6 ms·
> 1Password now has a subscription service for $3 a month and you get the first 6 months for free. Don't pay for this people. Use the open source password mana
by lllorddino 10y ago
> 1Password now has a subscription service for $3 a month and you get the first 6 months for free.
Don't pay for this people. Use the open source password manager Keepass http://keepass.info/ http://keepass.info/
- kumarski 10y agothe website is so poorly designed, it leads to consumer-non-adoptability.
- vog 10y agoIndeed. I would really love to recommend Keepass, but their website is really ugly and makes the impression of a non-polished software - even though Keepass is absolute mature and fine. On the other hand, the PuTTY website is also everything but polished, but people have always been using it. Also, I suspect that most people will get it through the third-party site "www.putty.org" instead of the real PuTTY website, whose URL is as complicated as: http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html http://www.chiark.greenend.org.uk/~sgtatham/putty/download.h...
- trimbo 10y ago> their website is really ugly I don't think it's ugly -- just dated. Isn't it weird that mentally we trust software less if they have a dated website? Shouldn't it be the opposite? (As in: a dated website means this software is mature and tested?)
- funkymike 10y agoThe problem with dated websites is that they have the appearance of being thrown on the web in 10 minutes and forgotten about rather than being mature and tested. If the software is well supported and maintained than the website should be too.
- CriminallyInane 10y agoIsn't the mentality more to do with insecure sites having dated websites with misleading links etc. Unless its a known company a dated/poor website often flags warnings for me about security, support for the product and more.
- saint_fiasco 10y agoIt could also mean the software is abandoned and hasn't received security updates in a long time.
- Redoubts 10y agoHeh, it doesn't even look half bad if you drop the bettermotherfuckingwebsite css on it.
- ocdtrekkie 10y agoYou know what always gets me: PuTTY's website isn't served over HTTPS. That software everyone downloads to type all their firewall and router credentials into... is from a website not served over HTTPS. I see the download and signature links are, but if I could have this non-HTTPS website offer up different links to your web browser...
- rb12345 10y agoThe downloads are all GPG-signed, so that shouldn't be an issue. You have the issue of the initial trust, but that applies to HTTPS too to a lesser extent.
- ocdtrekkie 10y agoHow many people do you think download the application, then check the signature? Additionally, if you can spoof the download link on this HTTP page, you can also spoof the signature link, and provide a fake signature matching your malicious package.
- rb12345 10y agoFrankly, about the same number of people as the number checking the HTTPS certificates are as expected. GPG does have the advantage though that once the public key is known and trusted, the package can't be tampered with on the server. (Authenticode might also work, but then you're back to trusting all the CAs that Windows does.)
- wepple 10y agoI love and use 1password, but to be honest I can't see any 'pro' features that I need/want: https://support.1password.com/pro-features/ https://support.1password.com/pro-features/
- jonknee 10y ago1Password is well worth the money. It is well designed for both desktop and mobile and I am happy to pay for software that I use every day.
- dimino 10y agoIt absolutely blows my mind that people are okay with giving their passwords (encrypted or not, see this very breach for why that's not always enough) to a 3rd party, but are not okay reusing a password somewhere. If 1Password ever got owned, the Internet would be severely fucked. And to stem the potential flood a bit, I realize there are plenty of good counterargument built up over the years to try and combat this general idea, but fundamentally the concept of giving your password to someone else to manage is still a confounding idea, regardless of whatever points those arguments make.
- jonknee 10y agoMy passwords are synced through WiFi on my local network, but thanks for your concern.
- macintux 10y ago> It absolutely blows my mind that people are okay with giving their passwords (encrypted or not, see this very breach for why that's not always enough) to a 3rd party That sounds more like LastPass than 1Password, although I haven't looked at the new subscription offering. I don't give my passwords to 1Password.
- chrisfosterelli 10y agoYou don't give your passwords to LastPass either, you give them encrypted random noise they can't do anything with.
- macintux 10y agoWhich does not change the parent post's point, that with LastPass you're still giving it to a 3rd party who could leak that information for brute forcing.
- wildflyalpha 10y agoI'd recommend something like LastPass instead. I used KeepPass for a number of years and it's a fine piece of software. To solve the problem of access on multiple devices and keeping it in sync I kept my password database in Dropbox. It works reasonably well but you often run into "lock conflict" issues when it is open from multiple devices, fine if it's read-only but I always felt uneasy when making changes. A few months back I switched to LastPass and although it's GUI takes some getting used to, I was able to import everything from KeePassX into it easily and de-dupe it. It even has 2FA support via Google Authenticator so it's convenient. There are also apps for Firefox, Chrome and Android (phone and tablet) so I forked out for a Premium license and I'm pretty happy. You can get it to generate passwords for a new site, no fear of using the same password in multiple places and LastPass will warn you if that happens.