Live data from Hacker News

1Password and the Crypto Wars

blog.agilebits.com

71–80 of 111 posts

Re: 1Password and the Crypto Wars

#71
post #44

Earlier quoted context omitted.

Any good cross multi-device alternatives?

https://en.wikipedia.org/wiki/KeePass https://www.keepassx.org/ http://keepass.info/

I used KeePassX in the past but switched to 1Password since there was no browser support to speak of. Has that changed?

Re: 1Password and the Crypto Wars

#72
post #34

Earlier quoted context omitted.

Unfortunately, the developer of Keepass has made the choice of using .NET for development, which means it's pretty much Windows only. There are some non-official clients for Mac OS X and Linux but they don't work great (missing features like auto-completion or browser integration). I'm still using Keepass on these platforms though, but I can see how a truly cross-platform solution like 1Password is appealing.

There are Keepass ports for every major OS. Since it's open source, anybody can implement the client.

[deleted]

Re: 1Password and the Crypto Wars

#73
post #21

In for a penny, in for a pound. If you care about security enough to use a password safe you might as well also use an open source solution that has even a remote chance of having its code looked at by more people than the ones trying to sell it to you. I mean, I know 1Password is all pretty and animated and things, but things like KeePass aren't so ugly as to be unusable.

What about Bruce Schneiers Passwordsafe?

I mean http://pwsafe.org/

Re: 1Password and the Crypto Wars

#74
post #71
post #44

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/KeePass https://www.keepassx.org/ http://keepass.info/

I used KeePassX in the past but switched to 1Password since there was no browser support to speak of. Has that changed?

If you run KeePass (not X), e.g. via Mono on Linux or natively on Windows, you can use the KeeFox Firefox plugin. I believe there are Chrome extensions as well.

I didn't find a better linux-native browser-integrating non-cloud alternative yet :(

Re: 1Password and the Crypto Wars

#75
post #70

Earlier quoted context omitted.

Personally, I am a Last Pass user. It is well included in most browsers out there and you have access to it on your mobile if you subscribe to the premium offer (12 dollars per year).

AFAIK LastPass is an online password manager, i.e., you do not only trust a software vendor like AgileBits for 1Password, but you trust your actual passwords to an online provider. Is that wise given that LastPass could get hacked or asked by authorities to provide your passwords – if there's not already an existing legal access channel?

As said elsewhere, passwords stored in LastPass are encrypted locally. They do not store your password so they officially don't have a way to decrypt your passwords. I agree that it's a matter of trust as your passwords are still stored on their servers.

Re: 1Password and the Crypto Wars

#76
post #69

Back in April, there was an attack on 1Password that managed to exploit some flaws in its crypto scheme to achieve a sizable speedup. [1] To this day, they have not managed to rollout the new 1Password 4 Cloud Keychain that is supposed to fix these flaws. [2] Lots of smooth talk, but apparently security is not a blocker. 1: http://hashcat.net/forum/thread-2238.html 2: http://discussions.agilebits.com/discussion/14780…

Isn't this the attack that reduced the strength of their PBKDF2 scheme by one (1) bit? Because they were unnecessarily calling PBKDF2 twice, where a normal system would have called it once and expanded the resulting key, resulting in exactly the same speed characteristics? Your snark would sting more if you knew what you were talking about. The reason nobody's hair lit on fire over this is that it's a stupid issue.

In 2011 they went from 1k to 10k iterations, too. This got done in advance of any known problems, and was a free upgrade.

Also, there were some design issues with their mobile app about 2-3 years ago (essentially, security could fall down to a 4-digit passcode in some cases), but they again fixed that by making the passphrase again the key to security.

In general I've found them nothing but responsive and competent on security issues (as well as better designers and general software engineers than any security company).

Re: 1Password and the Crypto Wars

#77

Earlier quoted context omitted.

KeePass is utterly unusable for ordinary users. Especially on non-Windows platforms, where it takes voodoo to make it even run.

Really? I use KeePassX on Linux and it literally could not be easier. I just enter my passphrase and my password file opens up, there's not much more to it. EDIT: Apparently KeePass and KeePassX are different?

KeePassX started as Linux client for KeePass but since then has become cross platform. I have not investigated yet what are the main differences between the KeePass and the KeePassX applications on Windows.

Re: 1Password and the Crypto Wars

#78
post #26

Earlier quoted context omitted.

Unfortunately, the developer of Keepass has made the choice of using .NET for development, which means it's pretty much Windows only. There are some non-official clients for Mac OS X and Linux but they don't work great (missing features like auto-completion or browser integration). I'm still using Keepass on these platforms though, but I can see how a truly cross-platform solution like 1Password is appealing.

Does 1Password have a Linux client? Looking at their page, they appear to only support Mac, Windows, iOS, and Android.

they create an HTML file in your Dropbox (when you sync) that you can hit with any browser.

Re: 1Password and the Crypto Wars

#79
post #21

In for a penny, in for a pound. If you care about security enough to use a password safe you might as well also use an open source solution that has even a remote chance of having its code looked at by more people than the ones trying to sell it to you. I mean, I know 1Password is all pretty and animated and things, but things like KeePass aren't so ugly as to be unusable.

Unfortunately, the developer of Keepass has made the choice of using .NET for development, which means it's pretty much Windows only. There are some non-official clients for Mac OS X and Linux but they don't work great (missing features like auto-completion or browser integration). I'm still using Keepass on these platforms though, but I can see how a truly cross-platform solution like 1Password is appealing.

As other said, Keepass2 works under Mono.

Even better, Keepass2 is included in the Ubuntu official repos. And it runs pretty well. Autotyping your password into other programs also works. I really like Keepass2.

  sudo apt-get install keepass2
Good luck!

Re: 1Password and the Crypto Wars

#80
post #21

In for a penny, in for a pound. If you care about security enough to use a password safe you might as well also use an open source solution that has even a remote chance of having its code looked at by more people than the ones trying to sell it to you. I mean, I know 1Password is all pretty and animated and things, but things like KeePass aren't so ugly as to be unusable.

I used Keypass for a couple of months. It was very unstable, regularly crashed my browser, and I lost all of my passwords at one point. I switched over to 1Password and never ran into these issues.

Ive used KeePass and KeePassX on Windows, linux, android, and iOS for over 3 years now, and I've NEVER EVER once had an issue like you guys are.
Post reply on HN