6 ms·
Am I the only one in here who loves their hosted solutions? We use Teams at work and I use Family for my wife and I. It's important to me that I have access to
by actionscripted 9y ago
Am I the only one in here who loves their hosted solutions? We use Teams at work and I use Family for my wife and I.
It's important to me that I have access to certain passwords on my desktop, laptop and phone. These items also need to be accessible to others who should be able to view/edit. There's no way to do with without some sort of cloud solution and so the decision becomes which cloud solution. I used to use Dropbox, but now have no need with Team/Family.
With teams, when a staff member leaves, we can easily remove them from the admin panel, update all passwords in all vaults they had access to and have those changes immediately available to everyone.
A lot of responses here sound incredibly paranoid and almost naive. If you're not syncing passwords between devices/users and you're not putting your information into the cloud then I would argue at some point you may be performing insecure actions to accommodate secrets use/management.
For example, how are you logging in on your phone to a service that requires a user name and password when the password lives only in a standalone system on your desktop? If you're not manually entering the password, you're likely doing something security-wise that isn't ideal.
- newman314 9y agoI disagree. In fact, given the regular loss of online credentials, I think you are misguided in your faith in a hosted password solution. There are plenty of people that do not want to for very good reasons. As far as syncing using non-hosted 1Password, I use a combination of wifi sync (for mobile devices) and Resilio (in local sync only mode, no tracker, no cloud copy a la Dropbox) to sync. Works very nicely across 5 or 6 devices and fits my use case of syncing only when my devices are on the same network.
- kobeya 9y agoDoes that work well with multi device updates? What happens if two devices write to the database and then sync?
- newman314 9y agoTBH, do you anticipate a scenario where you are changing passwords on multiple devices in short order or simultaneously? I don't make changes to 1Password that often so while I get that this is HN, not everything needs to be scalable =)
- kobeya 9y agoThe GP was talking about family sharing, so yes.
- rickfillion 9y agoIf you're using 1Password for Mac or iOS, then simultaneous writes are a non-issue. All sync types have conflict resolution implemented, where worst case scenario it'll put the overwritten password into a "Conflict" section at the bottom of the item. With the other apps, you'd get nice behavior with 1Password.com because the first one to hit the server will have its record saved in the archive. That's one of the nice features of 1Password.com, getting to see item history. You don't need to worry about accidentally overwriting changes.
- kobeya 9y agoWe’re not talking about syncing using the server but rather local file that is later synced via a file sharing service.
- bearcobra 9y agoI love it too. I completely understand why some people want to avoid a hosted solution, but it makes sense for me and my family. I've probably recouped the subscription cost in the time savings compared to having to troubleshoot my wife's setup every couple of months.
- macNchz 9y ago> I've probably recouped the subscription cost in the time savings compared to having to troubleshoot my wife's setup every couple of months. Absolutely agreed–the hosted solution made it so straightforward to get my girlfriend onto a password manager that I've never looked back. I had used the standalone version with Dropbox sync for a long time before switching, but I had enough (occasional, minor) issues with the sync process that I didn't want to push it on her and then have it become a point of frustration when I wasn't available to help debug it. The hosted solution has been totally seamless to set up on various devices, adding additional shared and personal vaults for household accounts was painless, and my own peace of mind in knowing she uses it for everything is worth a lot to me.
- zamalek 9y ago> Am I the only one in here who loves their hosted solutions? No, even though I'm fully-aware that it's ill-advised. You're picking your poison: you can either have absolute security (which should always win, but I am human) or convenience. That being said, I'm not a fan of them forcing people down their hosted route.
- epistasis 9y agoWhat part is actually hosted here? Do they store opaque encrypted blobs and pass those around, or can they see the actual secrets too?
- masukomi 9y agoI'm pretty confident that AgileBits only has access to the encrypted versions of stuff. They've thought about this long and hard and it would decimate their business if they did anything as stupid as storing things in plaintext. That's why you have to enter your master password... to decrypt the file.
- AGKyle 9y agoDisclosure: I work for AgileBits, makers of 1Password We outline the entirety of how this works in our white paper: https://1pw.ca/whitepaper https://1pw.ca/whitepaper We cannot tell what your data is. It's encrypted on your device using keys that only you know. Then we store it on our side on the server. The unique solution of using your Master Password and your Secret Key, makes brute forcing the data on our server an incredibly expensive job for anyone attempting to do so. It makes our servers an absolutely terrible target. I definitely recommend reading the white paper, it's quite easy to read, even if you aren't super interested in cryptography. If you have questions though just let me know. I'll make sure you get answers. Kyle AgileBits
- t0mbstone 9y agoAll it would take for 1Password to decrypt our entire vault is for 1Password to push out a software update that simply made it so that the client app uploaded the keys to 1Password's servers after the user typed it in. Without 1Password releasing their source code, end users would have no idea if such an update ever took place. We just have to trust 1Password as a company. Well, if we already trust 1Password as a company, what's the point of even using encryption? Might as well just store it in plain text in a database on your servers and trust that your employees won't look at them! Without open source auditing of all clients and md5 checksums of compiled binaries, security is nothing more than an illusion.
- mnutt 9y agoI really wanted to use 1Password for Teams, I don't mind paying a subscription model, and their whitepaper on their hosted solution is really quite thorough: https://1password.com/security/ https://1password.com/security/ My big issue is still with the web app allowing you to unlock your vault and access your passwords. They acknowledge in the whitepaper that it's theoretically possible that an attacker could MITM your SSL connection and serve malicious javascript, stealing both your master password and any secrets you access. They list certificate pinning and DNSSec as unimplemented future actions they may take, but also need to take into account that their web app servers themselves may be compromised. All of this could ideally be mitigated by centrally hosting encrypted password databases, but either a) having the extension/desktop app cryptographically verify all server pages and assets, or b) allowing the web UI to be entirely disabled. If they did either of those I'd sign up for an enterprise account in a heartbeat.
- AGKyle 9y agoThis is something we plan to tackle in the future. Probably via some sort of downloadable local copy of the web client. But it's possible we integrate it into each app somehow. It's still something I think we're trying to think through to try to get right before we act. As it stands, the only reason you need to login to the web client is for administration purposes and sign up. After that the native clients handle the rest. That said, as you indicated, we're aware of this potential vector of attack and acknowledge it. Kyle AgileBits
- nucleardog 9y agoI'm syncing passwords between devices, but I'm not using "the" cloud. I self-host ownCloud. I use their clients for syncing on desktop, and a separate utility on Android for syncing my 1Password vault to my phone. My data never leaves my hands. My thinking, besides just general paranoia, is that while AgileBits is probably more competent than I am when it comes to securing and administering their infrastructure, their infrastructure is also a much bigger target. It's unlikely -- given my general lack of doing anything interesting or controversial with my life -- that I will ever be specifically targetted. It's much more likely that I will become collateral damage. e.g., https://www.theregister.co.uk/2012/03/02/linode_bitcoin_heist/ https://www.theregister.co.uk/2012/03/02/linode_bitcoin_heis...