password manager as a service is as bad as password reuse: all your passwords behind a single password.

So then what would you suggest?

Presumably the alternative to 'a password manager as a service' is 'a local password database and password manager which is not a service'.

This can be something like password store, or keepass, where the attacker needs both your password database unlock key / gpg passphrase, but also needs access to the database / gpg keys, which means either physical access, or at least access to your local files.

I think there is some merit to pointing this out. If 1password allows anyone to make login attempts against their service, that means some bored teenager with a botnet can make attempts at your password.

I use password-store, and I could tell you my gpg passphrase right now, but you still couldn't access any of my passwords. You'd need to get access to my yubikey and my psasword repository before you could do anything with that passphrase at all.

I think it's true that a setup like mine, which requires a physical hardware token to decrypt my passwords, is more secure than a password service, however I also think the parent comment is totally wrong. 1password without a hw token isn't the most secure option, but it's way better than password reuse on random sites.

Re: 1Password for Linux beta

#43
post #40

Earlier quoted context omitted.

I'm talking about the program, not their website. It makes you enter an email before you can do anything. Says "Log in or create new account to access your vault", with a "Create account" button that asks for an email.

Click the settings "cog" and enter your self-hosted address. Of course you need to have setup your own self-hosted instance first :)

Oh I see, thanks!

Re: 1Password for Linux beta

#44
post #7

Oh good it's another Electron app and since there are only about 50 random dependencies mentioned in the package.json maintained by about 25 random people, exfiltration of all your passwords is only one of those being compromised away at any given point. And that is just the direct dependencies, I don't even want to look at the tree of it all. If you trust 1password with your passwords, really you are also trusting w…

The article says that it's written in rust, and also implies that it is a gtk app. That doesn't sound like an electron app to me. Did I miss something?

Re: 1Password for Linux beta

#45
I have been using LasPass since many years ago. There's an extension for Chrome and for Firefox. On Android I use the app and even though experience is not that "automatic" it works. I am surprised nobody mentioned LastPass is there any reason I should know?

Re: 1Password for Linux beta

#46

Earlier quoted context omitted.

Honestly, I think your opinion is unpopular because it demonstrates a serious lack of understanding or thought. If you re-use the same password for all sites, it takes just one sketchy site being compromised for all of your other sites to become compromised. In the case of a password manager, the manager itself is the one that needs to be compromised, and you have more reason to trust them to avoid being compromised…

Your mistake is assuming I had not thought of that. I have, and my position remains the same.

Then you should explain why you think what you think instead of just throwing around self proclaimed "unpopular opinions" without any explanation.

With the information you've provided (i.e. none), it really just looks like an uninformed opinion.

Why do you think the points I listed above don't make password managers more secure than password reuse?

Re: 1Password for Linux beta

#48

Earlier quoted context omitted.

Honestly, I think your opinion is unpopular because it demonstrates a serious lack of understanding or thought. If you re-use the same password for all sites, it takes just one sketchy site being compromised for all of your other sites to become compromised. In the case of a password manager, the manager itself is the one that needs to be compromised, and you have more reason to trust them to avoid being compromised…

Your mistake is assuming I had not thought of that. I have, and my position remains the same.

Do you have a counterpoint, or do you have this opinion solely for the sake of having a contentious opinion?

Re: 1Password for Linux beta

#49

Earlier quoted context omitted.

Honestly, I think your opinion is unpopular because it demonstrates a serious lack of understanding or thought. If you re-use the same password for all sites, it takes just one sketchy site being compromised for all of your other sites to become compromised. In the case of a password manager, the manager itself is the one that needs to be compromised, and you have more reason to trust them to avoid being compromised…

Your mistake is assuming I had not thought of that. I have, and my position remains the same.

Even though you thought of ways in which A is more secure than B, your position that B is just as secure as A remains?

Also: What is, in that case, the proper solution ordinary people should follow?

Re: 1Password for Linux beta

#50
post #41

In my opinion, it should be a bare minimum for something as important as a password manager to be free software. Others have mentioned Bitwarden and Keepass in this thread, both of which meet that criteria, but personally I'll stick with pass since I don't need a GUI.

I use pass(1) as well. I love that it allows me to use my yubikey.

Also a 1password user. Can't deny it's a wonderful product.

Post reply on HN