15 ms·
1Password X: A look at the future of 1Password in the browser
- doomrobo 9y agoDoes this mean that all crypto in 1Password X is now implemented in Javascript?
- fcarraldo 9y agoI'm worried about this too. The entire reason I migrated to 1Password over Lastpass is that I don't trust Lastpass' extension. There are too many edge cases, too much fuzziness around "offline usage", and too much reliance on the browser. 1Password's extension acting as an anchor for 1Password Mini, which runs as a separate application on my desktop outside of the browser ecosystem, is a major draw. I don't see how this is better in any way. What's the point?
- roustem 9y ago1Password X is a pure Chrome extension and does not rely on the native app. This has its benefits and obvious drawbacks. Some of the benefits: * Simpler installation * Support for multiple users on the same computer with Chrome user profiles * Support for Chrome OS
- fcarraldo 9y agoIs this an option for Chrome/Linux/ChromeOS users to provide a more streamlined first-use experience? The "a look at the future" and "this is just the beginning" wording in the announcement blog post implies that this is the direction that 1Password is taking as a product, and Chrome support is just the beginning. As a user who prefers a native implementation, uses local vaults, and uses Firefox, none of these advantages matter much. If it's not "for me", that's totally cool. If this new experience will replace the existing one, 1Password is no longer the solution for me.
- AGKyle 9y agoI think the easiest way to look at this is as you said, another option for users. Some enterprises don't allow their users to install applications, but do allow extensions, so this opens up that possibility. It also brought 1Password support to two new platforms: Linux and Chrome OS. As for this being the future. Imagine a world where from a design perspective this sets the tone. Thus, the beginning of the future. It's a first version that has to compare itself against versions that have existed for years. Of course it can't fully replace what we have. It may for some though, I won't discount that at all. For starters, there's no way to do Touch ID in the browser. There's no support for local vaults. There's only Chrome support, nothing for Safari or Firefox. There's a lot missing here. But in terms of the future, this sets the visual design up for how you'll start seeing future updates on the other side of the extension fence. So, lets go with "this isn't for you" :) In fact, I doubt in a lot of ways that this is for people on Hacker News. A smaller number will probably find it useful though. Kyle AgileBits
- fcarraldo 9y agoThanks for the response. I appreciate the clarification on this being the beginning of the visual design for the future. As long as _solely_ browser extensions are not the future of 1Password, then it will continue to be my password manager of choice.
- roustem 9y agoIt is implemented with WebCrypto APIs. The performance would be abysmal in pure JavaScript.
- ecesena 9y agoDoes this scare you? I'm asking honestly, I'm currently building a password manager in react native, and thus the core crypto is all js, relying on crypto-js. Would this be a deal-breaker for you?
- doomrobo 9y agoI don't think I know enough to feel a particular way about it. All I know is that some people I respect seem to dislike it[0][1], so I've just defaulted to avoiding it where I can. [0] https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2011/august/javascript-cryptography-considered-harmful/ https://www.nccgroup.trust/us/about-us/newsroom-and-events/b... [1] https://tonyarcieri.com/whats-wrong-with-webcrypto https://tonyarcieri.com/whats-wrong-with-webcrypto
- roustem 9y agoThe biggest concern with WebCrypto (with the JavaScript code using WebCrypto) is the fact that you have to trust the delivery mechanism. If there is a problem with TLS then there is a potential for a MITM attack that could modify the JavaScript code. Another potential issue is phishing. It is easier to create a fake web app compared to a fake native app.
- nathancahill 9y agos/the browser/Chrome Hey 1Password, make this available for Firefox too. It should be relatively easy to port with WebExtensions API, since it looks like a toolbar popup.
- diggan 9y agoHaven't you heard that the meaning of Browser now just means Chrome. Unless someone writes cross-browser, they are only targeting Chrome, which as a Firefox user, really sucks.
- passivepinetree 9y agoHopefully that will start to change with Firefox Quantum, which in my brief experience has been fantastic.
- AGKyle 9y agoDisclosure: I work for AgileBits, makers of 1Password I posted this elsewhere, just pasting here since it's the same question/concern and gets the same answer :) Making extensions cross browser can still be a bit difficult. Our focus here was to get something readily available for a browser that was in high demand on platforms that we were getting a lot of requests for (Linux and Chrome OS). I believe browser support will expand over time with this extension, it's just that we didn't want multiple browsers slow our progress or prevent us from doing cool new things. Give it some time and I anticipate we'll see browser support expand. Kyle AgileBits
- diggan 9y agoWas excited to read "Linux users and Chrome OS users could join in on the fun?" but then ". It works everywhere Chrome works" so still no love for Firefox users... Too bad the CLI is possibly the worse CLI ever made, otherwise Firefox support wouldn't have been so important.
- syllogism 9y agoEnpass is pretty good on Linux.
- AGKyle 9y agoDisclosure: I work for AgileBits, makers of 1Password I suspect that browser support for 1Password X will continue to expand over time, but focusing on one browser first helped us make it available sooner rather than later. Out of curiosity, what exactly do you not like about our CLI? It offers a ton of flexibility, perhaps that's part of the problem. If you have concrete issues though I'd love to make sure we get that recorded for our team. Kyle AgileBits
- newman314 9y agoUgh. Agilebits left out until the very end that this is only for their hosted solution. No surprise but looks like standalone users are left out in the cold. Again. Much as I like and use 1Password every day, I really really do not like the fact that they moved to a hosted model.
- dkonofalski 9y agoSame here. It doesn't even make sense to me because I already have the app installed on the same computer. I should be able to access the new features of this tool using the existing implementation. I'm even willing to pay for the extension if that needs to be done!
- jlgaddis 9y agoSame here. I bought 1Password (multiple times) and have it on my MBP, iPhone, and iPad and got the girlfriend using it on all of her devices too. Matter of fact, I switched to 1Password the very same day that LogMeIn bought out LastPass. I am not happy about them switching to a subscription model and pushing their hosted product and (in this case) making it a requirement. Yes, the standalone version is still around. For now. As much as I dislike it, it was (unfortunately, for us) probably the right business decision to make. The standalone version will go away at some point in the future. I'm sure of that, I just don't know when it will be. I'll never switch to their subscription/hosted product but many, many others probably will. That will reaffirm their decision and lead to them eventually completely dropping the standalone macOS version.
- dkonofalski 9y agoSupposedly, 1Password 7 for Windows will bring back standalone vaults to Windows. Since the hosted solution brings them the bulk of their revenue (I'm guessing), it made sense to me for them to focus on the Windows upgrade with hosted accounts and I forgave them for it as long as 1Password 4 continued to work. I really hope that same attitude continues on with later versions of 1Password X. Starting out with accounts makes sense so long as they add standalone support later. I'm a patient person and beggars can't be choosers.
- jaequery 9y agoWhat does this have that Lastpass does not?
- pvg 9y agoAn absence of a long history of security bugs.
- danpalmer 9y agoA designer </snark> In all seriousness though, Lastpass is not a particularly good looking piece of software, and in small ways that does impact my ability to use it efficiently. It generally looks like 1Password is much better on this front, although I still use Lastpass because it's ~50% cheaper.
- Infernal 9y agoIncompatibility with Safari, Firefox, and Edge?
- stimur 9y agoour main app and extension work with Chrome, Safari, Firefox, Edge. Password X in particular is new approach and its first iteration works in Chrome only. Which doesn't mean it will not work in other browsers as well in later versions.
- Infernal 9y agoFair enough. And full disclosure, I have been a happy 1Password user for years - will be a sad day if/when local storage is no longer an option and I have to find another solution.
- rcarmo 9y ago"1Password X was designed for our hosted 1Password service and connects directly to your account." Nope, sorry. No. Never. I'd rather change password managers than rely on a small, niche company to keep the data secure and in sync -- larger players have a much bigger advantage here. I can see a future coming when I'll only use 1Password on my phone, and have things stored on a secure enclave. It will be slightly more of a pain to use it on a desktop, but most browsers and operating systems are building their own simplified (and arguably more secure) password vaults...
- lucisferre 9y agoLarger players being? I can only think of Lastpass when it comes to similar feature sets.
- heartbreak 9y agoApple's iCloud Keychain would qualify as a larger player.
- TheSwordsman 9y ago... if you omit the lack of cross-platform support
- egeozcan 9y agoChrome saves and syncs passwords for you out of the box. Combined with an offline KeePass database, it works great.
- stephengillie 9y agoKeePass works great with Dropbox. These with Chrome are a pretty comprehensive solution across mobile and desktop, with layers of MFA, if the key file is stored separately.
- deleted 9y ago[deleted]
- RyanShook 9y agoShout out for Avast Passwords. Already does much of this for free. 1Password and LastPass always really annoyed me with their freemium model. Avast Passwords doesn't make you decide between controlling your passwords and paying for basic features. Highly recommend checking it out: https://www.avast.com/en-us/passwords https://www.avast.com/en-us/passwords
- cdoxsey 9y agoThe hosted nonsense and poor linux and windows support is why I switched to enpass.
- Nicksil 9y agoI'm glad you mentioned Enpass -- I hadn't heard of them. I'm currently a disgruntled 1Password user looking to jump ship. https://www.enpass.io https://www.enpass.io
- Mister_Snuggles 9y agoI've been using Enpass for a little while and it's working out really well. The thing I like most about it is that they are not in the cloud business. They have a list of seven cloud providers that they support for sync and let you pick one (or none if you don't want to sync). They also support using WebDAV/OwnCloud for sync if you want to do your own thing. The other cool thing about Enpass is that it's available for all of the major platforms. Having passwords synced between my phone, Linux computer, and Mac is really nice.
- neandrake 9y agoAnother one you can check out is Codebook - https://www.zetetic.net/codebook/ https://www.zetetic.net/codebook/ No Linux support though
- aagd 9y agoDefinitely not my future. I liked 1Password so far, but my passwords will never go to the cloud.
- nkw 9y ago> 1Password X was designed for our hosted 1Password service and connects directly to your account. Agilebits/1Passwords continued shoving of their 'hosted' services down their customer's throats amazes me. I'm not even particularly against SaaS/cloud/hosted/subscription/whatever, except a password manager is exactly the type of product that I do not want in that type of environment. Is it really impossible to have a successful software business without this BS? I guess I am in the minority but I would much rather you charge me more for the software or charge me for the upgrades, than push me into your hosted cloud-subscription stuff. Agilebits/1Password was by far the best product out there, with astonishing goodwill amongst their customer base, which they have managed to lose, not to competitors or outside forces, but rather by incinerating it themselves.
- askafriend 9y agoThey haven't lost any good will that matters in the long run. I find 1Password valuable enough to pay them a monthly fee and so do many many others. They changed their business model to be more sustainable/profitable and they know that means that they'll lose a segment of customers but that's OK. The products that won't do well with a business model like this are products that don't provide enough value. There is nothing wrong with the pricing model itself or a company choosing to adopt it.
- mcgrath_sh 9y agoFor me, it is both about the business model and the move to a hosted service. I’m against renting tools. I will gladly buy them, and I will buy frequent-ish updates (18-24 months). I'm not cheap. I simply value ownership of both the software and my data. I have bought five 1Password licenses for myself and my immediate family; a roughly ~$300-$320 investment. Toss on another $50 for iOS licenses and you have roughly six years of subscription revenue. So, if six years of subs is goodwill that doesn’t matter, that is fine.
- AGKyle 9y agoDisclosure: I work for AgileBits, makers of 1Password To be clear, we aren't "moving to a hosted service." We still offer the Pro features for iOS for $10 for users who want to purchase that instead of a subscription. We still offer 1Password 6 licenses for Mac, they're available via the Mac App Store, our website, and in app after the trial period ends. We have also announced we'll be offering 1Password 7 licenses when we release that in the future. We have also announced we'll be offering standalone vaults and traditional licenses for 1Password 7 for Windows. So nothing is "moving to a hosted service." It's simply another option and it's also the option we feel is best for a vast majority of our users, that may not be you that falls in that category, but you're also reading hacker news, you're not in the same category as a majority of our users either. Hope that helps a little at least. Kyle AgileBits
- syllogism 9y agoIn-browser password managers are completely insecure by design. Any site can write whatever they want within the page, so it's easy to fake the prompt and steal the password. The only way to prevent this is if the password manager runs as a standalone application, so that the password is entered outside the browser. 1password has this, and the workflow is fine --- switching to the insecure one makes no sense.
- psychometry 9y agoHow are sites going to trick the extension into believing the site is on a different domain?
- fcarraldo 9y agohttps://blog.lastpass.com/2017/03/important-security-updates-for-our-users.html/?utm_source=TWITTER&utm_medium=social&utm_term=Customer%20Serviced-tAnswering%20CS&utm_content=20170322d-t20170322212831 https://blog.lastpass.com/2017/03/important-security-updates...
- pfg 9y agoThe problematic bit is that the browser itself would prompt you for your master password. Getting users into the habit of entering their master password in a browser window means that it's relatively easy for sites to create a fake prompt that's likely to fool a lot of people. 1Password does a couple of things to mitigate this. First, the master password alone would not be sufficient to get access to your passwords. An attacker would also need access to your vault files (for local vaults) or your secret key (for 1Password Accounts, their SaaS offering). Second, the password prompt isn't rendered within the "danger zone" - the part of your browser window where the page you're visiting is rendered. Instead, it's a dialog on top of the extension toolbar where it's distinguishable from the site (at least with the Chrome extension for the standalone version on macOS, I haven't checked to see if this changed). Neither of these mitigations are perfect. Leaking your master password is obviously bad either way, and while I have some faith in my ability to detect a fake password prompt that's rendered in the wrong position, that's a bit like an anti-phishing strategy that boils down to "always check the domain", which we know doesn't work. Ultimately, not using an extension reduces your attack surface significantly, but incidentally that comes at the cost of some phishing-resistance that you gain from only ever entering your password through an extension matching the domain.
- SirensOfTitan 9y agoI have used 1Password for half a decade, but I'm pretty disgusted by agilebits behavior as they continue to shove non-cloud users aside. The amount of customer goodwill they've burned is astounding. I think it's time to start looking elsewhere for a password manager solution.
- AGKyle 9y agoDisclosure: I work for AgileBits, makers of 1Password I'm sorry you feel that way. What makes you think we're pushing you aside? We are still introducing features in 1Password 6 for Mac, and 1Password 7 for iOS that work for both our hosted solution and our standalone users. We are able to offer a lot of newer features to our 1Password.com membership users because that solution opens a lot of new possibilities. But we certainly haven't forgotten about users like yourself. 1Password 6.9 for iOS introduced Drag and Drop for iPad users 1Password 7 for iOS introduced Face ID, a new favorites screen, Quick Copy, and a host of other smaller features and improvements We're not stopping there either and have even more great new features lined up that will work for both our standalone users and our 1Password.com users. 1Password 7 was also a free upgrade for any iOS user, including those that had Premium features purchased. I'd love to hear how you think we're pushing you aside though because it'll help me understand how we can try to improve our language in various release notes and announcements to make it clear we aren't leaving you behind. Thanks! Kyle AgileBits
- threatofrain 9y agoI'm just wondering, does your period subscription license also include your "stand-alone" software?
- AGKyle 9y agoIt does. So if you purchase a subscription, you'll sign into an account for 1Password in the app. The presence of an active account (one that's in paid status, or trial) will unlock the standalone licensed portion of the application. So you can freely use those features to your hearts content. At least, that's how it works for Mac and iOS. I contribute to those teams specifically on the development side so I'm most familiar there, I'm not sure I know enough about Android to comment there and be accurate. If you need to know about Android I can find out though. Regarding Windows, not currently because version 6 is 1Password.com only, however, version 7 will add standalone vaults and a traditional license model, I anticipate it will copy our Mac application but until it ships I can't guarantee anything. Kyle AgileBits
- ejcx 9y agoFormer LastPass employee here. Looks to me like 1Password is going full LastPass. First fully hosted passwords. Now support for extension only (which is way worse security wise). SaaS margins and recurring revenue is better, and I guess their previous model was killing 1Password.
- drudru11 9y agoYeah - I'm surprised there aren't more comments pointing this out. When you state "their previous model", do you mean per-user pricing vs. per-device?
- ejcx 9y agoIt's both. My guess is the product offering and pricing changes are part of the same push for recurring revenue
- stimur 9y agoAgileBits employee here: > First fully hosted passwords In addition to standalone data > Now support for extension only In addition to existing apps and existing extension. > I guess their previous model was killing 1Password. The guess is wrong. Sorry. We said the opposite publicly multiple times.
- AGKyle 9y agoDisclosure: I work for AgileBits, makers of 1Password Hello fellow (or former) password manager person! Fancy seeing you here. The previous model wasn't killing us, in fact it isn't even "previous" because we still offer standalone licenses for those that want them and will continue to do so. For those who aren't aware of our upgrade cycle in the past: For Mac, we last charged for 1Password 4 back in 2013. Version 5 and 6 were free upgrades over the last 4 years. Version 3 users got free updates for 6 years before we released 1Password 4 as a paid upgrade. For iOS, version 1 was paid, version 2 and 3 were free upgrades. Version 4 was a paid upgrade by way of a new app. It went free with premium in-app purchase in version 5 and all users who purchased version 4 got the premium service free in 5, 6 and 7. If we really were struggling making revenue work for our standalone licenses we could've charged for upgrades every year like any other product does. 1Password.com is not about the revenue, it's about making a product that we can do more with. We have exciting ideas and features we want to create and introduce to our users but we couldn't do that without our 1Password.com solution. This is simply one of those options, our command line client is another one, and we'll be showing off even more great new features like these in the future. On the security side, I encourage any security researchers out there to try to prove our applications insecure by demonstrating it via our bug bounty program: https://bugcrowd.com/agilebits https://bugcrowd.com/agilebits Happy hunting. I hope that gives some insight at least. Kyle AgileBits
- srathi 9y agoOuch! I just switched to Firefox 57 and I can't use this new feature! Shouldn't the WebExtension be portable across both browsers with minimal work with Firefox 57?
- diggan 9y agoYeah, it requires minimal work but some companies can't even put minimal work into their extensions so here we are...
- caiob 9y agoAlso on Safari 11. WebCrypto is widely available now.
- AGKyle 9y agoDisclosure: I work for AgileBits, makers of 1Password Making extensions cross browser can still be a bit difficult. Our focus here was to get something readily available for a browser that was in high demand on platforms that we were getting a lot of requests for (Linux and Chrome OS). I believe browser support will expand over time with this extension, it's just that we didn't want multiple browsers slow our progress or prevent us from doing cool new things. Give it some time and I anticipate we'll see browser support expand. Kyle AgileBits
- deleted 9y ago[deleted]
- actionscripted 9y agoAm I the only one in here who loves their hosted solutions? We use Teams at work and I use Family for my wife and I. It's important to me that I have access to certain passwords on my desktop, laptop and phone. These items also need to be accessible to others who should be able to view/edit. There's no way to do with without some sort of cloud solution and so the decision becomes which cloud solution. I used to use Dropbox, but now have no need with Team/Family. With teams, when a staff member leaves, we can easily remove them from the admin panel, update all passwords in all vaults they had access to and have those changes immediately available to everyone. A lot of responses here sound incredibly paranoid and almost naive. If you're not syncing passwords between devices/users and you're not putting your information into the cloud then I would argue at some point you may be performing insecure actions to accommodate secrets use/management. For example, how are you logging in on your phone to a service that requires a user name and password when the password lives only in a standalone system on your desktop? If you're not manually entering the password, you're likely doing something security-wise that isn't ideal.
- newman314 9y agoI disagree. In fact, given the regular loss of online credentials, I think you are misguided in your faith in a hosted password solution. There are plenty of people that do not want to for very good reasons. As far as syncing using non-hosted 1Password, I use a combination of wifi sync (for mobile devices) and Resilio (in local sync only mode, no tracker, no cloud copy a la Dropbox) to sync. Works very nicely across 5 or 6 devices and fits my use case of syncing only when my devices are on the same network.
- kobeya 9y agoDoes that work well with multi device updates? What happens if two devices write to the database and then sync?
- newman314 9y agoTBH, do you anticipate a scenario where you are changing passwords on multiple devices in short order or simultaneously? I don't make changes to 1Password that often so while I get that this is HN, not everything needs to be scalable =)
- 7ewis 9y agoI purchased the standalone Mac 1Password app, but moved back to LastPass. I hate LastPass, and want to use 1P but LP just seems to work better. Despite being bloated and ugly. Admittedly, I haven't tried 1P for around a year now. So as I have a license, I have been tempted to go back. Is it worth it? My biggest gripe is in Chrome on iOS. Nothing ever seems to be able to autofill correctly and the UX is just horrible... 1. Tap Menu Button 2. Tap Share Button 3. Tap LastPass 4. Authorise Touch ID 5. Select Password 6. Autofill fails... Go back to 1. (Then hold to copy the password instead of fill)
- AGKyle 9y agoDisclosure: I work for AgileBits, makers of 1Password Chrome on iOS is a unique situation. We offer two things for developers that integrate with 1Password: 1. Native application integration. The idea here is that apps that offer a login to their service/site can pull the username and password from 1Password, then insert it into their native UI controls and sign the user in 2. Web view integration. The idea here is that the developer pass us the web view as part of the process and we handle the filling. Chrome is using option #1, so what they do is give us the URL, we provide the list of Login items, and then they take the username and password and provide the filling. For the filling parts we have absolutely no control over this in Chrome. Any filling related bugs are completely on Chrome to fix. If they used our web view filling option you'd have consistently the same filling behavior as 1Password does in Safari on iOS. Sorry you had this experience though. Unfortunately we can't really do anything about it except say we understand your pain. We spent a lot of time and effort getting our filling systems to work as well as they possibly can and when users report issues in Chrome we have to send them off to Google to report those and get them fixed. Kyle AgileBits
- 7ewis 9y agoThanks for the response. I thought the Chrome issue may have be something like you mentioned. The fact that you're here and replying is another reason why I want to like 1Password. I'd be shocked if a LastPass employee responded to me. Will try copying my passwords over tomorrow and see how I get on!
- fencepost 9y agoI find myself wondering if keepass is going to introduce a new vault type of small individual files in a directory and move into where 1Password used to be (including "cloud" using any of many cloud storage options). edit: Seems to me that even if you set a fixed file size of 1-2k for each entry it wouldn't be too huge, or perhaps a dual-file per entry system with one small fixed-size file (128-256 bytes?) for indexed info (URL, name, username), etc. and a second fixed at multiples (or powers) of 1KB for added data (actual passwords, password history, notes, etc.) you could mostly avoid disclosing information even about URL lengths, etc. You could probably reasonably obscure a lot by doubling the larger file's size as the minimum increment and for most scenarios the file size would still be pretty trivial by modern networking/storage standards. Would stink for binary storage or images, etc. but there are different solutions available for that.
- roustem 9y agoThat's how we designed the original 1Password data format (.agilekeychain). It certainly made syncing with Dropbox much simpler. It does have its drawbacks though. Once you have too many files (and make too many requests), both Dropbox and iCloud will start throttling you. It also might take a while to reload the data, even from the local disk. We had to add a cache file at some point.
- fencepost 9y agoI could see either local caching or (assuming the storage backend provides access to file metadata like date/time stamps that are internally consistent) I can think of several ways to have any instance of the application consolidate those small index files into larger ones such that you'd mostly need to load the consolidated file plus any individual entries modified since its timestamp. If those consolidated files were appropriately named you could even have multiple instances creating them at the same time without causing collisions. Cleanup could be a little trickier, but could likely be done with very little risk as long as a little bit of storage bloat wasn't a big concern. Interesting thought experiment, thanks for mentioning your real-world experiences with it.
- scblock 9y agoChrome only makes this effectively useless. Considering that the entire browser market is moving to a largely unified web extension format this is not that impressive. "Everywhere Chrome works" is simply repeating the mistakes of the past, but with Chrome now instead of IE.
- AGKyle 9y agoDisclosure: I work for AgileBits, makers of 1Password. This was posted in a couple different similar threads so I'm pasting it here as it's a direct answer to your concern. Making extensions cross browser can still be a bit difficult. Our focus here was to get something readily available for a browser that was in high demand on platforms that we were getting a lot of requests for (Linux and Chrome OS). I believe browser support will expand over time with this extension, it's just that we didn't want multiple browsers slow our progress or prevent us from doing cool new things. Give it some time and I anticipate we'll see browser support expand. Kyle AgileBits
- DavideNL 9y agoThe cloud storage they are pushing everyone to annoys me. I feel like it's just a matter of time before i will switch to something else. Also, does the average person really need a $3/month subscription even though they could just store the few KB/MB of data in their iCloud/Dropbox/whatever for free? No they don't, but they probably won't realise that anyway. To me it feels like they are trying to fool people. A 5 year subscription would cost you $3 * 12 * 5= $180 Who would ever buy 1Password software & upgrades for $180 in 5 years? Even though $3 a month feels like a small amount, it isn't.
- reiichiroh 9y agoNope. I'm out then having bought desktop licenses from 1.x to 4.x for Windows and OS X.
- khad 9y agoNothing is changing for you. Apps and extensions are still getting updates, and there is no plan to slow down. 1Password X is only for people who can't or won't install the apps (Linux, Chrome OS, corporate restrictions, etc.).
- woolvalley 9y agoThere is a segment of your users that still want the original 'on-prem' version that you started out with. These nerds have money and understand you want a sustainable business model. Just charge these people an annual software maintenance fee and stop neglecting the standalone version. Yes it wont satisfy everyone, but it will stop all the negative PR that comes out whenever you do something that is artificially cloud only.
- AGKyle 9y agoDisclosure: I work for AgileBits, makers of 1Password How are we neglecting our standalone users? I'm really curious here because we are still introducing features in our existing applications that work for our standalone users. Certain new applications like 1Password X and our CLI are only really easily possible because of 1Password.com, but just because these are being offered doesn't mean we're neglecting our standalone users. Just recently in 1Password 7 for iOS, we added Face ID support, a new favorites screen, and Quick Copy, among others. In 1Password 6.9 we added Drag and Drop support. None of these features are unique to 1Password.com, they work for everyone and they were free for existing users as well. Really curious how we're neglecting you though. I'd love to understand this so I can make sure we address it better. Kyle AgileBits
- woolvalley 9y agoYou don't discard them completely, but new things that can be made by reading local files vs using a cloud API are just made using a cloud API. Updates to current apps I'm guessing will still support local file users if it's easy. Your website has no obvious way on how to buy the standalone version now. It's pretty obvious through behavior that it's a deprecated mode without stating it outright. Most people can deduce it's an official PR position to deny the behavior that is being shown, like your doing right now. But please, just be honest and say it's deprecated. Or start supporting the on-prem users again & ask for a software maintenance fee. None of this on the fence stuff. One guy that I have seen that has done it out right is this one: http://www.keyboard-and-mouse-sharing.com/maintenance.htm http://www.keyboard-and-mouse-sharing.com/maintenance.htm Once deprecation enforcement starts becoming too much, those users are going to go away. A chunk of these customers don't want to do that although, because just paying the $24/year is cheaper than the time and hassle it would take to switch to something else. You could even combine it with the cloud version and just let people choose. But they are not going to chose that if they know on-prem is still deprecated. You guys used to make features that would explicitly avoid server side decryption, like watchtower. We want that back.
- vzaliva 9y agoToo little and too late. It took then years to finally announce (partial) Linux support. By this time most multiplatform users like myself tired of waiting and switched to other password managers like LastPass.
- rynop 9y agoAnyone else having issues adding a second account? I goto chrome://extensions/ click on 1Password X "options" > + Add an acct. I then get prompted to login to my 1st account, have no option to add a second account.
- rynop 9y agoSo found it - there is a "Sign in to another account" at the bottom of the login page.
- plainOldText 9y agoI’ve been using 1Password for years, mainly because the data stays local. If they decide to go full cloud-mode I’m switching to something else or just write my own cli password manager.
- AGKyle 9y agoDisclosure: I work for AgileBits, makers of 1Password We've already announced that 1Password 7 for Mac will be available via standalone licenses, and 1Password 7 for Windows will offer standalone vaults and be available via a standalone license model. So nothing is changing in that regard. Our 1Password.com is the default solution we send our users to but standalone vaults are an option for those that wish to continue down that path. Kyle AgileBits
- plainOldText 9y agoThank you for your reply! I'm more than glad to pay for standalone licenses as I find 1Password extremely useful.
- RoXX1337 9y agowill 1Password 7 for windows finally have feature parity with the mac/ios versions? It has been borderline unusable for years, I complained in the forums like 2 years ago and all that has happened since then is that my thread got deleted.
- AGKyle 9y agoFeature parity is something that our Windows team will be working towards. But you have to keep in mind that our Mac and iOS versions have existed for around 10 years. We last rewrote both of them for version 4 of each. 1Password for 4 iOS came out in late 2012, and 1Password 4 for Mac came out in late 2013. Also keep in mind that both our Mac and iOS applications have a fair bit of shared code. The entirety of their backend, cryptography, local database, and plenty of other utility classes. This means we write something for one and the other can often use it immediately. They're also by far our most popular clients so we have the most people working on them. Our Windows team has to try to keep up with that. So, as you can imagine they have a lot of work to do. I would not say they will be feature parity complete, more or less, ever. It's an uphill battle. However, I think it's safer to say that with 1Password 7 they will have the basics done that will allow them to start implementing more user facing features to try to narrow that gap. There will always be a gap, but it can certainly be a smaller gap. We don't delete any threads on our forum unless they are extremely egregious, so my guess is that the thread still exists unless you got out of line (or others maybe did). But we have always acknowledged that our Windows apps have had work to do. With 1Password 6 for Windows we rewrote the entire client from scratch. It used to be written in Delphi. The new client is written in C# and built on more modern Windows APIs. We wanted to build for the future this time but we also knew that it was going to set us back to square one. So about two years ago is when we started work on 1Password 6. It has come a long way, and with version 7 we'll see the return of standalone vaults and standalone licensing for those that want to remain on that path. Hope that helps some, I just want to set expectations accordingly. Our Mac and iOS apps haven't stopped iterating, and our Windows application was already behind by several years because of the rewrite, it also has nothing that it can share code with, so it's at a disadvantage. We want feature parity and we will likely reach that for the most common features but there will always be a gap. As long as you understand the above, we're happy to field requests for what you believe needs to be there that isn't already there (in version 6). Kyle AgileBits
- BjoernKW 9y agoAs a long-time happy customer of 1Password I have quite a bit of a problem with them pushing their new hosted product. If you want to offer that as an alternative by all means do but don't make it the only long-term option. I would have no problem with paying a monthly fee or paying for every major version (as I have done in the past when applicable) but I think for this use case being able to choose where to host your data - or to not host it at all - is much more justified than it arguably already is with SaaS products in other areas. 1Password certainly know their cryptography but do they also know how to secure servers and networks? I must say I trust Apple or Dropbox a lot more on this matter. In general, the tendency to build and provide every aspect of a service is bothering me. Otherwise known as the Not-invented-here syndrome, which we largely thought to have overcome with the Internet and the age of hosted software, particularly Web 2.0 kind of SaaS offerings, this development amounts to tight coupling and agglomeration of features that are secondary to the benefit of the actual product at hand: Why does every application apparently have to provide these features: - file hosting and serving - calendaring and event notification - messaging - PDF export - and most famously: Email ("Every program attempts to expand until it can read mail.") Why is it so hard to provide just the core features of your product and use other products and services by providers specialising in those to implement ancillary features required for building a product or service? We still have to go a long way in terms of connecting with and building upon other services, one particularly preposterous example of which I recently encountered with a supply chain management process where a company used two perfectly fine - if slightly aging - applications to keep track of different but related data sets. In order to exchange data between these applications a PDF containing the relevant data is exported from application A, sent via email and finally manually entered into application B again. The waste created by processes like this never ceases to amaze me.
- AGKyle 9y agoDisclosure: I work for AgileBits, makers of 1Password I hear you on this, but having years of experience using other sync platforms and having to work within their unique solutions has proven to us that to have the best experience it's best to have a solution designed for your application. Every sync solution has their own gotchas and dealing with it in 1Password is incredibly tricky. I get the feeling that many people think sync is this easy thing that takes a week and you're done. We are still fixing bugs in our various sync solutions and they've been released to users for years. Want an example of how each solution is weird for us? Lets take Master Password changes as an example. If you want grittier details, our blog post on the topic here gives a really nice overview: https://blog.agilebits.com/2015/04/28/how-1password-syncs-changes-to-your-master-password/ https://blog.agilebits.com/2015/04/28/how-1password-syncs-ch... But because of how Dropbox works, we have to: 1. Change the Master Password on one device, let it sync 2. Unlock the other device, let it sync, lock, then unlock again With iCloud, 1. Is the same as above: Change the Master Password on one device, let it sync 2. Unlock the other device with the new Master Password. Very different behaviors and that's just two sync solutions. Adding additional sync solutions would result in similar oddities between them. This type of inconsistent behavior is very difficult to explain to users when things go wrong. They don't want to know these details. They pay us to not know these details. We can't provide a consistent experience with other sync solutions. But we can if we provide our own. Things work the way users expect because we can design the solution to work like that because we control the entire solution. This is just coming from a developer who has been doing support with AgileBits for nearly 6 years. I was the last line of defense between our customers and our users when they wrote in. I seen all the messy stuff that users can find their ways into when things do not work how they expect. I happily welcome our new solution because we can design 1Password in a way that makes sense and is actually incredibly secure as well. That said, if you don't like our hosted solution... have you tried it? If not well... don't knock something you haven't tried. But if you have tried it and don't like it I'd love to hear your feedback. Seriously. I welcome your feedback if you have any after trying it. We love talking with our users and finding ways to make 1Password better. We wouldn't be where we are without our users. Anyway, if you don't like our hosted solution we offer standalone licenses and version 7 for Mac and version 7 for Windows will both be available as standalone licensed versions with standalone vaults just like you're used to. Nothing changes for users like yourself if they wish to continue using that variation of options. Kyle AgileBits
- nsudio 9y agonot sure if I am happy or sad to see Agilebits go this route
- hobarrera 9y agoIt targets Linux users, but is Chrome-only (and not Firefox support?). That's a really really odd, step to take, especially considering both browsers use pretty much the same extensions API.
- dbbk 9y agoHi, big fan of hosted 1Password here! I'm just curious, in the blog post you guys mentioned it autofills two-factor codes. I just tried using the extension on Postmark, and it didn't recognise the input field for my code. What heuristics are you using to determine the code input? As a front end developer myself, is there an autocomplete attribute for instance I could add that would help?
- AGKyle 9y agoIs this postmarkapp.com you're having issues with or another URL? I'd love to make sure I'm testing on the appropriate site and then I can get you some more information. Kyle AgileBits
- dbbk 9y agoHi Kyle, Yes, postmarkapp.com
- AGKyle 9y agoI just setup an account and enabled 2FA for it. What happens is the extension fills the username and password, then when you get to the next page, just click the extension icon and choose the item again. It'll fill the 2FA field. Or you can use the keyboard shortcut and it'll do the same thing. Does that work any better? As far as I am aware it won't automatically fill when the field is on a second page. The filling is one and done, it won't fill again on the next page without your instruction to do so. Kyle AgileBits
- dillera 9y agoAgile Keychain - 41.9 MB Created Wednesday, September 2, 2009 at 5:15 PM Modified Tuesday, November 14, 2017 at 10:02 PM I really don't like the idea of ever putting all my passwords on a server that requires Agilebits to run it. You guys are a dev shop. Let users keep their passwords themselves and keep the stand-alone version (and extensions for it!) going with simple version upgrade fees.
- jvzr 9y agoReading some comments, I feel like I may be the only one here: happy, paying customer. Had the standalone Mac and iOS clients, migrated to the Family plan when it was announced. Couldn't be happier. I really, really am. Love the 1Password.com client which displays all it usefulness on a guest computer. Can't wait to try out 1Password X, but unfortunately I've switched to Firefox recently :(
- AGKyle 9y agoThanks for the kind words. Use the tool that works well for you. If that's us, great, if not, great. We can't fault anyone for having a different opinion, so long as that opinion is informed :) Glad you're on our side though! Kyle AgileBits
- petraeus 9y agoSoon 1 Password will be a pay2win model, micro-transactions for filling in the password online. a second vault? that'll be 2.99 please