Live data from Hacker News

Apple unveils 'Passwords' manager app at WWDC 2024

zdnet.com

751–760 of 767 posts

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#751

Normally I’m conflicted when a big tech company comes to stomp on a market of smaller app makers but the password manager industry has left me with little sympathy. Years ago I bought 1Password via a one off payment and set it up to sync via my iCloud Drive. It all worked great. Then they took VC investment and quickly every new feature was locked behind a subscription gate. I switched to Bitwarden. Then they took VC…

>and you could never use a third party storage service with BW AFAIK You can run your own BW server, or at least you could as of a few years ago. It's not well documented, but it was doable. The only reason I don't use BW is because the iOS app doesn't locally cache passwords, and I didn't want to open up my home network or set up a VPN just for a bitwarden server.

There's also vaultwarden

https://github.com/dani-garcia/vaultwarden

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#753
I used to use Apple keychain and lost access to it at one point when I switched phones and no longer had a known device associated with my account. Even when I had the correct credentials, I could no longer access the keychain.

It may be my own ineptitude, but I won’t use it again.

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#755

Earlier quoted context omitted.

What’s the problem with it exactly? I’m using it on iPad, macOS, iOS and windows 10 and 11. Seems per much the same as it’s always been. I’ve got the family using it too. Just curious what issues other people are experiencing.

It's very much a "death by a thousand cuts" situation - I'm not a fan of the removal of 1Password mini which was my primary interaction with 1Password, especially for the common workflow of password generation/account lookup. It seems their focus is to drive this into the browser extension but that doesn't cover all of my use cases - I very often need to generate a login password _outside_ the context of a browser an…

Another classic issue of a "death by a thousand cuts" situation— you cannot hide the Mac menu bar icon and still keep the background agent running unlike 1Password 7 (Discussion from 2022 silently closed without any resolution here: https://1password.community/discussion/129305/latest-1passwo...).

They've constantly been downgrading the quality and the polish of the macOS app, just for "cross-platform" feature parity- leading to a subpar experience everywhere (Windows is a whole another can of worms).

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#756

I was happy using Bitwarden until recent updates that basically block out the entire form input. It's a dark pattern to me, built off fear and that's not the perception I want to see in someone in charge of my passwords.

You can turn this feature off under settings.

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#757
post #669

Earlier quoted context omitted.

I wouldn't look for any excuses for someone who is as often nasty as Apple is.

Sounds like this is a personal problem.

The opposite - it would be a personal problem if someone would trust the likes of Apple giving them undeserved benefit of a doubt.

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#758
post #337

Earlier quoted context omitted.

Cloud only, and they removed local storage of the vaults. If I'm somewhere that doesn't have internet connectivity, what happens then? Dislike of SaaS isn't limited to monthly fees, but the lack of features they removed to encourage SaaS adoption

If you are using a device that previously accessed your vault, it will be cached and accessible. It just won't sync until you regain network connectivity.

Is there an actual guarantee that all passwords will be cached (and not just e.g. the N most recently accessed ones), and that the cache will not expire at some point?

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#759
post #463

Earlier quoted context omitted.

It’s not that the gp is trying to avoid being secure. It’s that for a service that you only have a need for, a few times a year, mandating 2FA is an unnecessary hassle that can lead to user frustration. I’ve experienced the same with Gitlab. I rarely use Gitlab and don’t have anything important hosted there but when a project I was a member of enabled 2FA for all contributors, it made my Gitlab account completely fru…

True, but the alternative is that people with valuable projects to secure don't do that (because they aren't forced to), and lose things. That said, the sign-in flow with a Passkey and BitWarden is great. Click "sign in with a passkey", click "confirm", done. No username, password, or 2FA required. One day I hope BitWarden implement my suggestion of not requiring that second click if you only have one key.

Maybe they could have offered me the choice to "uncontribute" to that project, that is transfer my commits to the admin or to another account of mine that I would create, transfer the commits to and never access again after then. Then no more 2FA for opening issues and commenting on other projects.

I wonder if I can delete my account and create it anew with the same email and (probably) a different username.

Re: Apple unveils 'Passwords' manager app at WWDC 2024

#760

Earlier quoted context omitted.

True, but the alternative is that people with valuable projects to secure don't do that (because they aren't forced to), and lose things. That said, the sign-in flow with a Passkey and BitWarden is great. Click "sign in with a passkey", click "confirm", done. No username, password, or 2FA required. One day I hope BitWarden implement my suggestion of not requiring that second click if you only have one key.

Maybe they could have offered me the choice to "uncontribute" to that project, that is transfer my commits to the admin or to another account of mine that I would create, transfer the commits to and never access again after then. Then no more 2FA for opening issues and commenting on other projects. I wonder if I can delete my account and create it anew with the same email and (probably) a different username.

I think 2FA is based on your being a member of an organization, no? You could leave, I think.
Post reply on HN