Live data from Hacker News

1Password 8 will be subscription only and won’t support local vaults

1password.community

541–550 of 685 posts

Re: 1Password 8 will be subscription only and won’t support local vaults

#541
I feel like Buttercup [1] doesn't get enough attention. Open source, available on all platforms, and has imports from multiple other password managers. If several people offered a small monthly donation for some time, we'd all be in a more competitive situation with password manager companies whose interests drift from our own through time.

[1] https://github.com/buttercup/buttercup-core

Re: 1Password 8 will be subscription only and won’t support local vaults

#542

Earlier quoted context omitted.

The hatred comes from their proliferation. With what seems like damn near everything moving to a subscription model, it's more money out of my pocket for usually what amounts to rent-seeking (i.e, demanding more money, more often, whilst providing no additional value). That last bit I don't believe applies to 1Password, because there are certain things you can't do without some kind of centralization, and the article…

> what exactly does moving from a purchase to a subscription benefit me? Trust that the company which provides something you need is far more likely to continue to be around. Suppose you tell your employer that you're taking a 1-week vacation. How does it benefit them for you to do that?

ultimately? less guillotines in the parking lot.

Re: 1Password 8 will be subscription only and won’t support local vaults

#543

Earlier quoted context omitted.

> I don't really understand the almost-automatic hatred of subscriptions. if an app has ongoing development that you benefit from, it seems entirely fair to pay a subscription. I don't _want_ the ongoing development. Photoshop from 5 years ago is perfectly fine for me. Same with Lightroom, etc. I mean, I've only paid Apple _once_ for Logic Pro and have been getting upgrade after upgrade for no cost -- a nice bonus, b…

They did. They offered standalone licenses and subscriptions for an entire version's lifecycle and 97% (or something crazy high like that) of the people who downloaded went for the subscription. I've been a standalone user since v3 and finally upgraded after realizing that buying a license for Windows, Mac, and Linux would cost me more over 3 years than just paying the subscription.

Let me tell you, as someone who used 1password since 3.x .. when I went to buy 7.x standalone it took me over an hour to find the page that let me buy standalone over three sessions.

Why did 97% buy the subscription? Because they hid the other version in a locked filing cabinet in a basement with a broken staircase.

Re: 1Password 8 will be subscription only and won’t support local vaults

#544

1Password used to be native on the Mac, and now it's an Electron app. I'm not going to be using 1Password for this reason, and I encourage you to do the same. Subscription business models and non-native apps are hallmarks of rot by VCs. Dump them!

Hi. I'm a feature developer for 1Password, and I want to clarify a few things. I've already posted this elsewhere, but I've seen multiple threads spreading misinformation that our technical decisions are being driven by VC funding. This could not be farther from the truth. We have been working on these changes long before we received any form of outside investments. Over the past few years, we've been working on cons…

Does that new "core" prevent you from syncing via iCloud?

Re: 1Password 8 will be subscription only and won’t support local vaults

#545

1Password used to be native on the Mac, and now it's an Electron app. I'm not going to be using 1Password for this reason, and I encourage you to do the same. Subscription business models and non-native apps are hallmarks of rot by VCs. Dump them!

> Subscription business models I think a subscription business model is the only honest way to sell software that will require ongoing support. If you're comfortable with a snapshot w/o updates, then by all means buy once, but I think coming to terms with the demands of ongoing support also means coming to terms with continuing to support the product in some way. That said, I wish there were more variations in the wa…

why does 1password need ongoing support? Take these strings, encrypt them. Let me decrypt them using a password i specify. Let me search for them and sort them.

Done.

Re: 1Password 8 will be subscription only and won’t support local vaults

#546

1Password used to be native on the Mac, and now it's an Electron app. I'm not going to be using 1Password for this reason, and I encourage you to do the same. Subscription business models and non-native apps are hallmarks of rot by VCs. Dump them!

1Password on Linux is electron, and works wonderfully. Though, it's kind of sad for Mac users as they have been spoiled with native experiences for a long time.

Is that "spoiled" or jsut the way things should work?

Re: 1Password 8 will be subscription only and won’t support local vaults

#547

1Password used to be native on the Mac, and now it's an Electron app. I'm not going to be using 1Password for this reason, and I encourage you to do the same. Subscription business models and non-native apps are hallmarks of rot by VCs. Dump them!

Hi. I'm a feature developer for 1Password, and I want to clarify a few things. I've already posted this elsewhere, but I've seen multiple threads spreading misinformation that our technical decisions are being driven by VC funding. This could not be farther from the truth. We have been working on these changes long before we received any form of outside investments. Over the past few years, we've been working on cons…

>would cause a lot of needless development churn and hassle

The hassle of doing what your users are paying you to do? Any child can hack a UI together in HTML but there's a reason no one (usually) pays for that.

Re: 1Password 8 will be subscription only and won’t support local vaults

#548

I highly recommend Enpass -- solid UI, single purchase, local vault, and a very handy option to sync via Dropbox (and probably through other services as well).

Thanks for this! Looks interesting. I feel like I should have heard of it before... any idea why it's under the radar?

Re: 1Password 8 will be subscription only and won’t support local vaults

#549
post #485
post #452

Earlier quoted context omitted.

Simply not the same thing at all.

Why not? I had this setup for years before switching to bitwarden_rs. You have apps on every device to access your password database and do autofill. I stored everything in KeePass, recovery keys, TOTP seeds, sensitive documents and notes. I get the password sharing thing for families but for a single user they have the same featureset. The only thing missing is browser access but even though I now have browser acces…

It's not the same thing because the whole argument being made is in the context of 1Password and its target audience: normal users. That's your mum and dad and other very likely non-techie people.

Your choice of solution isn't the same thing.

Re: 1Password 8 will be subscription only and won’t support local vaults

#550

Earlier quoted context omitted.

In such a setup where the second factor is a TOTP I would count on the attacker being successful at phishing that too.

I previously thought that we were just having a difference of risk tolerance, but if you think some rando can _phish_ a TOTP secret, we are not even in the same universe of risk mitigation > Hello, dear sir, this is the USA IRS and we are going to send the FBI because your TOTP code is expired and are going to put you in jail if you don... hello? hello?! > Click this link and paste in your TOTP secret because we need…

For passive phishing (e.g. setting up an identical website to the real one) stealing a valid TOTP token is trivial and such campaigns have already been spotted in the wild [1]

> if you think some rando can _phish_ a TOTP secret

Given the context this discussion is about (someone with a 1Password vault, storing unique passwords and TOTP secrets for each account they have) do you see any scenario in which a user gets his password stolen but not the token (or the OTP secret seed altogether)?

> Hello, dear sir, this is the USA IRS

If an attacker via a phone call is able to get the victim to (a) unlock their 1Password vault, (b) spell out their password for account X, what makes you think they couldn't get them to also (c) open their 2FA app and spell out their TOTP token?

> I previously thought that we were just having a difference of risk tolerance

The point I was making is that there are no security advantages to setting up a time-based OTP as a second factor for authentication if the secret seed is going to be stored in the same vault where the passwords are: might as well just forego this TOTP setup altogether and save the extra hassle. Or get a hardware second-factor (TPM, Google Titan, Yubikey, ...)

[1]: https://www.zdnet.com/article/new-tool-automates-phishing-at...

Post reply on HN