Live data from Hacker News

1Password Has Raised $620M

blog.1password.com

591–600 of 723 posts

Re: 1Password Has Raised $620M

#591

Well, we're using dashlane for free right now and planning to pay for it (It's really cheap). I don't know what would be the use case for switching to this brand since now their focus will be to grow or die.

https://www.dashlane.com/cs/1k5JfApcebh1 - 6 months free right here

Re: 1Password Has Raised $620M

#592

Both the Fastmail[0] and Privacy [1] integrations have made 1Password a joy to use in the past few years. I've used premium BitWarden in the past, but the UX of 1Password is hard to beat. Congrats to the 1Password team! - [0] https://blog.1password.com/fastmail-masked-email/ - [1] https://blog.1password.com/privacy-virtual-cards/

A lot of comments don't seem to acknowledge the importance of UX to leveling up security. Historically, security products have had terrible UX with everyone working around these and introducing more risks. 1Password is doing a great service here by making security simple and reduces our overall attack surface.

I wholeheartedly agree with the UX comment, and for the "leveling up security" part specifically, I'll point out that 1P 8 now has a "generate horse-battery-stable 'security question' answers" button, which is about as close to the intersection of good UX and good security as I can imagine

My experience with Bitwarden is that their browser extension is gravely broken, which is a subset of UX, but crosses over into "how is this not a 'stop all work and fix it' bug?": https://github.com/bitwarden/browser/issues/1620

I have a paid Bitwarden subscription, because I wanted to give it a fair shake, but based on my experience thus far it'll be years before they catch up to AgileBits

Re: 1Password Has Raised $620M

#593
post #426

I really wish they weren't doing away with 1password classic and the native mac app. I like the fact I bought a license, that I can store the data on dropbox or icloud, and it works just fine. Yes, this is old news and sour grapes on my part. I just don't yet feel like migrating to bitwarden. I've been using 1password for 12 years since I saw it on a tutorial on peepcode.com. I actually taught my mother how to use it…

I don't even mind the subscription fee and cloud hosting personally, just make a kickass native app like they always had and I'll stay. If they force me to "upgrade" to 8 and it's not a native app then I'll just use something else like bitwarden.

I would be happy to pay the subscription fee for a native app, especially since my partner and parents can use it under the family plan. It works great for that! I've been paying for upgrades since 2007 (version 2.0 I think).

Except that version 7 also introduced some massive UI/UX regressions! There were so many that I started collecting them in a Ulysses note so that I wouldn't forget why 1Password has gone so far downhill.

----

Attachments:

- Attachments used to be attached to entries by drag files there, and they'd show up at the bottom (if I wanted my passport, there'd be a single Passport entry with copyable fields + jpeg photos of front and back at the bottom).

- Now, every attachment is a separate document cluttering up everything. If I want my passport, I search for "passport" and three separate entries come up: entry with passport details I can copy, and passport-front.jpg and passport-back.jpg. And if I delete Passport entry, the jpegs are still hanging around.

- See [1][2]

----

When it doesn't sync, there's no "force sync" button on iOS. So I just sit there waiting...

----

Can't suppress "duplicate password" warning:

- If I reuse a password on two or more entries, each of those entries shows this warning

- No way to disable it, clutters up the UI

- Some entries have an insecure password for local use, dev use, whatever, so let me disable the warning

- Tons of threads on their forums about this complaining about it [3][4][5][6]

----

Another warning that can't be disabled in preferences: 2FA available but not enabled

- If you have an entry where 2FA is available on that site, you cannot disable the warning if you don't have it set up

- To actually disable this, you need to tag the entry with 2FA (which is dumb because it implies that it has 2FA, but the tag is showing that it DOESN'T have 2FA enabled)

----

Subdomain matching doesn't work:

- This used to actually work fine but it was removed!

- If you have a.test.com and b.test.com with different credentials, 1password treats them as the same website and will ALWAYS show entries for both, breaking autofill

- See [7][8]

----

And after all this, I still planned to continue to use 1Password until they made their version 8 Electron announcement. That's absolutely the final straw and I won't be moving forward with them after that.

1 - https://discussions.agilebits.com/discussion/92007/1password...

2 - https://discussions.agilebits.com/discussion/111892/messy-do...

3 - https://discussions.agilebits.com/discussion/95438/reused-pa...

4 - https://1password.community/discussion/106132/suppress-the-r...

5 - https://discussions.agilebits.com/discussion/115492/feature-...

6 - https://1password.community/discussion/104141/watchtower-reu...

7 - https://1password.community/discussion/89271/matching-sub-do...

8 - https://1password.community/discussion/87028/stricting-url-m...

Re: 1Password Has Raised $620M

#594
I have as of yet been able to find a password manager I actually enjoy and doesn't have its share of problems. LastPass, 1Pass, NordPass, Enpass, KeePass...all of them fall short or feel slow/buggy or have poor integrations.

Re: 1Password Has Raised $620M

#595
post #5

`But we don’t just want to keep up; our goal is to push the envelope and explore beyond the boundaries of traditional password management.` Hmmm, sounds like the time to migrate may be sooner than I'd hoped.

You can never trust cloud-hosted password managers..

[deleted]

Re: 1Password Has Raised $620M

#596

"1Password Has Raised $620M" Ah fuck. They now need to grow at any cost to earn all that money back. And they'll throw their users under the bus, if they have to, because it's either grow like a unicorn or go bust. Also, I sincerely have no clue how a password manager could be so expensive. Last time I checked, the excellent KeePassXC was still free open source and developed by volunteers in their free time. How come…

> Also, I sincerely have no clue how a password manager could be so expensive. Last time I checked, the excellent KeePassXC was still free open source and developed by volunteers in their free time. Because 1Password is easy enough to use that my wife and I can share a family plan without her getting frustrated. If one of us has a login the other needs, we can easily share it. When I evaluated KeePass, the Wife-Accep…

I'm using KeePassXC on my work computer and it takes around 30 minutes of maintenance every two weeks when the browser extension can't find the desktop app or bare functionality like "copy password" stops working and I need to reinstall.

Re: 1Password Has Raised $620M

#597
post #401

Earlier quoted context omitted.

> Why would anyone expect important services to be free? I think the "common person" does not see these as growth hacks. The internet is full of things that "appear" free, and have "appeared" free forever. You have x-ray vision for how these businesses work internally, and you describe the playbook very accurately, but most people do not have this kind of context. Which makes it hard for those people to distinguish "…

> This is true. As a customer, depending on the good-will of leadership to counterbalance the influence of capital is depending on humans, and even really good ones are fallible and temporal. Well, I dunno, you always are depending on the "good will" of leadership. They could decide to squeeze every cent and provide as little value as possible at any time, whether they have venture funding or not. If your alternative…

> you always are depending on the "good will" of leadership

This isn't true if the product is FOSS. The Mozilla Company can be a disaster, but that's OK because Firefox is OSI-licensed. It will outlive Mozilla, and one or more community forks will appear to replace it, if needs be.

For example, observe how https://rockylinux.org/ rose from the ashes of RHEL/CentOS, after Red Hat were acquired by IBM.

The lesson is that as long as there's interest in an OSS product, there is money to be made servicing (hosting, bug-fixing, whatever) it. Where there is money to be made servicing it, a business will appear to soak up the demand.

> I'd argue this comes after the IPO.

I think it's purely a function of who your shareholders are, what your unit economics are, and how much money you have in the bank. It can happen to any stage of company. In general, contrary to popular HN belief (not saying it's yours), VCs prefer not to put good money after bad.

There are many public companies that are not relentlessly pursuing value optimization, because they have good unit economics, and have invested in attracting shareholders that are aligned with this idea. They are not starved for cash, and can raise money with low-interest loans when a growth opportunity presents itself.

> Without looking at 1Password finances though, even when it was a paid service, we don't know how profitable it was, if at all, and may be going after enterprise customers with this new funding is the only way to not only 'break even' and start making some good profits.

Like you say, we can't comment on 1P directly without knowing access to their Stripe account.

One might charitably say, their business hitherto was an experiment to see if one could build a VC-scale business around the problem of personal password management. The answer is no, but they can leverage their experience gaining that knowledge into solving a similar problem at an enterprise scale. That's probably how the execs & employees think, and it's a very reasonable take.

Unfortunately, while it's optimal for long-term viability of their business, it's not optimal for the consumer world writ large. While 1P has bootstrapped at the consumer's expense and benefit, building a consumer-facing brand for themselves along the way, it is now all downhill for the consumer from here, because they are no longer the focus of the company.

One can imagine a counterfactual, where they had developed their core applications as FOSS. 1P the business could continue to make money as 1P-enterprise, and "the people" could take over maintenance of 1P-consumer, if there was sufficient interest. The valuable experience they've accrued in building their product would continue to spin off value, instead of slowly grinding to a halt.

---

Don't get me wrong, if you put me in the shoes of some exec at 1P with a fiduciary responsibility, I would do the same thing they're doing. It's the only rational direction. Their decision space is/has been heavily constrained by their initial conditions (accepting VC money, not starting with a FOSS product, etc.). If they hit `git push` to some public remote today, they risk losing the entire network they've been investing the last N years in building. It's not reasonable to expect people to make that trade.

I guess I'm hopeful that people will observe these outcomes, that it may influence their own decisions in choosing the initial conditions of their own projects. Sometimes fiduciary responsibilities contravene social responsibilities, and the superior cure for that circumstance, like with so many others, is prevention.

Re: 1Password Has Raised $620M

#598
post #516
post #295

People thinking this is an absurd amount of money are sleeping on how 1Password is quietly positioning itself to become the ground truth storage solution for corporate secret management, across devops and non-technical groups alike. Given Hashicorp's market cap of 11B, and 1Password's narrative on how to become even more central to corporate use cases by being the storage layer for Vault deployments, it's a very reas…

They have been doing some pretty unfriendly moves towards their long-term customers, like making sure the new 1Password cannot be used without 'the cloud' like the old one could be. I have no doubt raising more VC money will only accelerate such trends. In fact I've decided to move off of 1Password to BitWarden, since at least one can realistically self-host it. That being said, it's not exactly easy to migrate from…

Long-term 1Password customer here, no affiliation with 1Password or AgileBits.

> They have been doing some pretty unfriendly moves towards their long-term customers

From my point of view this was not hostile at all: I used 1Password with Dropbox sync for years and absolutely loved it as a personal password manager _for myself_. But sharing of passwords with family was a real pain. I gleefully signed up for cloud-hosted 1Password Families at launch and haven't had a bit of regret. Of all the subscription services I use, at $4/mo 1Password is easily the best bang for the buck.

For sharing, it's just sooo much easer than trying to use Dropbox: I can invite family members just by entering their email address and 1Password walks them through the setup. I can create new vaults with the click of a button and easily select who I want to share them with. I can revoke access to members just as easily I don't have to have a Dropbox account and I don't have to wonder about whether I've set the right permissions on my vault files or whether my free Dropbox quota has been reached. I don't have to share _my_ vault keys and passwords with someone else to give them access to a vault. I can still export and back up an encrypted vault whenever and however I want.

It's no accident that all of these features are the same ones that make their product so attractive to businesses as well: ease of access and sharing are both essential for adoption by businesses.

One more note: I still have my old standalone licenses and can still go back to 1Password 4/6 with Dropbox sync any time I want and not pay another dime, as 1Password still has links to download the older versions on their website: https://1password.com/downloads/mac/

Re: 1Password Has Raised $620M

#599

Earlier quoted context omitted.

No, they are picking subscriptions 30 times more than licenses. When they first did this it wasn’t hidden at all. The website gave you 2 options side by side.

Are you sure? It looks like the license option was hidden almost immediately. https://web.archive.org/web/20160915083507/https://1password...

It was hidden in both the website and the app almost immediately, yeah. Announced in/near August, and your link shows it in September: https://www.windowscentral.com/1password-launches-subscripti...

I remember noticing the announcement of subscriptions (possibly a couple weeks after it happened), being concerned it'd spell the end for dropbox sync so I checked it out ASAP, and then discovering my fears were mostly justified - it still existed (and remained around for a couple years), but it was shoved waaaay off into a corner. E.g. in the next subscription-oriented version of the apps, unless you attached a synced file FIRST, the option for dropbox syncing or standalone licenses was never available. The official instructions for fixing this were to reinstall the app from scratch and attach to the file first, before signing in.

Notice that only a few months later, the standalone license mention at the bottom of the page isn't even there any more: https://web.archive.org/web/20170215115945/https://1password...

Super hostile behavior, right out the gate. It was clear they were going all-in on subscriptions.

Re: 1Password Has Raised $620M

#600
post #360
post #295

People thinking this is an absurd amount of money are sleeping on how 1Password is quietly positioning itself to become the ground truth storage solution for corporate secret management, across devops and non-technical groups alike. Given Hashicorp's market cap of 11B, and 1Password's narrative on how to become even more central to corporate use cases by being the storage layer for Vault deployments, it's a very reas…

Pretty typical for people here to be zoomed-in on the b2c side of a business because that's what they use, and fail to see the b2b side, the underwater mass of the iceberg.

I was going to say something about “just use pgp and rsync”
Post reply on HN