5 ms·
AgileBits has been pushing people to the 1Password subscription model for a long time now by neglecting their "lifetime" desktop customers. The 1Password chrom
by voska 7y ago
AgileBits has been pushing people to the 1Password subscription model for a long time now by neglecting their "lifetime" desktop customers.
The 1Password chrome extension (not 1Password X) used to work great, then it started crashing about daily for me after one of the updates, forcing me to quit Chrome to fix it. The final straw was when they "updated" the extension to a design that looks 2 years old and is far less functional.
I finally gave in and tried out the subscription model. Here's why it's worse:
- The 1Password X extension is standalone (doesn't need the desktop app) so when you have three different Chrome profiles as I do, you have to sign in to 1Password 3 times. Super annoying.
- They force me to store my data with them. Sure they're the most trusted in the industry and do their security audits, but if they get breached, I'm fucked.
- The Command + \ shortcut to autofill and login doesn't work on 1Password X
- They could have just said that their current business model wasn't achieving the goals and that they needed to charge more (I would have paid more/for a subscription) but instead, they beat around the bush by creating a new product that is inferior.
I no longer recommend them to others for password management. I tell friends and family to use iCloud now.
- JackC 7y ago> if they get breached, I'm fucked. This part is not true -- your data is encrypted with a randomly generated key that is kept locally. You could freely post the data they have all over the internet and it would be fine.
- sroussey 7y agoThe really worry has nothing to do with the data being on a server and more about their update servers sending malicious code.
- JackC 7y agoThat's true, but it would also be true of a desktop app using an offline vault, and is also true of all the other desktop apps you run. The risk of someone running malicious code on your machine is a reason to use two factor auth, not a reason to avoid cloud storage for encrypted files.
- DavideNL 7y ago> but it would also be true of a desktop app using an offline vault Well you can set an application firewall to block all internet access of the 1Password app. So, it can't update automatically, and when you manually update it and it would contain malicious code, it still can't connect/upload anything to the internet. You can even use 1Password sync via iCloud, which is handled externally - not by 1Password, but by macOS. Unfortunately, this can not be done on an iOS device (no app firewall), since Apple locks down everything and decided users may not control their own devices anymore :'(
- wool_gather 7y agoFWIW, Apple has a "VPN" API that can be used to implement a firewall (or a proxy, or etc.). I don't know whether there's a usable commercial product that does that, but if you're really into it you can certainly write your own.
- DavideNL 7y agoYea, but it doesn't really work because you cannot block on the application level. You can only block hostnames/ip-addresses, and these often change with updates, so you'd have to constantly monitor and block new hosts after the app starts leaking again.
- Cthulhu_ 7y agoThat MAY be the case (I'd love for a number of independent parties auditing the security, NOT paid for by AgileBits), but it's still a single point of failure. What if they have data loss? What if that data loss causes local data to be lost due to a sync operation? I've always used the Dropbox approach + backups. If Dropbox has an outage the file is still synced locally. If Dropbox deletes the file via a sync operation I still have my backups. If I delete the files Dropbox has an undelete option. All I want is control over the files.
- voska 7y agoIt also changes the risk profile. AgileBits is a big target, my local machines are not.
- bwoodruff 7y agoBen from 1Password here. We've designed the model so that we aren't a big target. The Secret Key helps with that. https://support.1password.com/secret-key-security/ https://support.1password.com/secret-key-security/
- AdamGibbins 7y agoThat's a strange statement, you're a big target because you're holding lots of peoples secret data. Doesn't matter how you model it, unless your model is to have minimal data/clients.
- bwoodruff 7y agoMinimal data of value, yes. Did you read about the Secret Key?
- microdrum 7y agoBen, everyone here understands the model. It isn't sophisticated and it isn't particularly special. You have a lot of [encrypted] sensitive data. On your network. On servers you own. You are a target. Once the bad guys get the data, they'll worry about the individual keys and whom they want to target. I'm one of the many people who are both dropping 1P and advising friends and family to do the same as a result of this episode.
- deleted 7y ago[deleted]
- lolsal 7y ago> This part is not true -- your data is encrypted with a randomly generated key that is kept locally. You could freely post the data they have all over the internet and it would be fine. Do we know this is true? I assume it is, but I haven't checked the source or verified that I can encrypt/decrypt my data with my key, or that there isn't a master key that 1password has that can access it.
- bwoodruff 7y agoHi lolsal. Ben from 1Password here. Implementation details can be found here: https://1pw.ca/whitepaper https://1pw.ca/whitepaper If you have any questions our security team would be happy to elaborate. They can be reached at support+security@1password.com
- lolsal 7y agoI think it's awesome that you publish a whitepaper, but it's just a whitepaper, not source. It doesn't prove anything. Edit: also there seems to be a lot of this: > We’re sorry. This section of this document is not yet ready. Any- thing you see in this section is at most an outline of things to come.
- bwoodruff 7y agoWe're offering a (mostly) closed source solution. You can evaluate the source for the web app, and the browser extensions. If your argument is that folks shouldn't ever consider using something closed source then obviously 1Password is probably not going to be a good fit and we're at a bit of an impasse. > Edit: also there seems to be a lot of this: Some, yes. I'm not sure I'd say 'a lot', but yes, it is a work in progress. Our security team should be able to elaborate on any points that we have yet to detail, though, if you're interested.
- 33Backpack33 7y agoI've confirmed it because you can see the data that the web browsers sends and it was encrypted. I've also tested this on LastPass and Bitwarden and from what I can see 1Password does it the best.
- beart 7y ago1Password X uses a different hotkey by default and it can be changed in the settings.
- davidcollantes 7y ago> I tell friends and family to use iCloud now. I used to use iCloud, and recommended it to anyone. Sign ons have become more, and more... complicated. There is 2FA, and others now, that 1Password also covers. How are you handing those with iCloud?
- voska 7y agoI'm still using 1P for myself, but looking for alternatives. For non-tech-savvy friends and family, I'm recommending iCloud.
- newscracker 7y agoTry Bitwarden, which has free tiers. You can later choose a (much cheaper) paid subscription if your needs are bigger. You can also self-host it as it’s FOSS.
- voska 7y agoI'm looking into this thanks to all the recommendations from HN :)
- krmbzds 7y ago+1 for Bitwarden. I recommend not saving recovery codes inside Bitwarden. For 2FA I recommend getting a Yubikey. For websites that don't support U2F, I recommend using the Authy app in single device mode with a strong sync passphrase.
- conroydave 7y agoIs it just me or does storing your 2fa code generators in the same place as your login/pw just seem like a bad idea. I know I’m screwed if someone gained access to my 1p... but they wouldn’t be able to get into the more secure services.
- bobbylarrybobby 7y agoI’d love to go iCloud only but it’s not really on the same level as 1Password yet. It can’t store multiple websites for one account, instead storing each website separately; it can’t store identities that aren’t just username and password, such as bank accounts and drivers licenses; and it doesn’t have support for two factor one time passwords, which means I’d need a separate app for that.
- lolsal 7y ago> it can’t store identities that aren’t just username and password, such as bank accounts and drivers licenses For what it's worth, you can manually create a "Secure Note" in Keychain Access and put whatever you want in there. It doesn't do any of the other stuff you mentioned though, just thought it was a nifty mostly-unknown feature.
- jplayer01 7y agoBtw, using code blocks for anything makes it unreadable on anything that isn't a 4k ultra-widescreen display (I assume, because it's certainly unreadable on my 1440p screen). I'm certainly not going to scroll back and forth just to read every single line of that.
- diabeetusman 7y ago- The 1Password X extension is standalone (doesn't need the desktop app) so when you have three different Chrome profiles as I do, you have to sign in to 1Password 3 times. Super annoying. - They force me to store my data with them. Sure they're the most trusted in the industry and do their security audits, but if they get breached, I'm fucked. - The Command + \ shortcut to autofill and login doesn't work on 1Password X - They could have just said that their current business model wasn't achieving the goals and that they needed to charge more (I would have paid more/for a subscription) but instead, they beat around the bush by creating a new product that is inferior.
- george_perez 7y agoI'm using Safari exclusively, but back when I had Firefox installed, you could change the shortcut for 1Password X. Does it not accept Command + \ as a shortcut?
- bwoodruff 7y agoBen from 1Password here. Firefox may, but last I checked Chrome did not. We get around that with the traditional extension by having 1Password for Mac listen for the shortcut instead of the extension itself.
- jplayer01 7y agoCheers.
- voska 7y agoOops. I can't edit anymore. Good to know for the future.
- bwoodruff 7y agoHi voska. Ben from 1Password here. I'm sorry some folks feel neglected. That certainly isn't our intent. I'd encourage anyone who feels that way to reach out to us at support@1password.com. We'd like to understand where those feelings come from and help in any way we can. To address the concerns about 1Password X... - We have desktop integration in beta which can help with point #1: https://discussions.agilebits.com/discussion/101231/introducing-desktop-app-integration-for-mac#latest https://discussions.agilebits.com/discussion/101231/introduc... - Our security model has never relied on the sync service that you choose: https://support.1password.com/1password-security/ https://support.1password.com/1password-security/ - Last time I looked into the Cmd+\ issue the primary difficulty was that not all browsers (Chrome, notably) supported \ as a keyboard shortcut for extensions. The reason we are able to get around this with the "traditional" extension is that 1Password for Mac is actually what listens for the shortcut, not the extension. The same functionality is still possible with 1Password X, just not with that specific shortcut. - 1Password for Mac can be used with the subscription offering. It isn't necessary to use 1Password X. 1Password X is a great alternative for those who cannot install desktop software, particularly those on ChromeOS or Linux. I'm sorry to hear you're no longer using or recommending 1Password but I hope that helps address some of your questions/concerns.
- voska 7y agoThanks for the response. I'll send you an email. I'd like to see AgileBits continue supporting the old 1P extension (i.e. fix the crashing problem) or bring that functionality (Desktop link, only sign in once across multiple Chrome profiles, etc) into the 1PX extension.
- bwoodruff 7y agoWe do support the traditional extension for both membership and standalone customers and it continues to be the recommended way to access 1Password in your browser where possible. If you're experiencing crashes with it we definitely want to know that. We hope to bring desktop integration into 1Password X but as of writing it is in beta testing so I couldn't say when / if it'll be ready for prime time. I've personally been using it extensively as part of the beta though and it is very promising if I do say so myself. Thank you!