Earlier quoted context omitted.
I am using 6, and the classic extension still works for me on Firefox. It was only when they discontinued (and refused to port) the Safari classic extension that I couldn't use Safari anymore. [0]: https://support.1password.com/cs/1password-classic-extension...
Works for me on Chrome too, but not Brave (my browser of choice). Are there any security concerns holding on to 1p 6.0 ? I notice the mobile app still sees updates, but could there be in theory an unpatched security hold in the desktop app ?
1Password Has Raised $620M
491–500 of 723 posts
Re: 1Password Has Raised $620M
#492Earlier quoted context omitted.
Pretty typical for people here to be zoomed-in on the b2c side of a business because that's what they use, and fail to see the b2b side, the underwater mass of the iceberg.
I think people can see that this is targeting businesses, but they're not happy about that because they're non-business customers. It doesn't bode well for the future direction of what has up to now been a good consumer-focused product. Like how Dropbox has gone from "a folder that synchronizes your files" to "an electron app for having discussion threads about files" because that's what business customers want.
Re: 1Password Has Raised $620M
#493Earlier quoted context omitted.
I mean... that seems fine? Taking a consumer product and making a business version of it feels like a totally ok way to grow a company that already has a stable product that people like. Them making new features you don't use doesn't mean they're going to break or diminish the stuff you do use. Sure, they could mess it up, but any company or open source project can mess everything up.
I can't remember a company that has served individuals and enterprises simultaeneously without one side getting a compromised offering. One of the things I like about Apple is they don't really pander to the enterprise. They won't turn the business away but you can see it isn't a priority.
The problem comes in when you try to cripple the home version so that small businesses, etc don't just use that.
Re: 1Password Has Raised $620M
#494Earlier quoted context omitted.
> Because much like privacy, password security shouldn't always be only a premium option. So then who foots the bill? Password managers are the duct tape used to protect a user because we don't inherently trust application providers. > proprietary code is a deal break for lots of people Sort of. First, "lots of people" seems like "lots of people" because we're on HN. The wider population doesn't care whether your app…
Bitwarden does charge for certain features like TOTP support, organizations, and enterprise features. They manage to have subscription income while remaining open source, whereas 1Password chooses to keep its code closed source. If you are saying that Bitwarden is worse because it offers a free plan, I disagree. It's nice that Bitwarden offers a security-audited* password manager to those who can't afford a subscript…
Well said - and this is the important part of the 'non-proprietary' argument of mine (above) - right now I consider 1Password's real customers being their shareholders/investors, not its users - the users are just another tool they use to bring value to their real customers (investors,etc.).
BitWarden's customers are their actual users.
Re: 1Password Has Raised $620M
#495Earlier quoted context omitted.
Well, Hashicorp stands on many legs and they don't have much competition in many areas as theirs solutions are pretty unique...
Their solutions are unique but the problems they are solving are not, they are in direct overlap with where 1P is going.
Re: 1Password Has Raised $620M
#496Eh. I used to use 1Password long ago, when it was still a "normal" app (one-time payment, not trying to become a unicorn). It was easy for me to switch password managers (my needs are modest, and I generally like to break my app habits once in a while). My journey included (1) self-written manager; (2) LastPass; (3) pass CLI, and (4) Bitwarden (free tier). I'm now a happy Bitwarden user. It's ugly, and I'm a UX desig…
If you think "security" is the reason you have a password manager, how come all of your accounts are tied to your email address? If you just wanted security, there are, by far, more secure tools and practices you could employ than Bitwarden (among them keeping a notebook of passwords on your person at all times).
Your comment reads, to me, as a signaling effort. "I'm aware of bad corporations and I don't support them!" is less strong of a signal than you may think.
Re: 1Password Has Raised $620M
#497Re: 1Password Has Raised $620M
#498Earlier quoted context omitted.
But 1Password previously had the option to _not_ use their cloud, and they deliberately killed it to push people onto their subscription offering. So I think in the context of a conversation about how financial conditions will force changes which change the customer experience, I think it's entirely fair to compare them to a non-cloud option.
>they deliberately killed it to push people onto their subscription offering There are things available via the Cloud version that aren't available with local vaults and, in order to maintain those, they decided not to put the time into implementing those changes for local vaults. Local vault users are less than 1% of their user base.
Re: 1Password Has Raised $620M
#499I really wish they weren't doing away with 1password classic and the native mac app. I like the fact I bought a license, that I can store the data on dropbox or icloud, and it works just fine. Yes, this is old news and sour grapes on my part. I just don't yet feel like migrating to bitwarden. I've been using 1password for 12 years since I saw it on a tutorial on peepcode.com. I actually taught my mother how to use it…
Migrate to Bitwarden. I owned a 1 password 6 license and hung onto it for dear life until last year. I technically had a 1 password subscription from work, and when that ended last year, my password experience hit a brick wall. I couldn’t add passwords from Windows. My Mac client refused to work, I had to uninstall multiple times and delete a data directory to erase any sign that 1 password subscription was on the sy…
Re: 1Password Has Raised $620M
#500Earlier quoted context omitted.
> Even if you can tell a compelling story about how they carefully encrypt everything right now, you're always a silent update away from it all being dumped on the internet. This is also true for your operating system updates, browser, browser extensions, compilers, the infrastructure for your email service provider, any libraries those things use etc. Not to mention your local password manager. Even if you don't acc…
> This is also true for... Agreed, those are already risks, and ones that are a lot harder to mitigate (though I do try where I can). Does that mean I should add another one that I can easily avoid? There are risks in both local and cloud password managers. Maybe those risks seem equivalent to some folks, and the cloud features are useful enough for it to be a no brainer for them. For me, I don't at all mind manually…
> Does that mean I should add another one that I can easily avoid?
All other things being equal? Avoid it, of course. I firmly oppose letting perfect be the enemy of good in the sense that more secure is better than less secure even if it's not perfectly secure. But I also oppose it in the sense that rejecting beneficial functionality because it's not perfectly secure, especially when it's not close to the biggest or most attractive attack surface, doesn't make sense. Even when password managers' servers were compromised— LastPass, for example— I don't think anybody ever got ahold of passwords. KeePass OTOH was broken with KeeFarce and RATs are a lot more common than cloud service server breaches.
> This seems focused on the case of a dedicated attacker focused on you specifically. Id think each of us is more likely to be affected by various automated attacks that are backed by large dumps of account credentials.
Nope— If it was automated the distinction is even less significant. A script would only need to search your email for whatever specific types of logins it supported and fire off password resets. Non-email 2FA becomes even more of a hurdle without the option of social engineering it or some other human-touch fix.
Consider this. (very) Roughly, this is the market penetration for these products:
* computer: 90%+
* smart phone: 85%
* tablet: 50%
* computer, smart phone and tablet: 40%
Most people (in this country, at least,) have multiple devices. Most people have internet access. Most people aren't going to be able to manage storing and sharing passwords among their devices at all, let alone more securely than cloud storage would do it. So for most people's use cases, it would be like citing health when refusing to put a teaspoon of sugar into the cup of tea they're having with cake and ice cream.
So like I said, avoid it if it doesn't improve your life— I have no stake in your password management choice— but I will actively butt in to qualify the sentiments expressed in this thread because, a) many users, even on this site, aren't sophisticated enough to engage in the sort of cost/benefit analysis that we are, and b) to them, this conversation is unintentional FUD. Cloud-based password management is vastly superior to regular folks' existing methods. If they're put off by technically savvy people saying they're fundamentally insecure, that is the embodiment of perfect defeating good.