7 ms·
Unfortunately this only works with hosted 1Password (as far as I can tell), there doesn't seem to be any support for self hosted vaults. Can Roustem or anyone
by ceocoder 6y ago
Unfortunately this only works with hosted 1Password (as far as I can tell), there doesn't seem to be any support for self hosted vaults. Can Roustem or anyone else from 1Password team clarify this?
This was the precise reason I switched to BitWarden 6 months ago, needed a solution where my passwords didn't leave my network.
- dteare 6y agoI'm no Roustem but I'm close. :) You're right, 1Password for Linux integrates tightly with the 1password.com service and as such does not support local vaults.
- Xylakant 6y agoSo how can I access credentials when I’m not connected to the internet? Not at all?
- PascLeRasc 6y ago1Password always stores a local cache, you just won't get updates from other devices synced.
- bwoodruff 6y agoThis is the correct answer. Thanks! - Ben, 1Password
- the_svd_doctor 6y agoIts cached locally on desktop app and phone app.
- barnabee 6y agoI currently get by on Linux by syncing my 1Password vault and reimporting it to KeepassXC every time I need a newly added or updated entry. Annoying to have to create new entries on another devices and sync when I need an account on Linux but it works. Looks like this update provides me with nothing useful. There’s no way I’m moving to a 1Password account, but I might just switch away entirely the next time I need to pay for an update or whatever, given the apparent lack of interest in serving my needs despite the amount of money I’ve paid for updates, etc. to date and the fact that it’s clearly technically possible.
- sedatk 6y ago> There’s no way I’m moving to a 1Password account Why?
- pseudalopex 6y agoUse local vaults and you can firewall the application. Sync a different way and somebody would have to compromise 1Password and the sync service to get your passwords. Use a 1Password account and you have to use your master password in a web browser to manage your account.
- barnabee 6y ago1. I don’t like or want subscription software. I shouldn’t have to pay continuously to retain access to features I’ve paid for for years and it’s not ok to potentially lose access to my main method of creating and accessing secure logins across devices if I stop paying (which could be by choice or, whether temporary or permanently, involuntarily/accidentally). 2. I don’t want to store my data on their servers. I have ways of securely syncing data that I trust and that use only devices I control. For reasons of trust, security, etc. I want control of where my vaults are stored and it not to be the same company as the one that provides the software (for some machines/vaults I can also prevent 1Password from accessing the internet at all, to ensure the vault can’t leave a secure network, for instance). 3. If everything I store in synced folders was a separately charged service I’d be paying thousands a month. This trend is unsustainable and unwanted. I see absolutely no incremental value in the hosting service so I don’t want to pay for it. 3. The whole sleazy business model that pushes users towards subscriptions and makes it harder and harder to stay on self hosted vaults and uses things like this, described by them as the most requested feature, as leverage to try and force more users to switch. When the subscription model was introduced there were assurances to concerned customers that we were valued and this self hosted sync method would be supported. I am fine not getting features that are and should be deeply integrated with and require their hosting service (I also have no interest in ever having access to my vault via a web browser, which has the potential for horrible enough security properties that I’m glad it’s not an option (and I don’t have the time or inclination to have a feature which I don’t require anyway audited)). But when an entire desktop client is put in that bucket, it is because someone decided to make it so to try and get us to fall in line, not because it needs to be. Not the action of a company that respects any the users who still want to self host like they say they did. At this point, with what appears to be a company that’s hostile to my use case, it’s getting difficult to justify spending more money at the next upgrade just to avoid the one time pain of evaluating options and switching to something that’s potentially better for my needs (if it, say, has a full Linux client I can use). If I move I’ll also likely plan to switch over the teams I manage that do use the subscription model. Subscription software makes far more sense in a corporate setting, and if the 1Password account fits the threat model then great, I use it, but if I am no longer using or evaluating 1Password (especially when the reason is partly trust in the company itself), that gets trickier, as does continuing to recommend it to others.
- ceocoder 6y agoAppreciate your response. I'll reiterate what I've said past threads - I love 1Password a lot, and used it exclusively from 2012 to early 2020, in addition to using it personally I converted majority of my extended family to it as well. What irks me is that I paid for the desktop (macOS) app and iOS app once back in 2012 and once again for 1Password 7 (or 6?) upgrade, that is not enough to support the company and is primarily the reason why AgileBits went subscription route. Again - 100% understand and I'd like to support this business. I really don't want to store my passwords on your "servers", and I'm sure there are few others like me - not a majority. In our case BitWarden's idea of paying for a subcription (happy to do it), and hosting BitWarden in my own network - pretty close to local vaults in terms of analogy. I still like the UX of 1Password, if you ever allow local vaults and still charge subscription, I'll sign up on day 1 - I just don't want anything to do with my entire vault being hosted elsewhere, potentially irrational but when it comes to things we store in 1Password and the like - CC #, Passport number, decryption keys, licence codes, launch codes (jk) - I feel OK with my irrational paranoia. Thanks again for making 1Password!
- ben509 6y ago> I really don't want to store my passwords on your "servers", and I'm sure there are few others like me - not a majority. Businesswise, it makes sense as a first push: get a solid UX working for existing 1pass users who sync via the cloud better access on Linux. Then move on to the less glamarous parts like local vaults. > I just don't want anything to do with my entire vault being hosted elsewhere, potentially irrational... There is no logical mechanism that can tell you the correct amount of risk to take on, and yet you can't take actions without accepting some degree of risk. You can't justify your tolerance of risk, so it can't be rational, and yet you have to take an action, therefore you can't be fairly accused of being irrational. It's thus neither; I call it "arational" behavior. You might think, hold on, there's a logical way: I'll look at what happens to a group of people pursuing different risk strategies, then model the expected risk vs return, and thus I can determine the optimal level of risk. But I'd argue it's fallacious to apply that general claim to the individual. For one, you invariably have a set of outliers who were overly risky and beat the odds, were they all wrong? If not, what's the cutoff point, and why? (And likewise, a set of outliers who were unlucky despite being overly conservative, were they also wrong?) Another reason is, as they say in finance, "past performance is no guarantee of future results." Any model you come up with to justify a risk strategy can and will be invalidated as history unfolds.
- DRW_ 6y agoI hope Agilebits considers adding local vault support. I’m a long time user and even a subscriber, but I don’t actually use the account I pay for, for anything except license to use the software - I still use local vaults. I’m happy with this arrangement - it’d be a shame if the Linux client never gets this functionality.
- varenc 6y agoIs this a preview of things to come for Mac/Windows? Will 1Password stop supporting self-hosted vaults?
- burnte 6y agoNo, this has been available for YEARS on Mac/Win, so it's not a preview of anything. Self hosted vaults haven't been in the new apps for years either, although the last version to support local vaults is still available.
- varenc 6y agoThe latest versions of 1Password still support locally stored vaults. They only sell the cloud service subscription these days, but you can still use local/Dropbox vaults on every platform. (except for Linux it seems)
- nikitaga 6y ago...why? Of all possible target audiences it would seem Linux users would be the least receptive to this kind of thing. Forgive my bluntness, but to me this looks like you're just testing forced adoption of 1password.com hosted SaaS on a platform you don't really care about before rolling out the same to Mac & Windows. Which would be unfortunate.
- burnte 6y ago1password as a SaaS app has been out for years, this is not a testing balloon.
- derefr 6y agoI can't speak for them, but it's my impression from using 1Password for a good few years (both the local-vault product, and then the "account" subscription service) that local vaults are basically deprecated, even though they work fine. They're just not a good way for AgileBits to make money. So they'll keep them working in the software for existing customers who paid for them and expected them to work; but they won't add new features to them (except by coincidence as part of architecture-level updates) and won't bring them to new platforms where they weren't originally promised to work. They're a legacy feature, serving legacy customers. For the same reason that they won't bring local vaults to Linux, I don't think they'll ever kill local vaults for macOS or Windows. There are customers who paid for that product, and expect it to still work. (And, unlike e.g. an old version of Photoshop, it's implicit in the USP of a "password manager" product that it'll continue to get updated so that it works on new OSes and so forth, so that you can still have access to your passwords. You can't just stop supporting it; that'd break the whole value-prop of the product, retroactively, and so break the trust of future customers in any "password manager" products you have today.)
- pseudalopex 6y agoThey killed self hosting on all platforms and other sync services on Windows. They tried to kill local vaults on iOS.
- wolco 6y ago
- rootusrootus 6y agoThis is what I like about HN, interesting people drop by from time to time to visit. I have been a happy 1Password customer for years, but I am in the market for a change now. I really wish 1Password had an iOS client that didn't require 17+ permissions.
- bwoodruff 6y agoWe're not thrilled about the 17+ requirement either and are evaluating our options there. Thanks! - Ben, 1Password
- ketralnis 6y agoI'm in the same boat as the sibling: I'm about to move off of 1password because there's no Linux client. I'm a regular licence user, not a subscription user, and I will never buy a subscription from you but I've been happily paying to upgrade every time you release an upgrade to the regular software. It seems that this is signalling your commitment to stop supporting users like me, and that's very disappointing.
- tonyedgecombe 6y ago* I will never buy a subscription from you but I've been happily paying to upgrade every time you release an upgrade to the regular software.* So you are a subscriber in reality, it's just your payments a slightly lumpy.
- tw04 6y agoA subscription implies you lose access to the software when you stop paying the subscription. Buying a license implies you own it and are entitled to use it indefinitely. You might not get any updates but you also aren’t losing access to what you already paid for. Very, very big difference.
- bwoodruff 6y agoWhile I understand where you're coming from, I think "indefinitely" is a fairly impractical viewpoint in the sense of modern computing, particularly in the context of 1Password. Presumably you'll continue to update your web browser and your OS, which will at some point necessitate updates to the 1Password apps. For example, with Safari 13, which came baked in with macOS 10.15, Apple changed their entire extensions framework and retired the old one. 1Password 6 was built around the old one. So even if you have a license, and could theoretically install 1Password 6, if you're a Safari user it doesn't do you much good. Membership on the other hand would've included 1Password 7, where we implemented a Safari App Extension for Safari 13+ support. Just a counter-point for consideration. Also, for what it's worth, 1Password memberships become read-only when your subscription lapses, but you don't lose access. - Ben, 1Password
- ntucker 6y agoPlease tell me local support is coming. I'm a longtime 1Password user who only uses local vaults and I feel like 1Password is increasingly showing me they aren't interested in me as a customer.
- cevn 6y agoI am another linux user that uses local file syncing, so I guess I will have to use the old 1password 4 for windows build forever ha.
- mdaniel 6y agoDepending on your use case, KeePassXC supports reading local vaults, but currently just reading them because I didn't have the need to try and round-trip the vaults for my on-call laptop. I don't believe it would be an overwhelming amount of work to implement the write portion (err, aside from getting a security review) but I do seriously doubt that KeePassXC would accept the PR to change the backing store, meaning it would have to be a fork :-(