Live data from Hacker News

1Password for Linux beta

blog.1password.com

51–60 of 254 posts

Re: 1Password for Linux beta

#51
post #20

I would like to throw out Bitwarden out there. Cross platforms, works on everything and can be self hosted if you so desire.

bitwarden looks cool. what parts are open-source and what parts are closed? (are all the premium features closed-source or are they just charging for that in the hosted-by-them version?)

In the past it was entirely open source, though the hosted version did check for a license key before enabling the premium features. That said, the code for the premium features and the license key check were themselves open source.

I see some of the newer premium features, particularly around SSO are under a noncommercial visible source license of their own devising though

Re: 1Password for Linux beta

#52
post #41

In my opinion, it should be a bare minimum for something as important as a password manager to be free software. Others have mentioned Bitwarden and Keepass in this thread, both of which meet that criteria, but personally I'll stick with pass since I don't need a GUI.

What does that even mean? There is free alternatives. I use 1password because it does a good job.

Re: 1Password for Linux beta

#53

Unpopular opinion: using a password manager as a service is as bad as password reuse: all your passwords behind a single password.

I have MFA. Have fun

As if SMS was secure.

Your phone company will believe any random person to be you.

Not all factors are secure.

Re: 1Password for Linux beta

#54

Earlier quoted context omitted.

Honestly, I think your opinion is unpopular because it demonstrates a serious lack of understanding or thought. If you re-use the same password for all sites, it takes just one sketchy site being compromised for all of your other sites to become compromised. In the case of a password manager, the manager itself is the one that needs to be compromised, and you have more reason to trust them to avoid being compromised…

Your mistake is assuming I had not thought of that. I have, and my position remains the same.

[deleted]

Re: 1Password for Linux beta

#55
post #42
post #8

Earlier quoted context omitted.

So then what would you suggest?

Presumably the alternative to 'a password manager as a service' is 'a local password database and password manager which is not a service'. This can be something like password store, or keepass, where the attacker needs both your password database unlock key / gpg passphrase, but also needs access to the database / gpg keys, which means either physical access, or at least access to your local files. I think there is…

> If 1password allows anyone to make login attempts against their service, that means some bored teenager with a botnet can make attempts at your password.

They would need to guess both your master password and your 128 bit secret key.

https://support.1password.com/secret-key-security/

Re: 1Password for Linux beta

#56
post #48

Earlier quoted context omitted.

Your mistake is assuming I had not thought of that. I have, and my position remains the same.

Do you have a counterpoint, or do you have this opinion solely for the sake of having a contentious opinion?

Using a password manager is a good idea.

Using a password manager as a service is my point of contention.

Re: 1Password for Linux beta

#57
post #42
post #8

Earlier quoted context omitted.

So then what would you suggest?

Presumably the alternative to 'a password manager as a service' is 'a local password database and password manager which is not a service'. This can be something like password store, or keepass, where the attacker needs both your password database unlock key / gpg passphrase, but also needs access to the database / gpg keys, which means either physical access, or at least access to your local files. I think there is…

I can agree that a 'password manager' as a service is less secure than a 'local password database that's not a service', but that's not the comparison the OP made.

They compared passwords as a service to reusing a single password and said it was the same, which IMO is foolish.

Re: 1Password for Linux beta

#60

Earlier quoted context omitted.

As if SMS was secure. Your phone company will believe any random person to be you. Not all factors are secure.

I dont think my yubikey receives SMS

Yubikeys are secure, but the most popular second factor is SMS, followed by authenticators, which are better than SMS in my opinion.

MFA does not imply bulletproof security.

Post reply on HN