7 ms·
I was a 1Password user from when it was fully self-hosted until they started pulling bait and switch tactics to move people to subscriptions and online vaults[1
by iuguy 6y ago
I was a 1Password user from when it was fully self-hosted until they started pulling bait and switch tactics to move people to subscriptions and online vaults[1]. I also had Windows licences, and Windows was certainly a 2nd class citizen while I used 1Password. And of course, it doesn't look like the 1Password Linux client is open source. The back-end certainly isn't.
I switched to Keepass[2] initially, synchronised with NextCloud but it wasn't intuitive enough for everyone. We moved everyone to Bitwarden a few years ago using bitwarden_rs[3] and have never looked back.
[1] - https://medium.com/@kennwhite/who-moved-my-cheese-1password-6a98a0fc6c56#615b https://medium.com/@kennwhite/who-moved-my-cheese-1password-...
[2] - https://keepassxc.org/ https://keepassxc.org/
[3] - https://github.com/dani-garcia/bitwarden_rs https://github.com/dani-garcia/bitwarden_rs
- panpanna 6y agoI think keepass has the base functions covered, they just need a slightly better UI and a simpler way to sync passwords. Thankfully, it's open source so I'm sure someone with fix that soon ;)
- rb666 6y agoI'm also a big fan of Bitwarden. Have tested 1Password, LastPass and a few of the other password managers over the last 5 years. This is the one that ticks all the boxes, has the least bloat, does correct matching. I support it with pleasure!
- somemirth 6y agoYeah same, Bitwarden is really good. Have been using it for the last 4 years.
- DavideNL 6y agoI tested Bitwarden for a while and found it was lacking features compared to 1Password. Until a few weeks back they didn't even have a "Trash", delete an item and it was gone forever. Exporting 1Password to Bitwarden was a complete mess, attachments in items were not imported at all/deleted (you don't get a warning of this.) Bitwarden is okay, but compared to 1Password they have a long way to go in my opinion.
- deleted 6y ago[deleted]
- sascha_sl 6y agoIt depends. 1Password lacks some things I'd really want (like configurable matching, having everything on a subdomain that's not on the public prefix list match is cumbersome). The Windows client is also extremely laggy and doesn't use Windows Hello half the time. 1Password X, which is almost a must-use on Windows, also has desyncing issues. So I guess if you don't mind the above and are on macOS, it's better.
- unicornfinder 6y agoWould agree with this. I went from Mac to Windows and the 1Password client on macOS is much, much better. It's slowly improving on Windows though.
- signal11 6y agoAs a 1Password for Windows user, I can't say I ever experienced lag with Chrome or Firefox. I don't use Hello though, so can't speak to that.
- sascha_sl 6y agoWith 1Password or 1Password X? 1Password X is good for autofill, but it's delegating management to the website which isn't very good a lot of times. 1Password proper however... using it in 2 Windows machines and both ignored the shortcut to open it at least once today.
- rb666 6y agoOdd reply, how are these not very minor issues? Importing from 1 specific vendor is relevant for such a tiny part of the userbase. And yes, trashcan is handy, but really not essential. You first need to make the mistake of deleting an account you wanted to keep, and then the site needs to lack a "forget your password" feature (which is already a trashcan). A clean and fast UI, proper matching of (sub)domains, is something you use constantly. I cannot imagine they aren't more important to all/most users than the single item you mentioned.
- sjellis 6y agoI am very happy with Bitwarden as a product. It does everything that I want, and I like the UX better than the other password managers that I tried. The fact that it is Open Source code that has been professionally audited also gives me an extra level of assurance.
- rocqua 6y agoI looked into the encryption of bitwarden and it seemed to use a little-known SQL encryption extension. That seemed a little too iffy for me.
- faebi 6y agoIt‘s why I switched to Keeweb, it’s keepass compatible, works anywhere and has desktop apps too.
- atoav 6y agoUsing keepass (synced via nextcloud) for ages now, what would be the arguments for bitwarden?
- dgellow 6y agoFYI, the Windows application is now at the level of the macOS version. I was also annoyed by the move to a subscription model and waited a while before accepting to switch. But I'm now quite happy paying yearly given how well they improved their cross-platform support.
- zwirbl 6y agoAt least for me the switch to 1PasswordX messed up my password vault, which took quite some time to repair manually from backups. This drastically reduced my confidence in the software to a point where I switched to bitwarden
- sascha_sl 6y agoI can't mirror that experience, half the time the shortcuts (Ctrl+Alt+| or Shift+Alt+|) don't work for me, or are so slow in opening the application that going to the tray is faster. I loathe the 1Password Mini interface because it doesn't have editing and wish I could just default to something that does. There's also a lot of polish issues. For instance, if you have your taskbar with tray on a secondary screen, it still renders the context menu on the primary. If they are different sizes it might do it offscreen.
- meerita 6y agoI believe you can still self-host if you want. I don't understand how can you be disturbed by offering a cloud service to host your passwords could be bad to switch. I'm happy sub of 1Password and i self-hosted my passwords before for a long time.
- heliodor 6y agoThis is the kind of thing where more paranoia is better. Their service is a big fat target. I don't understand how you can't be disturbed by that.
- SpaethCo 6y agoAll the encryption happens client-side. For this to be a problem you not only have to gain access to the blobs stored on their service, but you also have to be able to decrypt them. I expect they probably pay more attention to abnormal access than most self-hosted users would as well, so you'd actually know about a data leak faster so you could rotate your passwords.
- TheFlyingFish 6y agoPersonally, I'm more comfortable with a service that has entire teams whose entire job is finding and fixing holes in the service than I am with something I toss on a server somewhere and forget about for months at a time. Realistically, which is more likely? 1) That 1Password gets breached and loses their customer information, or 2) that I install Bitwarden on my server, somebody discovers a hole in it, I don't hear about it for a while (or do but don't have time to update), and get all my passwords stolen? For me, the second seems more likely, so I'm happy to stick with 1Password.
- lmedinas 6y agoSame issue for me, having online vaults was the killer for me. Also the subscription made me really think if the service was worth it after all, specially after buying the apps they are asking me more money. I moved to Keepass (and opensource apps) and im fairly happy with it. I dont think i will go back to 1Password.
- makach 6y agoA program worth using is worth buying
- bgeeek 6y agoWoah! I think a lot of people in the free / open source community might have a problem with such a statement. However, I do pay for a password manager because I recognise their importance and view them in a slightly different, almost unique way. I'm not averse to paying for software and services online, too.
- makach 6y agoWhat problems do you think they have? Software is moving away from the classic buy-model and into a subscription/rent based model. Free/open software does not mean no-cost.
- abbub 6y agoHow many times do I have to buy the same software, though?
- makach 6y agoIt depends on how risk-averse your are.
- m12k 6y agoI'm still using 1Password self-hosted - works fine.
- mapgrep 6y agoThis comment is like a canonical example of why a company would choose not to develop for Linux. 1Password puts real resources and risk into supporting a platform that may not pay off, but it’s Not Good Enough for much of the community because: -The client is not open source -the backend is not open source -it’s not “a first class citizen” right away (the Windows port is by all accounts improving) I’m not trying to put down your comment but to point out that when you have a fragmented platform that is difficult to develop for plus a community that is often hostile to closed source or less than perfect feature parity you are going to be relatively deprived of commercial offerings. This is why we see less Linux support broadly. Not that you personally should change your opinions.
- ubermonkey 6y agoWell, maybe. I'm not a Linux desktop person, though, and I'm just as hacked off about 1P's shift to a hosted service, and their poor treatment of the Windows client.
- iovrthoughtthis 6y agoDo you not think that poor Linux support is a result of low users numbers rather than the communities requirements? MacOS has higher barriers to entry than Linux if you want to be on their stores, these do not seem to be an issue for people to overcome.
- lghh 6y agoI think it's fair to say users of different platforms have different needs and if a product doesn't fit that need they won't use it. I don't see any problem with that at all.
- 013a 6y agoDeveloping for every platform has unique properties. Every platform has its own native UI toolkits and look-and-feel; try to release an Electron app, and people complain. Write a great iOS app, but no iPad port, or be a couple months late with support for The Notch, people complain. Linux's main difference is that, with so few users, when their priorities are disrespected by Big Corporate, the populace sides with Big Corporate. Rather ironic; most of the priorities Linux users have are motivated by respecting the user's privacy, security, and freedom. It seems likely to me that its a thought process similar to why much of the downtrodden American middle-class sides with Republicans, despite rarely having their best interests in mind. I use 1Password, and it's fine. But these complaints are legitimate. This is a closed-source security facing application from a company that has raised at-least $200,000,000, which at one time charged a large amount of up-front money ($60+) for their product, used dark patterns to drive customers to their subscription-based closed-source cloud product, then left the original users in the dust. AgileBits should have no-ones good will, and even as a 1Password user, I support anyone who uses this forum to discuss their move to alternatives.
- tikiman163 6y agoYou should consider LastPass. They've had considerably fewer security breaches than KeePass and is accessible either using a local app or from any modern browser regardless of OS. It even has a smart phone app, although the phone app requires a subscription.
- def_true_false 6y agoLastPass has a history of breaches and idiotic design choices, e.g. https://bugs.chromium.org/p/project-zero/issues/detail?id=1209 https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
- kingosticks 6y agoThe Firefox extension is bit hit and miss, the exporting function has been broken for years (no points for guessing why that might be). I am not that happy with it and I do not recommend it. I used to pay for the access to their Android app but that became a free feature ages ago; shortly after the company changed hands, I think. The premium subscription basically gives you some online storage and better support but I don't think those features are worth the subscription cost and so I downgraded to the free tier.
- trevor-e 6y agoYep, super annoying for me as well. I paid $60 which I feel is quite a lot for a password manager. When I built my new computer the other weekend I found everything on 1Password's site was subscription-walled, I finally found a download via a hidden Google backlink. But, of course, since I don't have a subscription it's now in read-only mode... feels really scummy of them.
- WillPostForFood 6y agoThe downloads for older versions aren't hidden. They are at the bottom of the respective OS download pages: https://1password.com/downloads/mac/ https://1password.com/downloads/mac/ https://1password.com/downloads/windows/ https://1password.com/downloads/windows/ I still use 1Password 6 with Dropbox to sync. Works great. If you have a license, you may have the wrong (new) version, or just need to activate it.
- trevor-e 6y agoOh wow, this actually helped me fix it. I had to downgrade to 1Password4 for Windows (no mention my license only works with that version), and after that I was able to enter my old license key. By hidden I meant the downloads page is only linked in the footer. All of the main 'Get Started' and 'Try Free for 30 Days' links funnel you into their subscription process. I thought signing into my account might help, but then realized I'm not able to do so in a 'legacy' account because I don't have a secret key. What a confusing and hostile user experience to 'legacy' license purchasers. It's like they are trying to forget that we ever existed.