Live data from Hacker News

Evaluation of five password managers

medium.com

91–100 of 216 posts

Re: Evaluation of five password managers

#91
post #30
post #8

> Mac OS, Windows, Linux, Android, and iOS ... full functionality can’t be dependent on an app which is only available on Mac OS and/or Windows. In other words, lack of full Linux support is a show-stopper for us. This ruled out 1Password... ...Huh? 1Password supports all of those platforms (including Linux) https://1password.com/downloads/linux/

It really doesn't. I'm a full time linux user and I can tell you the support from both lastpass and 1password is abysmal. I have to copy and paste my passwords from both of those platforms using their half-baked browser plugins that rarely work with linux clipboards.

Both Lastpass and 1password browser plugins worked totally fine for me on Linux. My only complaint re: 1pass is the lack of native Linux app — you can't do mildly complicated things in the browser extension like edit credentials. On the other hand, LastPass doesn't have a native app.

Re: Evaluation of five password managers

#92
post #45

we decided that Bitwarden is the best choice for our company, and we’ve begun the process of migrating from LastPass to Bitwarden. whois lastpass.com LogMeIn, Inc. whois bitwarden.com WhoisGuard, Inc.

Using WhoisGuard for their domain is so not a problem. Namecheap gives you that for free and by default, and it cuts down on spam mail from other registrars. Bitwarden is open source and self-hosted. This is a better trust model than any of the other offerings by a mile.

I have no criticism of the service or WhoisGuard, just the idea of that kind of site using it.

Re: Evaluation of five password managers

#93
post #75

Earlier quoted context omitted.

That page says, "Requires Google Chrome or Firefox," and the download link takes you to the Chrome web store. I'm not sure the poster considers that full support.

That's somewhat fair, although the 1Password X page (which is what AgileBits calls their in-browser version) describes it as being comparable to the native versions, which to me goes against OP's statement that > full functionality can’t be dependent on an app which is only available on Mac OS and/or Windows. The existence of 1Password X means that full functionality is not _dependent_ on a MacOS/Windows app. The arg…

1Password X is definitely not comparable to the native versions, and the statement was "full functionality can’t be dependent on an app which is only available on Mac OS and/or Windows."

> The argument that there should be a graphical (because there _is_ a multi-platform CLI), native app for Linux, which does not depend on any browser, is a perfectly valid one -- but it is also an argument that I don't believe they've made.

I think they're making that argument.

Re: Evaluation of five password managers

#94

Earlier quoted context omitted.

That page says, "Requires Google Chrome or Firefox," and the download link takes you to the Chrome web store. I'm not sure the poster considers that full support.

How many Linux users don't have chrome or firefox installed? I think the article would be a bit more accurate to say there's not native client support for Linux.

Regardless, 1password X does not provide the full functionality of the native apps, so it's fair to say a Mac or Windows app is required for full functionality anyway.

Re: Evaluation of five password managers

#95
post #62
post #35

Earlier quoted context omitted.

There's a few issues with the master password derived password system, including: What if you need to change your password for a site to a different one? What if the site changes its URL?

There's a counter on Master Password, so if the password expires or you need to change it, you just +1 and it's new. They also have settings depending on password requirements (no special characters, etc.). I'm unsure what the URL really has to do with it, you could just generate a new password for the new URL and change it.

Sometimes different URLs share credentials (LDAP). Changing isn't necessarily an option?

Re: Evaluation of five password managers

#96
post #30

Earlier quoted context omitted.

It really doesn't. I'm a full time linux user and I can tell you the support from both lastpass and 1password is abysmal. I have to copy and paste my passwords from both of those platforms using their half-baked browser plugins that rarely work with linux clipboards.

I use 1Password via the CLI ( https://support.1password.com/command-line/ ) on Linux (well -- FreeBSD) Desktop all the time. I wrote a wrapper for the CLI ( https://github.com/dcreemer/1pass ) to make it a bit more ergonomic to use with things like FZF. I used to use "pass" like others here, but did not like the Android experience. *edited to add: and we use the 1Password team account at my day job -- and are satisfi…

afaict, the 1password cli app is just a client for their API and has no offline mode, so if I can't reach 1password's servers, I can't access any of my secrets.

I believe the browser addons do not share this shortcoming, though.

Re: Evaluation of five password managers

#97
post #30
post #8

> Mac OS, Windows, Linux, Android, and iOS ... full functionality can’t be dependent on an app which is only available on Mac OS and/or Windows. In other words, lack of full Linux support is a show-stopper for us. This ruled out 1Password... ...Huh? 1Password supports all of those platforms (including Linux) https://1password.com/downloads/linux/

It really doesn't. I'm a full time linux user and I can tell you the support from both lastpass and 1password is abysmal. I have to copy and paste my passwords from both of those platforms using their half-baked browser plugins that rarely work with linux clipboards.

There is an official lastpass cli, but I don't know how well maintained it is. https://github.com/lastpass/lastpass-cli

Re: Evaluation of five password managers

#98

I like the functionality comparison but I'm really curious how they stack up to each other security wise.

Bitwarden recently completed a 3rd party Audit[1] and Bitwarden is the only one to be completely open source[2] (server and client).

[1] https://blog.bitwarden.com/bitwarden-completes-third-party-s... [2] https://github.com/bitwarden/

Re: Evaluation of five password managers

#99

> Yubikey support in browser (Personal) BitWarden: no huh? I use my yubikey in the Bitwarden browser extension. Otherwise, a very extensive collection of comparison data. Not surprised to see Bitwarden come out on top.

I'm also currently using it with a Yubikey and on personal account.

Re: Evaluation of five password managers

#100
post #85

Glad to see Bitwarden up on top. They tick all the boxes for me - open source, transparent security (including recently published audit), feature-rich, optional self-hosted, and easy to use.

Used to be a keepass user until I found bitwarden. It does everything better, more simply. Sync is handled so much better and the browser extensions are super intelligent at picking up login fields.
Post reply on HN