Live data from Hacker News

1Password 4 for Mac is here

blog.agilebits.com

71–80 of 106 posts

Re: 1Password 4 for Mac is here

#72

Supported this company with the first version of 1Password. Then paid again for a family version of v3 last year, as well as the paid version for the iPhone which has been somewhat of a let down... now they want more money. All so I can store/use passwords. I've spent less money on other apps that I actually spend more time using daily. Guess I'll start searching for some alternatives before they start dropping suppo…

"— All Mac App Store customers get 1Password 4 for free. Yes, all of them

— All website customers who purchased 1Password for Mac in 2013 get v4 for free. Yes, that’s a nine-month free upgrade window

— Launch sale price for new customers: $39.99 – that’s 20% off the regular price of $49.99

— Launch upgrade sale price for website customers who bought before 2013: $24.99 – that’s $10 off our regular upgrade price of $34.99".

Re: 1Password 4 for Mac is here

#73
Hmm, 1Password always seemed like an overly-complicated (though polished) solution to a basic problem to me.

Personally, I just use a variant of:

one-way-hash(master-password + site-domain)

Seems to work really well, doesn't require special software, allows me to replicate all my passwords on any computer, and passwords are unique to each website and seemingly-random. Use a strong master password and it seems like an ideal solution to me and you only have to remember one master password and use no special software.* For extra security, perhaps base85-encode the output and truncate it if you want a password with special characters in, and use a slower function (e.g. bcrypt with a high work factor?) to prevent brute force attacks if you're using a simple password.

[* Note, SuperGenPass basically does just this, but has security issues since it runs as JavaScript in the browser as a bookmarklet. My personal solution is a script which does something similar, run using a quick hot-key, that grabs the domain from my front-most web browser window and grabs my master password from the system keychain and then puts the generated password on my clipboard.]

Would be very grateful if someone could point out any security flaws in this method that haven't occurred to me!

Re: 1Password 4 for Mac is here

#74

Maybe they can make a decent Android version one of these days. If they had a good Android version, I'd update to v4 for OSX in a heartbeat. I own an OSX license for v3, a Windows license for v3 (or whatever its at right now), and iOS licenses for iPad and iPhone - even though I don't have an iPhone or iPad anymore. I have a big investment in this program, but their slipshod Android version has me re-evaluating this…

Yeah, they claim it's in the works, but I think that's been true for over a year now. Maybe soon? An app like this shouldn't take a year to make, especially since the current version is so incredibly bad. Some improvement sooner would be preferable, I think.

I have yet to find any alternative that is even remotely as user-friendly. LastPass does legitimately seem to be well run and secure, but the browser-extension UI is horrible at omg levels. KeePass(X/etc) also looks decent, but it's .NET (for what appear to be good reasons, but still), has slightly scary code (lots of reimplementing builtin classes), and again, omg-horrible UI.

I'd love a reasonable alternative, 1Password is unfortunately getting too pricy as time goes on, though it has been hands-down the best.

Re: 1Password 4 for Mac is here

#75
post #36
post #4

Earlier quoted context omitted.

Yes, but Apple's functionality only supports Safari on Apple devices. 1Password supports other browsers and Windows.

Yes, Apple's functionality seems best for casual users (ie, my parents) who generally only use safari on their ipads and mac. iCloud Keychain is a better experience on iOS because only Apple can extend Safari - If you're using 1Password on iOS, you can't do the equivalent of "CMD+\" - you have to use the launch the 1P app - which breaks the workflow. I don't see me moving away from 1Password anytime soon - though the…

You can use a Safari bookmarklet to open the current page in 1Password app, to minimize the disruption in your workflow, see http://www.macstories.net/links/1password-4-1/

Re: 1Password 4 for Mac is here

#76
post #54
post #49

Earlier quoted context omitted.

But the only reason they couldn't update 1Password 3 to the new API is because they pulled it from the store -- in order to force all users to upgrade for $18.

I don't think they pulled it to force people to upgrade.. I suspect they pulled it because selling multiple versions would be confusing. It's clearer if there is one app per platform. Getting my wife to use a password manager is tough enough - Having to explain why there are 14 variations in the store would just add to the burden. But as to why it was a new version in the first place.. This is Apple's supported answe…

I don't have a problem paying for an upgrade. There's features I am definitely excited about, like multiple Vaults which I mentioned above.

But as an end-user who only owns an iPhone, the only "feature" I notice in 1Password 4 for iOS is "Dropbox syncing still works". Not very compelling.

Re: 1Password 4 for Mac is here

#77
post #72

Supported this company with the first version of 1Password. Then paid again for a family version of v3 last year, as well as the paid version for the iPhone which has been somewhat of a let down... now they want more money. All so I can store/use passwords. I've spent less money on other apps that I actually spend more time using daily. Guess I'll start searching for some alternatives before they start dropping suppo…

"— All Mac App Store customers get 1Password 4 for free. Yes, all of them — All website customers who purchased 1Password for Mac in 2013 get v4 for free. Yes, that’s a nine-month free upgrade window — Launch sale price for new customers: $39.99 – that’s 20% off the regular price of $49.99 — Launch upgrade sale price for website customers who bought before 2013: $24.99 – that’s $10 off our regular upgrade price of $3…

Not sure why you're quoting this. I read this when I visited the page... I just find it ridiculous that if I pay the $24.99 to upgrade, I will have put close to $100 into an app that basically stores passwords for me conveniently.

Re: 1Password 4 for Mac is here

#78
post #24
post #14

Earlier quoted context omitted.

it's a free update if you bought 1Password 3 from the Mac app store

Unfortunately I paid them directly so 1Password 4 for the desktop would cost me $25.

I have purchased 1Password 3 in 2010. So I used it three years without any upgrade costs. For an application that I use everyday, it's certainly worth $25. Although, the pricing is steep for other reasons: I have recommended many non-techies to use 1Password, but they would never spend $50 on a password manager.

I won't purchase the upgrade to 4 immediately. 1Password 3 is still working fine. Shared vaults look to be a nice feature, but other than that I don't think I need any of the changes.

Besides that, I'd like to see how good the iCloud Keychain will work in Mavericks/iOS (although it is not a cross-platform solution, Agilebits' Windows and Windows Phone apps haven't been stellar either).

Re: 1Password 4 for Mac is here

#79
post #73

Hmm, 1Password always seemed like an overly-complicated (though polished) solution to a basic problem to me. Personally, I just use a variant of: one-way-hash(master-password + site-domain) Seems to work really well, doesn't require special software, allows me to replicate all my passwords on any computer, and passwords are unique to each website and seemingly-random. Use a strong master password and it seems like an…

One domain flaw: dropbox.com used to be getdropbox.com and probably others. Unless you remember and/or changed your password when that happened, it might now be unrecoverable.

One password flaw: some sites have weird restrictions (probably your bank, for instance). A hashing solution is unlikely to meet those requirements, meaning you have to store the value securely somewhere, so why not store them all? On the other hand, if the output can meet the requirements, it's probably partly based on the requirements. If the requirements ever change, your password now doesn't match.

I know I've thought of others previously, but the short version of it all is that at some point you'll probably have to have secure storage for something that doesn't work with the hashing system you have. Once you have that secure storage, why not just use it instead, since it can resolve nearly all of the problems?

Re: 1Password 4 for Mac is here

#80
post #79
post #73

Hmm, 1Password always seemed like an overly-complicated (though polished) solution to a basic problem to me. Personally, I just use a variant of: one-way-hash(master-password + site-domain) Seems to work really well, doesn't require special software, allows me to replicate all my passwords on any computer, and passwords are unique to each website and seemingly-random. Use a strong master password and it seems like an…

One domain flaw: dropbox.com used to be getdropbox.com and probably others. Unless you remember and/or changed your password when that happened, it might now be unrecoverable. One password flaw: some sites have weird restrictions (probably your bank, for instance). A hashing solution is unlikely to meet those requirements, meaning you have to store the value securely somewhere, so why not store them all? On the other…

Anecdotally, the "one domain flaw" has only ever happened for me for two websites over long time I've been using this system: getdropbox.com and amazon.com (using international amazon sites). Worst case scenario, you can request a password reset if the domain changes, because it's not the sort of thing that happens often.

The "one password flaw" has never been an issue, but my bank uses proper two-factor authentication with a physical card-reading device, so maybe that's why... I've never actually encountered a website that places problematic restrictions on passwords except (weirdly) Microsoft.

But they're just personal anecdotes that those flaws haven't been an issue for me, but I agree they exist and could be show-stoppers for others. I certainly wouldn't recommend it to anyone non-tech-literate. If I did need secure storage outside of that system (which, you're right, does happen–mostly for wifi passwords and the like) then I just use the system keychain as intended.

But I do still have concerns about the overall security of the system simply because I don't understand it well enough...

> Once you have that secure storage, why not just use it instead, since it can resolve nearly all of the problems?

Because I don't want to pay for 1Password licenses, or be caught out if I'm using someone else's computer, or if all my backups catastrophically fail :)

Post reply on HN