17 ms·
1Password for Linux beta
- dundercoder 6y agoExcellent! 1Password has been my weapon of choice for years. Works flawlessly on macOS, previously got by with the browser extension in linux.
- eigenspace 6y agoYeah, I've been happily using it as a browser extension in linux, but very glad to have a standalone app.
- 29athrowaway 6y agoUnpopular opinion: using a password manager as a service is as bad as password reuse: all your passwords behind a single password.
- corytheboyd 6y ago...no, it’s not at all the same thing
- iamdbtoo 6y agoSo then what would you suggest?
- TheDong 6y agoPresumably the alternative to 'a password manager as a service' is 'a local password database and password manager which is not a service'. This can be something like password store, or keepass, where the attacker needs both your password database unlock key / gpg passphrase, but also needs access to the database / gpg keys, which means either physical access, or at least access to your local files. I think there is some merit to pointing this out. If 1password allows anyone to make login attempts against their service, that means some bored teenager with a botnet can make attempts at your password. I use password-store, and I could tell you my gpg passphrase right now, but you still couldn't access any of my passwords. You'd need to get access to my yubikey and my psasword repository before you could do anything with that passphrase at all. I think it's true that a setup like mine, which requires a physical hardware token to decrypt my passwords, is more secure than a password service, however I also think the parent comment is totally wrong. 1password without a hw token isn't the most secure option, but it's way better than password reuse on random sites.
- gilrain 6y ago> If 1password allows anyone to make login attempts against their service, that means some bored teenager with a botnet can make attempts at your password. They would need to guess both your master password and your 128 bit secret key. https://support.1password.com/secret-key-security/ https://support.1password.com/secret-key-security/
- eigenspace 6y agoI can agree that a 'password manager' as a service is less secure than a 'local password database that's not a service', but that's not the comparison the OP made. They compared passwords as a service to reusing a single password and said it was the same, which IMO is foolish.
- adambyrtek 6y agoI've never used 1Password, but both LastPass and Bitwarden support hardware tokens like Yubikey for two-factor authentication. Keeping the encrypted store locally might give you some edge, but I personally need to be able to access secrets from more than one device, and once you allow external access then the advantage of your solution compared to hosted services disappears.
- TheDong 6y agoI don't think the advantage completely disappears. Let's look at one possible attack: the attacker knows all my passwords, and they manage to steal my laptop from my car. What can they do in each scenario? In the case of lastpass, bitwarden, or keepass, the attacker now has all my passwords. The 2fa token was used once in the past, so all the passwords are stored on the device, protected only by a password at most. In the case of password-store with my gpg-private-key on the yubikey, the attacker still can't decrypt anything unless they also stole my yubikey, which I never leave unattended. The fact that my private key on my yubikey isn't just required to sync or login (like it is for the 2fa case), but is rather where the actual decryption is done every single time I access a password, does have a difference. I don't think the difference is very large though, no.
- murermader 6y agoIn order to log in, you need a (really long) secret key + a strong password, that should not be used anywhere else. That is pretty secure. The secret key can be kept save, because it is only required once for each device, when you log in the first time.
- eigenspace 6y agoHonestly, I think your opinion is unpopular because it demonstrates a serious lack of understanding or thought. If you re-use the same password for all sites, it takes just one sketchy site being compromised for all of your other sites to become compromised. In the case of a password manager, the manager itself is the one that needs to be compromised, and you have more reason to trust them to avoid being compromised than some other random site. Some random sketchy website being hacked doesn't need to effect the rest of your network of logins if you use a manager. Most password managers (such as 1password) won't let anyone from any machine access your stored passwords over the web by just supplying your single password. They require multiple extra steps that are quite limiting, so for the most part they first need access to a computer that you've already installed your password manager on. Furthermore, if your password manager is compromised, you have a very clear path to your password on that manager, and then a list of all the websites, usernames and passwords that you need to change in order to regain secruity. By contrast, I'm still rediscovering old websites I used 10 years ago that used my old omni-password which was compromised.
- 29athrowaway 6y agoYour mistake is assuming I had not thought of that. I have, and my position remains the same.
- eigenspace 6y agoThen you should explain why you think what you think instead of just throwing around self proclaimed "unpopular opinions" without any explanation. With the information you've provided (i.e. none), it really just looks like an uninformed opinion. Why do you think the points I listed above don't make password managers more secure than password reuse?
- luhn 6y agoDo you have a counterpoint, or do you have this opinion solely for the sake of having a contentious opinion?
- 6y ago
- NikolaeVarius 6y agoI have MFA. Have fun
- 29athrowaway 6y agoAs if SMS was secure. Your phone company will believe any random person to be you. Not all factors are secure.
- NikolaeVarius 6y agoI dont think my yubikey receives SMS
- 29athrowaway 6y agoYubikeys are secure, but the most popular second factor is SMS, followed by authenticators, which are better than SMS in my opinion. MFA does not imply bulletproof security.
- ssully 6y agoWell since this discussion is in a thread about 1password I think it's worth pointing out that 1password doesn't even support SMS as an MFA option [1]. [1]: https://support.1password.com/two-factor-authentication/ https://support.1password.com/two-factor-authentication/
- gilrain 6y ago1Password does not use SMS for 2FA.
- Lazare 6y agoYou're totally right. As long as you have a different, secure password for every site and service, and you keep a careful list of all of them, and make sure to keep this list backed up, and encrypted, and sync this list across your devices so you have access to it when and where needed, then you totally don't need a password manager. ...oh wait, that's literally a password manager. Sometimes opinions are unpopular for good reasons.
- mekster 6y agoHave you heard of 2fa? Master password alone won't unlock the rest of passwords.
- xmunoz 6y agoThis is too little, too late. I had to migrate away from 1Password last year because of lack of Linux support, and have since been using Bitwarden.
- overcast 6y agoThe browser plugin works fine though?
- bilal4hmed 6y agoI would like to throw out Bitwarden out there. Cross platforms, works on everything and can be self hosted if you so desire.
- tw04 6y agoRequisite: Use bitwarden-rs if you're planning on self-hosting. https://github.com/dani-garcia/bitwarden_rs https://github.com/dani-garcia/bitwarden_rs
- xienze 6y agoYes, this is a fantastic project. The official Bitwarden Docker image is kind of wonky, it needs some sort of license and you have to generate the docker-compose.yml, etc. It really doesn't make for a good automated process at all. bitwarden_rs on the other hand, works just fine, never had an issue with it or incompatibility with the browser extensions or mobile apps.
- mekster 6y agoThe "rs" project is too good to be true. The official one uses MS SQL server and takes quite a bit of memory (which I call it a hidden monthly cost as I need to be using a bigger cloud instance) but this one only takes so little, you can host it on any cheap VPS and it has been working just fine against official clients for years.
- xiaomai 6y agobitwarden looks cool. what parts are open-source and what parts are closed? (are all the premium features closed-source or are they just charging for that in the hosted-by-them version?)
- Macha 6y agoIn the past it was entirely open source, though the hosted version did check for a license key before enabling the premium features. That said, the code for the premium features and the license key check were themselves open source. I see some of the newer premium features, particularly around SSO are under a noncommercial visible source license of their own devising though
- stefan_ 6y agoOh good it's another Electron app and since there are only about 50 random dependencies mentioned in the package.json maintained by about 25 random people, exfiltration of all your passwords is only one of those being compromised away at any given point. And that is just the direct dependencies, I don't even want to look at the tree of it all. If you trust 1password with your passwords, really you are also trusting whoever wrote the braces library for superfast brace expansion.
- TheDong 6y ago> exfiltration of all your passwords is only one of those being compromised away at any given point No, that's absolutely not true. Those dependencies will not automatically update in your local app. The 1password developers should be auditing all updates to those dependencies too, and if you trust the 1Password developers to be competent, then you don't have to trust 25 random developers. Furthermore, this isn't unique to electron apps. If they wrote this in c++, you'd still have to trust 1password devs to audit a dozen libraries they'd vendor in.
- drdaeman 6y agoTrust is non-binary. It is a perfectly legitimate concern that npm dependencies are a threat vector. Obviously, at build time - but we've all heard stories how less security conscious developers let malicious code slip through with just `npm update`. And compared to, e.g., C++ tooling (npm) makes it somewhat easier to slip a malicious update through. So it's not like that's strictly incorrect. The concern is that is not exactly clear what processes AgileBits have in place and how they manage those dependencies. They could - and probably do - things the proper way (private registry for all dependencies, etc), but the concern is that they're accidentally missing something is perfectly valid - albeit voiced incorrectly (as a statement that it is insecure, not a question whenever they do things in a secure manner). Brain farts just happen, even to the very best developers and teams.
- self_awareness 6y ago> Trust is non-binary. What do you mean by that? You either trust, or you don't trust. How can you half-trust?
- haunter 6y agoI want to use KeePassX/KeePassXC but haven't really found any iPhone clients with Dropbox syncing + Face ID unlock. So still with 1Password even though I'm not a big fan of it anymore. It works, so there is that.
- tass 6y agoKeePassium is great and supports 3rd party file sharing. https://apps.apple.com/us/app/keepassium-keepass-passwords/id1435127111 https://apps.apple.com/us/app/keepassium-keepass-passwords/i...
- tw04 6y agoReally? KeepassXC themselves recommend strongbox in their FAQ. It supports FaceID and dropbox (among others) sync: https://apps.apple.com/us/app/strongbox-password-safe/id897283731 https://apps.apple.com/us/app/strongbox-password-safe/id8972...
- nitrohorse 6y agoI think Strongbox supports those features: https://github.com/strongbox-password-safe/Strongbox https://github.com/strongbox-password-safe/Strongbox
- techsupporter 6y agoKyPass supports Dropbox (I use it with WebDAV but Dropbox is present) and Face ID: https://www.kyuran.be/software/kypass/ https://www.kyuran.be/software/kypass/
- xiaomai 6y agoThis is pretty cool. I am a long-time super-satisfied user of pass (https://www.passwordstore.org/ https://www.passwordstore.org/) for all my personal needs, but my work uses shared vaults in 1password and this will make dealing with that a lot more smooth it looks like.
- mbillie1 6y agoLack of 1password support on linux is the main thing keeping me on macos. Sounds like I might be switching back soon.
- dotancohen 6y agoYou might want to look at KeepassXC.
- RealStickman_ 6y agoThat does not come with a simple way to have your passwords and automatically though. A better alternative in my opinion would be Bitwarden.
- Jedd 6y ago> That does not come with a simple way to have your passwords and automatically though. I suspect a typo, but could you describe the problem in more detail? I'm using KeepassXC, and while there are a few challenges around workflow, there's nothing insurmountable.
- RealStickman_ 6y agoYeah, I wanted to write that it does not come with a simple way to sync passwords. Simple as in you type a password and it is synced, instead of having to manually copy the file to each location. Definitely not insurmountable and I used that system for a while as well, but something like Bitwarden, which I now use, is just easier.
- Jedd 6y agoGotcha. I guess for most of us on HN the big delineation is -- can you sync your password store easily (and exclusively) to your own systems, vs can you sync easily with a remote managed service. I'm very much in the camp that eschews the latter. As per my comment elsewhere in this thread, I've got a reasonably robust arrangement using a combination of Syncthing and KeePassXC, which so far has worked well for me.
- beckler 6y agoDoes anyone know if this supports standalone licenses, or is it strictly subscription only?
- flobosg 6y agoIt seems to be subscription only, just like the Windows and macOS versions. EDIT: I was wrong about 1Password 7 for Windows and macOS, see further replies.
- Qerub 6y agoNeither the Windows or macOS versions are subscription-only but they have hidden the standalone license option carefully… See e.g. https://1password.community/discussion/107609/is-1password-7-standalone-license-only-available-as-subscription https://1password.community/discussion/107609/is-1password-7... for some first-hand informaton.
- bgentry 6y agoThe 1Password macOS app is not subscription-only; the standalone purchase is just fairly well hidden because it's not the recommended path: https://support.1password.com/upgrade-mac/ https://support.1password.com/upgrade-mac/ This topic inevitably comes up on every HN 1Password thread.
- 8fingerlouie 6y ago> the standalone purchase is just fairly well hidden because it's not the recommended path I don't care how many arguments they bring to the table that the subscription model is superior, the things that matter are still "broken" in the subscription model: Control over my data and "cost control". With a standalone license i can control where i store my sensitive information, and don't have to rely on 1Password doing the "right thing" and protect their servers. I can also choose if i want to upgrade, or if the current version is good enough for my needs. I will never pay a subscription for any software.
- SparkyMcUnicorn 6y ago
- shmerl 6y agoKeepassXC is packaged in most distros and is open source.
- dyingkneepad 6y agoIt's not a very direct alternative. 1password uses a server and keeps everything in sync for you automagically, while on KeepassXC you have to sync your devices yourself (with some help from them). The more open source alternative would be the aforementioned Bitwarden.
- shmerl 6y agoI think managing your devices sync yourself is an upside, since you can establish yourself to where you sync and how. But it is more complicated to set up as a downside.
- thamer 6y agoHaving to sync passwords manually sounds like a hassle. With 1Password all my credentials are on all my devices, always up to date. It integrates with the password management APIs on iOS so I can create an account on a computer and log in using this same service's app on my phone seconds later and the password will already be there, I just have to stare at the device for a second and I'm logged in. It's all incredibly seamless and I can't imagine having to go back to managing passwords manually.
- shmerl 6y agoI wouldn't trust it to a closed source client and their cloud.
- cowmix 6y agoIt doesn't work with DUO 2FA yet so... I don't know how this can be out of beta.
- gilrain 6y agoThis is a beta.
- mjlee 6y agoI've been running the dev preview since early August, and it's been pretty good so far! Really pleased they're working on this.
- comex 6y agoUses Electron. What a shitshow. Edit: I checked: neither the macOS nor Windows version uses it. So it's not even that they think Electron is acceptable for high-quality desktop apps. They just don't consider Linux important enough to make a high-quality app for it.
- deleted 6y ago[deleted]
- terabytest 6y agoOut of curiosity, what are the aspects of quality you'd be missing out on in an Electron app that you would find in a fully native app?
- self_awareness 6y agoSmall RAM usage.
- pseudalopex 6y agoOr they're going to replace the native apps when the Electron app is out of beta.
- dlojudice 6y agoHas anyone tried Keeper [1]? It seems to be feature complete, cross platform, etc [1] https://www.keepersecurity.com https://www.keepersecurity.com
- jdu9 6y agoIn my opinion, it should be a bare minimum for something as important as a password manager to be free software. Others have mentioned Bitwarden and Keepass in this thread, both of which meet that criteria, but personally I'll stick with pass since I don't need a GUI.
- waynesonfire 6y agoI use pass(1) as well. I love that it allows me to use my yubikey. Also a 1password user. Can't deny it's a wonderful product.
- lomex123 6y agoWhat does that even mean? There is free alternatives. I use 1password because it does a good job.
- _jal 6y ago...as in freedom, not beer. It means the gp considers the problem space sensitive enough that the source should be available for inspection and modification.
- tialaramex 6y agoThe latter in particular means that if there's a thing you wish the software did and it doesn't you can fix that. The more central to your everyday life something is, the more important that is. We take this for granted elsewhere in our lives. You buy a refrigerator, the fridge company doesn't get to tell you that too bad you're only allowed to keep soda in their $80 dedicated "Soda rack" and that little shelf is only for vegetables - you can just put your soda there anyway, and if you want you can even make or buy a gizmo that dispenses cans just the way you want, screw their $80 plastic garbage, you made one from stainless steel scrap at community college. You can take Free Software like pass to pieces to understand how it works too. The thing I keep coming back to is how it uses 'tr' to get random passwords, because it's so simple and yet when you step back it's obviously the correct design. The method goes like this: Unix 'tr' has a mode where it just ignores all input except the character classes you selected which pass through. So e.g. you can say you want passwords with just A-Z0-9. Hook it up to /dev/urandom and the device spews random bytes into it. All the ones that aren't acceptable are just thrown away. Then you catch the desired length of output from 'tr' and you're done. I've seen software attempt to try to bodge a budget of random bits into a fixed character set, which is very difficult to do safely and correctly - but 'pass' just doesn't try to do that at all, why bother when you can make as many random bytes as you want anyway?
- aaronfc 6y agoI have been using LasPass since many years ago. There's an extension for Chrome and for Firefox. On Android I use the app and even though experience is not that "automatic" it works. I am surprised nobody mentioned LastPass is there any reason I should know?
- Osiris 6y agoI've been using it for years ago. There are a few annoyances I have with it, mostly on mobile integration, but not enough for me to try to migrate to another platform. I'd be curious is someone could explain why it would be worth the effort to transition from LastPass to some other provider.
- Proven 6y agoBeen using it cross-OS for years. I'm totally disinterested in wasting my time on finding something better that I don't even want to try even free alternatives. It just works and it's inexpensive.
- gilrain 6y agoLastPass was bought by LogMeIn, which raised some eyebrows. More recently, LogMeIn was bought by private equity vultures. That raises alarm bells for more people. It was that plus experiencing a lot of bugginess in their apps that got me to switch to 1Password. It's been a huge improvement.
- zwayhowder 6y agoI started moving the day LogMeIn acquired them. Lastpass used to have a very open policy of notification for potential security issues and I trusted them as much as one can trust a SaaS vendor. IIRC LogMeIn completely ignored a number of security issues in their applications and refused to acknowledge vulnerabilities.
- Zizizizz 6y agoNah you're fine. There are other good alternatives but Lastpass does the job and that's fine. They do have a lastpass-cli which is quite nice to have as well. It operates somewhat like pass.
- greatgib 6y agoIt blows my mind how you can be smart enough to use Linux and still use a proprietary closed source "password manager" on it. If it was something unimportant, like a game, ok. But a password manager? The key to all your digital life and secrets... And in addition from an American company that will upload your (encrypted) passwords to a cloud in US? And in addition, I find it deceptive that they try to confuse the potential users by pretending to be somehow involved or concerned by open source. See this exchange for example: https://www.reddit.com/r/privacy/comments/7l75d5/comment/drmrkv3 https://www.reddit.com/r/privacy/comments/7l75d5/comment/drm... <<We're not open-source, but we do act like it!>> Wtf?
- dyingkneepad 6y agoIt is worth mentioning that even if you're using an open source manager like Bitwarden, unless you're compiling your own apps and servers you're not really guarenteed to be running the code they host on github.
- henryfjordan 6y agoUnless you lovingly hand-entered all the 1s and 0s for your compiler, you may not even be able to trust anything: https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
- least 6y ago> It blows my mind how you can be smart enough to use Linux Please don't overstate the intelligence required to use linux. It's not that high. > ...and still use a proprietary closed source "password manager" on it. People run plenty of proprietary closed source software on linux. This can include password managers, because perhaps they prefer it. Also a password manager of all things is something most people will need to use cross platform, not solely on linux. > If it was something unimportant, like a game, ok. But a password manager? The key to all your digital life and secrets... Games being another proprietary closed source application people run on linux. Games still present meaningful risks to your computing and privacy. > And in addition from an American company that will upload your (encrypted) passwords to a cloud in US? AgileBits is a Canadian company. > And in addition, I find it deceptive that they try to confuse the potential users by pretending to be somehow involved or concerned by open source. A company can be involved and concerned with regards to open source without releasing a product that is open source. Microsoft releases and contributes to a lot of open source software but Windows and Office are both closed source.
- dyingkneepad 6y agoThe reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered "offline" managers like KeepassXC, but synchronization gets way worse, and there's also the issue about trusting someone else with your mobile apps. I will probably end up convincing myself and keep using Bitwarden more at some point, but I will also probably do some kind of password peppering/salting along with it. Am I really the only one here?
- SloopJon 6y agoI definitely have some password manager anxiety. I'm not too concerned about hacks or losing my password database. For me, it's more about the sense of independence, and being able to log in to my accounts using just my noggin. I might be able to remember one or two strong passwords, but not dozens, which is kind of the selling point of a password manager. I use KeePassXC with a password and key file. I sync the database, but not the file, using Syncthing. On the whole a satisfied customer, although the browser integration isn't perfect.
- als0 6y agoThe most important password is your e-mail. If you lose that then you can lose everything. It's the only password I don't save in a password manager.
- ChuckNorris89 6y agoUhm, that's why you should have 2FA/MFA. Not having your password stored in a password manager doesn't make it bulletproof.
- als0 6y agoI use 2FA/MFA when I can but most sites don't support it.
- ButWhatFor 6y agoHow will this integrate with passwordless infrastructure? Isn’t that the way we are going?
- loeg 6y ago1pass can store arbitrary keys, not just passwords. Also, we're a long, long way from that being reality.
- qudat 6y agoI've been using gnupass for a few years after using LastPass. I couldn't be happier. I control the codebase and all changes made to my password store via my gpg key. It's easy to use, easy to store on multiple repositories.
- wishysgb 6y agoI have been using lastpass for more than 10 years and honestly I do enjoy the ease of use. for example biometrics on the phone. Should I switch? is it worth the time investment.
- ed25519FUUU 6y agoI still can’t bring myself to pay $5 a month in perpetuity for a password manager. None of these saas companies ever price single user licenses below $5, even though $1 or $2 would be much more reasonable.
- gilrain 6y agoListening to music costs $10 per month. Netflix is $15. Surely securing the keys to your digital life is worth at least $5.
- wott 6y ago$5 is the one-time cost of a paper alphabetical index notebook that will store your passwords for decades, will never get hacked, will never fail and will never be shut down.
- overcast 6y agoExcept when it's stolen, lost, burned, easily read, and outrageously inconvenient for long complex passwords.
- tw04 6y agoBoth of those are insanely expensive to create (movies, tv, and commercial music) and bandwidth intensive. 1pw can count the average users bandwidth in kilobytes per month. And while the software is refined, it’s about 1/1000th the complexity and infrastructure of Netflix or Spotify.
- overcast 6y agoThe bandwidth and infrastructure is not where the costs are.
- ed25519FUUU 6y agoI think it’s worth $70, maybe $100. But I want to own my software, not rent it.
- vzaliva 6y agoSo after ignoring Linux users for 10 years they finally decided to grant us their support. I feel my money are better spent supporting vendors who support Linux early on and do not view it as an afterthought. I will stick with LastPass.
- jamesgeck0 6y ago1Password X has been around for years.
- laksdjfkasljdf 6y agoIs there any reason to not use `pass` plus one of the frontends for your Desktop platform of choice? Hearing about people using 1password, etc, I get an uncomfortable smug feeling, similar to when i hear that someone is coding on notepad.exe :(
- deleted 6y ago[deleted]
- pjmlp 6y ago> A true Linux app Electron apps are not true Linux apps, maybe for ChromeOS they can be considered as such.
- switch007 6y agoWhen I read that I had a suspicion that it was going to be electron. It takes some gall to write that heading. Disappointing, 1Password!
- pjmlp 6y agoI already have a browser installed and WebWidgets support on Gtk and KDE, no need for having a bundled browser with each application. Want to do a native Linux app with Web stack? Easy, do it like in the old days, start a daemon and use the local browser. Naturally this makes it harder, because now they would need to worry about Web standards instead of ChromeOS APIs.
- floatboth 6y agoElectron has nothing to do with ChromeOS. In fact ChromeOS could not run Electron apps until the very recent "Linux app support" that's still not available on all devices AFAIK. (Or developer mode hacks + awkward ways of exposing GUI to Chrome that don't support GPU acceleration.)
- pjmlp 6y agoAnother one that didn't get the message that shipping Chrome as application runtime, with Chrome specific APIs, not available as Web standards, is hardly any different than turning the Web into ChromeOS.
- floatboth 6y agoYour post above reads like an incorrect factual statement, not vague message. Either way, Electron's APIs for using native parts of the app from the web part are purely Electron's and DO NOT exist in other Chromium based products.
- setheron 6y agoDoesn't the browser app.1PasswordX make this less necessary ?
- deleted 6y ago[deleted]
- randomsearch 6y agoRecently tried out every password manager as I was sick of LastPass being glitchy with some websites. I’m using OS X and iOS exclusively, with Safari, Chrome, and Firefox. After trying out 1Password, Dashlane, etc. I returned to LastPass - contrary to most of the reviews I found online, LastPass works much more smoothly with most sites and apps. The integration with iOS is much nicer. I found the gap between LastPass and everything else was sufficiently large that it was a no brainer to switch back. I’m still occasionally frustrated with LastPass, but having seen what the alternatives are I won’t be revisiting them for a good few years.
- murermader 6y agoHow is the iOS integration from LastPass better than from 1Password? I am pretty happy with 1Password, it integrates really nice 'next to' keychain
- randomsearch 6y agoSorry, bit misleading there - I meant the iOS LastPass app is better, not the "press here when entering a password" integration.
- jegp 6y agoLet me just mention Gopass (https://gopass.pw https://gopass.pw) which is a brilliant terminal-based `pass`-compatible password manager (https://www.passwordstore.org/ https://www.passwordstore.org/). Gopass is open-source, free, and based on open standards. Meaning, you can use your keystore practically anywhere. For instance on Android with the Password Store app (https://play.google.com/store/apps/details?id=dev.msfjarvis.aps https://play.google.com/store/apps/details?id=dev.msfjarvis....)
- dewey 6y agoSeems like there's a redirect missing. The working address is: https://www.gopass.pw/ https://www.gopass.pw/
- aborsy 6y agoCan I use Yubikeys on iOS and Android? The GPG keys are externally held.
- Fnoord 6y ago> Can I use Yubikeys on iOS and Android? Yes you can. Some YubiKeys support NFC (not sure if that works on iOS though), but also you can use USB-A <-> USB-C converter, USB-A <-> microUSB converter, or just a USB-C or lightning YubiKey, or convert to lightning I guess.
- aborsy 6y agoI know my Yubikey supports NFC, and I use it with other iOS password managers. But Pass on iOS doesn’t seem to support Yubikeys.
- aborsy 6y agoI use keepassxc on Dropbox. It syncs everywhere and if I have doubt about its cryptography, I browse the code, see at least what libraries it’s using, check the forks, read reviews and commentary on the source code, etc. Maybe 1password offers UI to organizations. But for individuals and small groups, it seems to offer fees and less provable security.
- m12k 6y agoLots of people saying they will only use an open source password manager - fair enough, that's your prerogative. But I think it's unfair if everyone just complains that this isn't open source. First people complained that 1Password wasn't on Linux. Then they made a browser extension that works on Linux, and people complained it wasn't native. Then they make a native application, and people complain that it's not open source. That's not their business model, that was never on the table. But it's worth celebrating when Linux is gaining support, even from proprietary companies. It's good that Steam supports Linux even when FreeCiv exists. It's good that Unity supports Linux even when Godot exists. Let's give 1Password some credit for supporting Linux - thanks guys!
- dijit 6y agoI mean, I agree with the principle of your argument, I'm not really one to care _too_ much about specialised programs like this being closed source, especially if they have well defined migration paths and so on. However, this has been _years_, 8 or 9 by my quick check on the App Store. First there was the "agilekeychain" and the python libraries (blimey) to read from it, so I could kinda do my thing on linux, but then it was deprecated and they spent 18months trying to create a CLI variant that on arrival basically never worked. Then they pushed a subscription model which was rather expensive for the functionality too, and after paying for new versions a few times I felt a bit annoyed, and I still could not access my passwords from Linux anyway.. Then they pushed really hard for their own hosted sync (for new vaults at the very least); And without dropbox I couldn't even sync to linux. I'm not sure if they went back on that. Eitherway, the problem is not that it isn't open source per-say. The problem is that it's an incredibly closed ecosystem as it exists today, and an expensive one- maybe you're better off looking at equivalently featured, free, and more open options... of which there are many.
- dingaling 6y agoYou're assuming that 'people' in all those example are the same set of individuals.
- m12k 6y agoNo, I don't think it's the same people. But I wish the people pleased by this development would be more vocal. As a developer, I know just how discouraging it is to make an improvement and all you get back is complaints. I don't think the devs at 1Pasword deserve that treatment for taking Linux seriously as a platform.
- afarviral 6y agoIn the spirit of throwing things out there: keepass/keypassx and keypassdx database(s) synced via nextcloud or syncthing is a dream. My passwords on all my devices and under my own control. Cant beat it.
- Fnoord 6y ago> Cant beat it. Bitwarden_rs can achieve the same.
- deleted 6y ago[deleted]
- chb 6y agoThis isn't ready for beta: no ability to delete logins, no ability to generate a new password or create a new login, no context menu, and not even a Cancel button for the user who starts to edit an entry and then realizes that they can't regenerate a password.
- MaxGabriel 6y agoMy coworker packed it for Nix if that's helpful to anyone: https://github.com/chessai/1password-beta-nix https://github.com/chessai/1password-beta-nix