35 ms·
1Password 8 will be subscription only and won’t support local vaults
- latortuga 5y agoI love 1Password and I'm happy to pay a subscription so they can continue to run a useful service! Thank you 1Password team!
- evanb 5y agoAlso a stand-alone user since 1pw4. This news finally got me to try pass, the command-line utility. https://www.passwordstore.org/ https://www.passwordstore.org/ The format is plain text. You can git control your password repo. You can organize into directories, etc. It has an extension architecture; you can have it generate otps, for example. You can have specific passwords unlock with more than 1 key, if you want to do eg. family or business sharing. There are mobile apps, browser plugins. None as smoothly polished as 1pw, but good ENOUGH. There are (imperfect) tools for migrating, but you can write your own scripts. So far (using it for 48 hours) the worst part was setting up a gpg key.
- stuzenz 5y agoI was reading through the comments wondering why so many technically capable people are paying for a password store service when passwordstore works nicely in the space and gives you some comfort in knowing how it works. I highly recommend pass. My set up is as follows: - setup the key, share the private key to other devices who are going to use the same pass store; - use syncthing to sync my passwords between devices (you can use github - but I just find it works nicely with syncthing; - all passwords and other content are just gpg encrypted text files; - use the pass cli utility to read the passwords; - first line of the text file is the password so the apps and cli will read that into the clipboard (with a time limit to expire if you are on your phone; - for android phones/tablets I use 'openkeychain' to manage the key and 'password store' as the app to read the encrypted text files and copy the passwords; There are other browser extensions etc. I just don't find a need to use them though. It has worked well for me over the years while I have seen the passwords market go more towards a subscription model over time. My wife uses the same system, I just set it up for her and then it is seamless for her as well. https://www.passwordstore.org/ https://www.passwordstore.org/
- vinceguidry 5y agoI really wish they'd offer other encryption backends than gpg. GPG is pretty long in the tooth. I never have problems with pass, all my problems are with gpg.
- antiframe 5y agoWhat, specifically, is your problem with gpg?
- vinceguidry 5y agoAt the moment, it's that it has very inconsistent support in MacOS. Most of my machines are Linux, after I got the issues worked out on those it works reliably. OSX I use infrequently enough for it to be worth a ton of time troubleshooting. And so it only works rarely, like I think after a reboot. I think eventually I'll figure it out. The error I get is "no secret key". Even though when I run 'gpg' and then make sure my key is there, it still doesn't work when I run the pass commands. But I'd rather use a backend that doesn't require as... weird... integration into the OS as GPG does. Between pinentry and having to store the passphrase, gpg just doesn't offer the same sort of out-of-the-box functionality as something less... heavy.
- seqizz 5y agoI also use and love pass on desktop, even with syncthing and browserpass, all perfectly working. But I am using yubikey to hold my key and that makes it not a good match for mobile setup. Also last time I tried, the mobile apps mentioned were not so easy to use, so I gave up on that front.
- e_proxus 5y agoFor me it’s more about trust. I’d rather trust a company with decades of experience this area than a bunch of random developers that published different unvetted apps on various app stores. And technically, Syncthing doesn’t really seem viable on mobile last time I looked (and also has the problem of 3rd party apps instead of official ones).
- j7ake 5y agoI have been using passwordstore for several years now and I wouldn't be able to go back another product, even if other products were free. Note that the private git repo can be uploaded to the cloud, which allows one to access passwords on multiple computers as well as on my phone. Also I would like to highlight qtpass client for a very user-friendly GUI interface to quickly access passwords. In my opinion, anyone that has basic knowledge of the terminal should be able to set up passwordstore no problem. Once it is set up, one can use qtpass or other GUI clients.
- Zizizizz 5y agoI've been using it for over two years, I absolutely love it. Check out pass-otp as well as rofi-pass (if on Linux) as I think it's the best way to have password entry on any computer. It sends the keystrokes so I can paste passwords in nested virtual environments where an extension might not be installable
- salutis 5y agoAnother happy user of “pass” here. The program integrates with Emacs, Firefox, Unix, and Git like butter. No need for any clouds or services. ;^)
- ramesh31 5y agoMaybe I'm missing something here, but I've never understood the value of any of these password services. How can it possibly be more secure to have your entire digital life hackable with a single cloud based point of failure? Surely it's safer to simply use an encrypted text file on your local PC.
- jl_agilebits 5y agoHi. I'm a features developer for 1Password. You raise a very good question (one that I used to have myself, before I started working here). I would recommend you read our security whitepaper (https://1password.com/files/1Password-White-Paper.pdf https://1password.com/files/1Password-White-Paper.pdf) if you want details, but the TL;DR is that we don't know your account password and our servers only store your encrypted information (which we cannot read), and communication is done over HTTPS with an additional layer of encryption via the SRP (Secure Remote Password) protocol. You also might enjoy this blog post: https://blog.1password.com/what-if-1password-gets-hacked/ https://blog.1password.com/what-if-1password-gets-hacked/
- Mindwipe 5y agoI read the paper when it was published, and wasn't great then and it's definitely not great now.
- jl_agilebits 5y ago> I read the paper when it was published, and wasn't great then and it's definitely not great now. Would you mind elaborating on this?
- Mindwipe 5y agoIt's really simple. It just doesn't consider anything unexpected happening. Compromised algorithms are unlikely. But not impossible. Quantum computing enabling brute force attacks is unlikely in the immediate future, but not impossible. Certificate pinning compromise during transport is not implausible for state actors. And in those scenarios and others, having the vault stored remotely on someone else's machines is inherently less secure than not. The assumptions made in the paper are clumsy.
- nicolas_t 5y agoWell this is the end of the road for me with 1password. I refuse to use anything that doesn't have a local vault. The potential damage if my vault is somehow is accessed is too high, if the vault is stored in the cloud, how can I verify that no one can access it? In that case I have to give access to this app with little snitch since it relies on internet access which means that if I received an update that would disable end to end encryption, I would be none the wiser. Granted, the chance of attack is small but the consequences are extreme. There's no single file more valuable on my computer than my password vault. I prefered buying the license compared to the subscription but I don't particularly mind a subscription for a service I use regularly. I mind the risk to my privacy.
- deleted 5y ago[deleted]
- yunesj 5y ago> the chance of attack is small Is it? I would be surprised if attacking 1Password wasn’t a priority for governments and hackers. If the encryption used on vaults is ever broken, compromised, or buggy, users are screwed.
- perryizgr8 5y agoThey don't have to break the vault encryption. They just have to gain access to 1pwd's git and push out a compromised update. And then watch the passwords roll in automatically.
- nicolas_t 5y agoYes exactly that's what I'm worried about, I'd say if that happened it would be targeted and the chance of me being targeted is small but I also don't want to ever leave myself open to such a thing (also because I've lived in autocratic countries, I don't automatically think all governments are trustworthy).
- mberning 5y agoDone with them. I have been holding out on 1Password 6 for years. The fact that you can’t get the safari extension without going to 7 has had me considering moving for a while. Now it is without a doubt that I will be migrating to bit warden or something similar. Another great product ruined.
- LeoPanthera 5y agoI actually don't have a problem with this, but I do have a problem with press releases that are sprayed with emojis. It's incredibly unprofessional and gives a real amateur flavor to the whole thing, which for security software is really offputting.
- bootloop 5y agoLooks like a forum post to me not a press release?
- LeoPanthera 5y agoIt's obviously more than that, with titled paragraphs and embedded images, this is a prepared statement pasted into a forum.
- ChrisMarshallNY 5y agoThat's been their M.O. for years. I get their emails, and they are similar.
- cpuguy83 5y agoMaybe ask yourself "Why?". It is a much more fun, not suit and tie kind of announcement. This is also a consumer product, not enterprise.
- netmare 5y agoIt's too much fun for me too. Blushing faces and clapping hands look like kindergarden drawings, not consumer-oriented at all. I guess some people are more serious than others. :-*
- HomeDeLaPot 5y agoTo be pedantic, it looks like it's actually an official reply on a community forum, not a press release. Also, thinking that the use of emoji reflects the software quality is a mistake in our current culture.
- nightski 5y agoI haven't had a single bad experience with Bitwarden. I even pay for it now and still run it locally just to support them. Highly recommended if you don't want to be forced into 1Password's service.
- tluyben2 5y agoBitwarden and KeePass here, bitwarden is very good. I do not use browser plug-ins so both are kind of the same but bitwarden just wins on the little things.
- threatofrain 5y agoMay I ask why do you use both Bitwarden and KeePass? Do they have some kind of story of working together?
- kazen44 5y agopersonally, i use bitwarden for passwords only, and i store backups of OTP seeds in a seperate keepass file. I have my OTP codes on yubikey for daily use. (works great, and breaking a yubikey is a lot harder then destroying your phone and losing all your OTP).
- DavideNL 5y agoYou might want to check out the Strongbox iOS app if you don't use Desktop, it's also really good. It uses a Keepass database also.
- jszymborski 5y agoI use Bitwarden for shared passwords with my family (using an Organisation). For my personal passwords, I prefer keeping a local KeePass vault (I access over a local network drive, VPN in elsewhere). I totally agree that primitives are some of the least important parts of choosing password managers, but what I like about KeePass is that you can use Argon2 as the password derivation function and specify your hardness factors. Because my laptop and desktop have a strong-enough CPU and I don't mind waiting 20-or-so seconds before the first unlock, I can set quite high values for this.
- s_dev 5y agohttps://clipperz.is/ https://clipperz.is/ is so much cooler and free. Best of Luck 1Password.
- vezycash 5y agoThanks for mentioning this. It was the first password manager I ever used before switching to lastpass and then to bitwarden.
- ipaddr 5y ago"Do not trust us! Trust our code and the Clipperz community of users and developers!" Last github update 657 days ago.
- comeonseriously 5y ago> Last github update 657 days ago. Maybe it's done.
- tectonic 5y agoWell darn, I guess I have to find a new password manager. 1Pass + Dropbox sync was so good.
- djkorchi 5y agoKeePass + Dropbox works, and you can sync to Android from Dropbox with KeePass2Android.
- baal80spam 5y agoThe real advantage of KeePass(XC), at least for me, is that it can be used to store so much more than simply user/password. I use it to securely store notes and important files.
- avelis 5y agoI have used the Dropbox sync for a long time.
- foogazi 5y agoThat’s my setup too - but now I’m running into 1Password changes and the Dropbox free tier restrictions
- art-vandelay 5y agoSame situation here. I guess my setup will break once they remove dropbox sync from the android app.
- frosted-flakes 5y agoJust save your vault as a local folder and sync it yourself. I use SyncThing.
- ValentineC 5y agoI think the problem here is that 1Password wants to remove "standalone" vaults altogether, preventing any form of 3rd party sync solution.
- wkirby 5y agoNah. I'm good. See ya 1password.
- JohnWhigham 5y agoYup, I'm out of here as well. Been using them since 2014, been frustrated since they heavily push you toward using their cloud, and now this shit happens.
- maxharris 5y ago1Password used to be native on the Mac, and now it's an Electron app. I'm not going to be using 1Password for this reason, and I encourage you to do the same. Subscription business models and non-native apps are hallmarks of rot by VCs. Dump them!
- tablespoon 5y ago> Subscription business models and non-native apps are hallmarks of rot by VCs. Dump them! Can you go more into how non-native apps are a "hallmarks of rot by VCs"? I hate them too, but my impulse is to blame MBA thinking (build once, less investment, who cares if it sucks) than VCs specifically.
- afarrell 5y ago> Subscription business models and non-native apps are hallmarks of rot by VCs. Dump them! The costs of developing and maintaining software are recurring -- especially for security-critical software. Subscription business models align incentives towards ongoing maintenance.
- fortuna86 5y agoWhere they going out of business before offering stand alone licenses? If no, this is a money grab.
- afarrell 5y ago> Were they going out of business... Whom would you rely on to handle something that matters to you: A. Someone who refuses to eat until they start collapsing from hunger? B. Someone who eats regular meals?
- fortuna86 5y agoYou didn't answer my question. Was this a healthy and sustainable business before, or were these changes necessary for survival?
- chrisfosterelli 5y agoThis makes sense to me. Lots of other products have head in the same direction over time (e.g. YNAB) for similar reasons. SaaS is familiar to consumers and ultimately a nicer business model for most products. If you support SaaS for new customers, maintaining the old product / pricing model indefinitely eventually stops making sense. At some point you have to make a move like this. It is probably particularly timely to do this because Lastpass recently changed their pricing model (whether deliberately aligned or not). It's no longer possible to use the free plan of Lastpass and use it on both desktop and mobile: you have to pick one or the other. For many use cases this is effectively a requirement to use the paid plan. So now 1password has the opportunity to push legacy users to a paid monthly subscription knowing that some portion who may have switched to Lastpass to avoid a monthly fee now won't be able to do so, and will probably just pay the monthly fee to 1password instead.
- smnrchrds 5y agoI will run the installed version of YNAB as long as it runs on my computer, and after that I'll probably run in in a virtual machine until the end of time. I am not comfortable with my financial information being on the cloud in the hands of a third party, much less so when it is not the likes of Google and Apple with armies of security engineers and can be hacked much more easily.
- monocularvision 5y agoI held off on the new YNAB for a very long time before switching about a year and a half ago. I absolutely love the new version and the syncing works so much better than before. And the new iOS client is loads better.
- chrisfosterelli 5y agoYeah I can totally understand that. I'm similar with the sync feature: the last thing I'm going to do is give them (or their 3rd party provider) my actual bank credentials. I would feel better if they supported some type of end-to-end encryption. I can also understand how, at least from a business perspective, most users probably don't care enough to not use it.
- miika 5y agoStill using v6 and not planning to upgrade
- cpuguy83 5y agoI was pretty stubborn at first, but honestly 7 has a lot of nice features, especially for families. You can also continue to use your old vault, though the announcement here seems kind of vague if this will continue to be true.
- miika 5y agoThanks for tip, I might upgrade. I was just disappointed that I would have to buy the app again in order to upgrade.. because I just couldn’t see why it wasn’t free update.
- g19fanatic 5y agoapp.keeweb.info with drive sync... good way to go
- eloeffler 5y agoI've never tried 1Password but I've seen many here who endorse it. Does anyone have experience with both 1Password and KeepassXC? Especially with 1Password local vaults...
- aniforprez 5y agoI've only briefly tried Keepass but the UI, the general clunky nature of the UX and such turned me off. To be completely fair, this was 3 years ago when Lastpass was becoming more and more useless and unreasonable. I tried out Dashlane and ended up using 1Password and have been a very happy customer since. I'm not particularly concerned with self hosting or syncing personally
- mdaniel 5y agoI used KeePassXC as the Linux client for 1Password before there was one from AgileBits, and stopped short of implementing _write_ for the opvault format because that wasn't in my use case (and I also had some non-trivial concerns about KeePassXC accepting the PR, so I was trying to pitch it as a way to get more people to import 1Password opvaults) I would be on-board with implementing the write side to opvault if they'd accept the PR, and would also implement the browser extension protocol server if 1Password would specify it, since as others have pointed out the KeePassXC browser extension is suboptimal Then again, with all the massive outpouring of Bitwarden support in every single one of these threads ever, I am pretty sure the real solution is just to bite the bullet and jump ship to Bitwarden/vaultwarden like everyone else seems to be doing I'm willing to stick around long enough to see if AgileBits makes good on their local vault something something, but given the past few years of activity, I'm going with "they're bluffing" or "it'll be a horribly hobbled implementation"
- mdaniel 5y ago> Then again, with all the massive outpouring of Bitwarden support in every single one of these threads ever, I am pretty sure the real solution is just to bite the bullet and jump ship to Bitwarden/vaultwarden like everyone else seems to be doing To follow myself up, I seem to have found another "those people don't know what they're missing" situation because I actually did try Bitwarden (Premium) this weekend and what a dumpster fire compared to 1P I thought about writing up all the shitshow, but ultimately it just boils down to them not caring about their product or users For some of the platforms, I would actually be on-board with jumping in to fix the innumerable bugs, but with them being a mixed setup (open and "premium" features), the fact that so much fundamental behavior has been broken for so long with no obvious mitigation strategy makes me question whether this is something I would want to invest in
- matthoiland 5y agoAnyone have good/bad experience moving from 1Password to Apple' iCloud Keychain? I've recently been using keychain for new accounts, but not sure I wanna bite the bullet and go all in - just need a nudge.
- ValentineC 5y agoMy daily drivers are a MacBook Pro and an iPhone, but I'd go with a 3rd party password manager every time for the ability to access passwords on a non-Apple device if I want.
- jw1224 5y agoI thought about it, but decided I’d miss 1Password’s 2FA auto-fill too much — it’s a huge timesaver for me.
- frou_dh 5y agoNever had any reliability issues with iCloud Keychain since switching over 2-3 years ago, but obviously it's less featureful than 1Password. I liked how 1Password had a dedicated section for software licenses, but now just use a Notes note for that.
- kstrauser 5y agoThe most valuable parts of 1Password for me are storing non-password stuff like license keys, secure notes, random security question answers, and the like.
- kergonath 5y agoI’ve always used secure notes in the Keychain app for this. Not as smooth as 1Password, but it does the job when I need a licence number (when I get a new computer, so once every ~3 years) or an answer to a security question (can’t say how frequent that is; certainly not more than 1 every other year). I’ve been doing that for more than a decade (more like 2 actually) without a hiccup.
- sfotm 5y agoI don't recommend Apple's keychain. It's smart enough to track usernames and passwords and feels very satisfying to use on an iPhone, but doesn't capture some other parts of authentication. This includes security questions, OTP, capturing notes around how sign-ins can be weird (HSAs and other portals rife with redirects), and non-iOS devices (as well as non-safari browsers). Bitwarden is fantastic. I pay for the OTP features, though I feel keeping the codes alongside my passwords weakens my security posture. That's my choice, though.
- vishnugupta 5y agoI know what 1Password is but haven't used it. Are there advantages of using it over Apple's built in keychain? Would appreciate if someone who has used/uses 1Password could comment on this.
- monocularvision 5y agoFor me the most important features are 1. Family support and 2. Cross platform (see #1… we have some Windows machines in the family) If it were just me, the iCloud stuff would probably be enough.
- cpuguy83 5y agoNot tied to Apple. I don't think Keychain (up to but not including iOS 15 beta) supports OTP. On macOS, not much other than Safari seems to use it, I think?
- xondono 5y ago-Multiplaform support -Password sharing There’s some nice “sanity checks” on all passwords, manual or generated, like reused password warnings and by default it checks your logins at haveibeenpwned, which is a nice to have.
- horsemans 5y agoIt has a built in 2FA generator. It supports many more kinds of secure data than passwords and credit cards. It has specific entry types for bank accounts, passports, reward programs, software licenses, and so on. It also has lots of built in analysis tools for determining: - which of your passwords are reused, weak, or present in online password dumps - what websites can have 2FA enabled on them As well as the ability to store entire documents in vaults. Been using 1Password since 2008 and it's the only software of its kind I recommend to anyone on any platform.
- ChrisMarshallNY 5y agoI like it for a number of reasons (other wallet apps can meet these bars, as well): 1) It is very cross-platform. It works on iOS, Android, MacOS, and Windows. I believe that it is also Linux-ready. 2) It has the ability to sequester groups of passwords into "vaults," that can then be assigned in different configurations, for different accounts. This way, the Treasurer gets the banking login, and whatnot, but the Webmaster never sees them, and Treasurer never sees the CP login. 3) It seems to support a whole bunch of TFA. 4) It syncs over everything, and helps to enforce password hygiene.
- nonameiguess 5y agoI'm glad I've been using Bitwarden anyway, I guess, but to me, this is totally unacceptable for security-critical software. You absolutely need to make it possible to self-host. If you're content to only ever be available to low-information, low-effort individual consumers, fine, I guess that's a market, but you've locked yourself out of ever being able to sell to high-security organizations that can't use public cloud services.
- puttycat 5y agoI highly recommend Enpass -- solid UI, single purchase, local vault, and a very handy option to sync via Dropbox (and probably through other services as well).
- canadaduane 5y agoThanks for this! Looks interesting. I feel like I should have heard of it before... any idea why it's under the radar?
- puttycat 5y agoI'm not sure it's that under the radar. It's often recommended here in similar discussions.
- chumsong 5y agoSounds terrible. Doing fine with keepass + dropbox.
- InTheArena 5y agoI am a big fan of 1password. I was very unhappy with the transition to subscription only, and tried bitwarden. After months of futzing around with it, I went back to 1password. I did so after reviewing their audit results, awhat they documented about their architecture, and after they added great support for Linux. At the end of the day, not everything is a conspiracy - and their model appears to be incredibly secure. I would like the self-hosting option (that like Bitwarden, will still require a subscription), but a big part of what I am doing is sharing credentials with family. 1Password does a great job there. Honestly at the end of the day, everything else is about your value proposition. I didn't know or realize that 1Password had shifted to electron as asserted elsewhere. I guessed that there was a new version given that linux was supported but it made no difference for me. Great for them. Likewise, they are far more secure then me editing a password file. Eventually the market will decide here. If people really care about swift versus javascript, then it will penalize them eventually. That said, people arguing that dashlane and others are better then 1password, given that dashlane has access to your passwords, I can't imagine that this is a choice that makes any sense given the basic requirement of a password manager (keep my passwords safe). -- edited correction - dashlane, not lastpass.
- Justsignedup 5y agoI did not realize LastPass has access to your passwords...
- InTheArena 5y agosorry, quick correction. It was dashlane. https://blog.dashlane.com/virginia-tech-passwords-study/ https://blog.dashlane.com/virginia-tech-passwords-study/
- xondono 5y ago> That said, people arguing that lastpass is better then 1password, given that lastpass has access to your passwords Don’t get me wrong, I hate Lastpass with an unprecedented rage for something that should be a simple utility (I’m forced to use it at work and it’s a time sink), but I don’t know where you get that and would like a source.
- xondono 5y agoI honestly have 0 problems with this. They’ve gone over and beyond to support old licences far longer than it could be expected, and a password manager is the kind of sensitive and ubiquitous product for which SaS actually makes sense. Anyone remotely involved in anything similar knows it’s a PITA to keep up to date while keeping device compatibility, and the folks at 1P have been doing great work.
- craigc 5y agoActually a sensitive product is exactly where this does NOT make sense. No matter how good their security is with their cloud version it will still be less secure than having a vault locally on your disk. That is a fact. Subscription services to me are only justified if they are providing a SERVICE which they are with the web version and ability to sync through their own servers, however, using a local version with your own vault can be done without any service at all. So to me this looks like them intentionally crippling their own software in order to force people into paying a subscription fee that is not necessary. They already hide the ability to purchase a standalone license for 1Password 7 trying to get people to pay the subscriptions so this is the next logical step.
- jl_agilebits 5y agoHi, I work for 1Password. I can understand your frustration that we're phasing out local vaults. Luckily, I have some good news: we're currently running a survey to gauge user interest in self-hosting options. If you're interested, go to https://survey.1password.com/self-host/ https://survey.1password.com/self-host/ and let us know your thoughts. Thanks!
- Mindwipe 5y agoToo little, too late. You've already burnt trust here.
- _dot__dot_ 5y agoSelf-hosting is not a viable alternative to a vault kept on Dropbox, unless that is what you mean by self-hosting.
- reilly3000 5y agoI got started with 1Password SaaS based on a work account and added it for my family, so I am not losing anything with this change. I've generally been pleased with the service and its definitely been an upgrade from LastPass in terms of usability and security (no random autofills into hidden forms, no breaches etc...)- that said I'm sad to see this direction. I can't see how this could have been costly to maintain, nor that it would bring them incremental revenue given the backlash and ample competition. Maybe predictable cashflows are worth it, but in principle self-hosting should always be an option.
- jrm4 5y agoPaid third party password managers (without indemnification or other real skin in the game) have always been a dumb idea. This just makes it worse.
- FreezerburnV 5y agoI guess I’m the outlier in being very happy with 1Password and fine with paying for the subscription service. Not only is 1Password the best password manager I’ve used, but it makes it seamless to share stuff with my wife. I don’t care if 8 is an Electron app either, considering I usually interact with it via the browser anyway with their extension. (Also I know that the majority of what they wrote for it is Rust and fast, and I generally trust the engineers to do a good job since they’ve done a good job with it in the past) Also they make a CLI tool for accessing passwords allowing you to integrate password management there: https://1password.com/downloads/command-line/ https://1password.com/downloads/command-line/
- ValentineC 5y agoI'm perfectly happy with paying a subscription, and think $4.99/month for 5 people is affordable. What I'm not happy with is the possibility of password access being limited or sync breaking if 1Password servers go down. At least with Dropbox (iCloud, wifi) sync, I have full control over the local vault file. Ultimately, it might be mostly about ownership and choice for me.
- auslegung 5y agoIf the servers go down you'll never lose access to anything. You would lose sync while the servers were down but you would be able to access everything you already had on every device.
- DavideNL 5y agoAlso I think the "head" of the family can reset passwords of the other accounts...
- DavideNL 5y agoNot sure why I'm being downvoted...: https://support.1password.com/recovery/ https://support.1password.com/recovery/ Ps. They can delete accounts too: https://support.1password.com/add-remove-family-members/ https://support.1password.com/add-remove-family-members/
- xuki 5y agoThe writing was on the wall when they took VC money[1]. Anyone has a good guide to move to Bitwarden/Lastpass? [1] https://techcrunch.com/2019/11/14/fourteen-years-after-launching-1password-takes-first-funding-a-200m-series-a/ https://techcrunch.com/2019/11/14/fourteen-years-after-launc...
- judge2020 5y agohttps://bitwarden.com/help/article/import-from-1password/ https://bitwarden.com/help/article/import-from-1password/ I'd only recommend LastPass if you're a fan of LogMeIn, Ltd. and only being able to see your passwords either on Desktop or Mobile (on the free version).
- dylan604 5y agoSorry, but where else other than Desktop or Mobile are there to view data?
- judge2020 5y agoI mean you can only view your passwords on mobile, OR you can only view your passwords on desktop. On the free version, you can't be signed into both desktop and mobile at the same time, and you can only switch 3 times. https://support.logmeininc.com/lastpass/help/what-can-i-expect-to-change-for-lastpass-free-on-march-16-2021 https://support.logmeininc.com/lastpass/help/what-can-i-expe...
- _jal 5y agoSecond vote for Bitwarden. Lastpass is a bucket of ass. They've had security bugs in their browser extension before, but it is almost required to use it - the webapp works horribly without it. My least-used browser gets that extension, so it isn't running most of the time, at least. And with it, the UI is still terrible. The app is just awkward and poorly done. The one good thing I can say is the user/group model is reasonably implemented.
- 5y ago
- samgranieri 5y agoDamn. This is a huge mistake. I've used 1password for over a decade. I will happily buy an upgrade license. I just don't want another subscription to my credit card. This is rent seeking! Maybe I'll try bitwarden.
- WillPostForFood 5y ago>People are said to seek rents when they try to obtain benefits for themselves through the political arena. They typically do so by getting a subsidy for a good they produce or for being in a particular class of people, by getting a tariff on a good they produce, or by getting a special regulation that hampers their competitors. You may not like the subscription business model, but it isn't rent seeking. Monthly payment != rent seeking.
- criddell 5y agoFrom Wikipedia: > Rent-seeking implies extraction of uncompensated value from others without making any contribution to productivity. I think the rent seeking comment was about removing the option for (free) Dropbox sync and only supporting the subscription-based plan. They are asking for more money for less product.
- WillPostForFood 5y agoThat's out of context, which the preceding sentence establishes: >by manipulating the social or political environment in which economic activities occur, rather than by creating new wealth. Otherwise simply raising the price on something would be rent seeking.
- criddell 5y agoIt's rent seeking because users can't buy the old version with more flexible sync options due to the monopoly granted to the 1Password by copyright. Raising the price of something certainly can be considered rent seeking. For example: https://pnhp.org/news/rent-seeking-by-drug-barons/ https://pnhp.org/news/rent-seeking-by-drug-barons/
- deleted 5y ago[deleted]
- devnulll 5y agoI use 1Password, and migrated over to their subscription service some time ago. A password manager seems like the best overall option at this time. However, given they have all the password for many people, how are they not one of the biggest targets in the world? In their old Dropbox model, I understood the security model. In the service model it's moved to "Just Trust Us". Is there anyone who can help me understand how this model is secure?
- judge2020 5y agohttps://1password.com/security/ https://1password.com/security/ It's basically E2EE (where the encryption key is your master password + secret key, which looks similar to a guid), with the caveat being that 1password is still accessible via the browser so you do have to trust they're not compromising you by saving your secret key + master password separately (that is, unless you're auditing the login page every time you open it).
- djrogers 5y agoErr, have you checked with them? https://support.1password.com/security-assessments/ https://support.1password.com/security-assessments/ They've gone pretty far above and beyond what we're used to seeing wrt sharing security details, audit results, and architecture information.
- cgb223 5y agoAs long as 1Password keeps their policy of not selling usage data to 3rd parties like LastPass does, I’ll keep using this service Self hosting would be nice to keep though. Been thinking about setting up a server to hold all that stuff
- Cd00d 5y agoI've been a long time user of LastPass, and have never heard anything about them selling usage data. This is both upsetting and disturbing.
- mackrevinack 5y agodo you have any links or a quick summary of what lastpass is doing? i hasn't used that in years but i would be curious to know anyway
- brandonarnold 5y agoThe argument they're making in this longwinded post applies to most software today. Standalone licenses made sense when your life revolved around one PC saving data to its own hard drive. Today, if you want that, there are great free/DIY options.
- avidiax 5y agoSubscription based licensing is mostly rent-seeking. The cloud storage, compute, and egress for a password manager is fractions of a penny per year per user. Yes, engineering and upkeep and new features costs money. If those features are truly valuable, then the market would bear paying an additional one-time fee, just as photoshop 8 had to be better than photoshop 7 in some way to justify the purchase.* But what new features could a mature password manager possibly have? Support for newer version of IOS and Android is the only must-have that comes to mind. * File format changes not-withstanding.
- thatswrong0 5y agoSubscriptions are not rent seeking.
- arepublicadoceu 5y ago> Subscriptions are not rent seeking. Subscriptions for expensive products that relies heavily on deals, licensing and huge cloud infrastructure like Netflix, Spotify, etc? Yeah, it's not rent-seeking. Now, for an app that store your passwords, maybe some attachments and, since forever, allowed local vaults. Nowadays being intentionally crippled unless you adhere to this, comparatively, expensive annual subscription? Yeah, that's totally textbook definition of rent-seeking behavior.
- paulryanrogers 5y agoHaving dabbled in productizing desktop software I think it's more because of API churn on modern OS's. It used to be you only need to buy once, and things work for years. Maybe a modest paid upgrade after a major OS upgrade. Now OS's evolve continuously. Semantic versioning be damned!
- deleted 5y ago[deleted]
- acdanger 5y agoDoes anyone have experience migrating from 1Password to an alternative? Hoping there’s an export data from 1Password solution at least.
- rvz 5y agoFirst Electron and now it is subscription only with no support for local vaults. That is a definitive scam and it turns out I was right again [0], when they added Linux moved to Electron and that was a hint in itself of where 1Password was going. [0] [1] I'd rather use a standalone extension as a password manager than use a heavy Electron app that will run my Macbook to the ground. It is either Bitwarden or Dashlane at this point. [0] https://news.ycombinator.com/item?id=27194871 https://news.ycombinator.com/item?id=27194871 [1] https://news.ycombinator.com/item?id=27195834 https://news.ycombinator.com/item?id=27195834
- 0x5f3759df-i 5y agoStandalone user for about a decade now. I find this incredibly disappointing. I don’t mind paying a subscription fee if that’s what makes the business work and allows continuous updates. But either they give us a self-hosted option or I’m done with 1password. Keeping my passwords in someone else’s cloud is a red line for me.
- darknavi 5y agoIf you're actually interested in a self-host option I implore you to fill this survey out for them: https://survey.1password.com/self-host/ https://survey.1password.com/self-host/
- pearjuice 5y agoThe only fear I have with 1password (or any password vault for that matter) is that one day they disappear or see great malfunction losing my data. The thought of having to reset my password everywhere is gut wrenching. Some accounts I don't even remember I have them yet sporadically use them. Losing all of it would be a problem.
- deleted 5y ago[deleted]
- djrogers 5y agoI've been a happy user for over a decade (with a little break in there when I relied on iCloud Keychain), and happily transitioned to the subscription model when it came out. Frankly, it just made more sense - I use it on a ton of different devices, and buying a standalone version for each one cost more than the sub does. I'm also not worried about the Mac app moving to electron - I interact with 1password via my mobile or browser plugin 99% of the time anyway, so I just don't really care.
- _dot__dot_ 5y ago> I'm also not worried about the Mac app moving to electron - I interact with 1password via my mobile or browser plugin 99% of the time anyway, so I just don't really care. The main 'customer benefit` claim for the electron switch (as opposed to the 'developer benefit') they are pushing is 'consistent UI across platforms` so your view exemplifies that, at best, there is really no customer benefit to the switch.
- vbezhenar 5y agoI'm considering to buy macbook soon and I was thinking about moving from KeePass to 1Password, as KeePass sync between Linux and iPhone was not very nice, but reading those news I'll keep using KeePass. I hate subscription software and I'll avoid it whenever possible. Also $3/month is just too much for such a simplistic service.\ Edit: if it's an electron app, my comment does not make sense, sorry, I'd never buy it anyway.
- dschuetz 5y agoOooh, I see, my passwords are far more securely secured in The Cloud then? How do they plan to stay in business? "We have your passwords now! You would not want to lose them unless you agree to our new pricing policy now, would you?"
- sam0x17 5y agoThere's nothing better for orgs right now. Every startup I know of uses it heavily internally. 1Password is here to stay, though this opens up the market a bit for a free competitor or open source project to come in and really disrupt things.
- rkagerer 5y agoBetween this and the Electron news, is Troy Hunt (haveibeenpwned creator) still going to endorse 1Password as his recommended password manager?
- arepublicadoceu 5y agoWell, it would be really strange if he didn't endorse his sponsor.[1] [1] https://www.troyhunt.com/have-i-been-pwned-is-now-partnering-with-1password/ https://www.troyhunt.com/have-i-been-pwned-is-now-partnering...
- rkagerer 5y agoMore recently, he also joined their board of advisors last year[1]. Have a TON of respect for the man, just a little surprised/disappointed these recent moves happened under his watch and would love to hear his unedited take on it all. [1] https://www.troyhunt.com/ive-joined-the-1password-board-of-advisers/ https://www.troyhunt.com/ive-joined-the-1password-board-of-a...
- arthur_sav 5y agoNext "feature". We'll scan your passwords so we know you're know a terrorist wink wink
- politelemon 5y agoThat should fit perfectly into the iphone ecosystem. (considering the recent scanning news)
- 0x000000001 5y agoThey already do this, it's called Watchtower https://support.1password.com/watchtower/ https://support.1password.com/watchtower/
- arthur_sav 5y agoYeah but it was opt-in and you could have local vaults only. Not anymore...
- donohoe 5y agoI love 1Password but the subscription-only path doesn't sit well with me. They're intentionally removing key features so they can justify providing a service that I can do myself. I'm increasingly sick of good standalone software suddenly moving to this model. They are a business, I get it. However how many subscriptions are we going to have to end up with? I get it with Slack, Dropbox, Github, etc as they all started with infrastructure to run. But 1Password (and Adobe and others) are pushing profits far far above their users. It's a shame.
- TheRealDunkirk 5y ago> However how many subscriptions are we going to have to end up with? I started making a list to answer that question myself. So far, I'm up to SEVENTEEN, but I'm sure I'm still overlooking a few.
- donohoe 5y agoI remember dropping cable cos of the costs and now we all have 2-5 streaming services we pay for...?
- syntheticnature 5y agoYou can at least cycle through streaming services, dropping them when there's less content of interest and then re-adding when it has accumulated. It's much more difficult to do that with your password manager.
- Bud 5y agoEven if pick-and-choose subscriptions weren't cheaper than cable (which they are, for me so far at least), I'd gladly pay up to 2x the cost of Comcast service just to avoid subsidizing Comcast's evil monopoly, and how Comcast is intentionally keeping much of the US from having real, modern internet service (read: fiber with symmetric speeds, instead of their bullshit where they pretend a 1000Mbps down/20Mbps up link is lightning-fast and don't even TELL customers what the upstream speed is).
- 5y ago
- lwhi 5y agoI've been using it via subscription for some time. Really happy with it. To be honest, I didn't know it supported local vaults.
- Shihan 5y agoSwitched to KeePass when they introduced the subscription model. I believe the only app that I tolerate as subscription is Lightroom CC. I want to minimise subscriptions because otherwise it is 5$ here, 10$ there and at the end it can be a surprising amount I have to pay each year. But yes, for some apps it may be worth it, but for 1Password I found suitable alternatives.
- 0x49d1 5y agoWhat subscription model? KeePass has no subscriptions, just local exec app.
- bostonpete 5y agoPretty sure they're saying they switched to KeePass when 1Password introduced the subscription model.
- Shihan 5y agoyes, that was what I meant.
- dang 5y agoOngoing and related: 1Password for Mac Moving to Electron - https://news.ycombinator.com/item?id=28143563 https://news.ycombinator.com/item?id=28143563 Recent and related: 1password is considering a self-hosted option to store vaults - https://news.ycombinator.com/item?id=28104134 https://news.ycombinator.com/item?id=28104134 - Aug 2021 (215 comments)
- aborsy 5y agoKeepassxc with Dropbox works good and is super secure! It accepts Yubikey, is open source, has good reputation and is free. But please donate. Developers spend a lot of work on FOSS of all kind.
- mooman219 5y agoKeeWeb + KeePass + Dropbox gave me everything I needed to emulate 1Password, and I definitely recommend that stack if you're greatly opposed to this 1Password change. That being said, the thing that got me to change was when I tried out 1Password for a month and ran into a few minor accessibility issues on their web frontend. I sent a support ticket and very quickly got a response back, was told those issues would be fixed, and then notified me several days later when they were. Like I'm paying 2.99 a month and still received some amazing support. I use a lot of open source projects, and if I have an issue then I try to upstream a fix because the maintainers are usually volunteers, but I've spread myself thin. 1Password gave me the impression that it's in good shape and has great support which was a burden off my mind.
- mvid 5y agoOh well. I've been a 1password user for maybe a decade. I don't mind paying for a subscription, but they have become increasingly user hostile over time. Pushing the in-browser versions of the product, hiding the steps to enable local vaults, and now removing local vaults entirely. Custody of your secrets is something thing a password manager should move away from, not toward. I moved my data to Bitwarden this morning.
- TheRealDunkirk 5y agoI've stuck with 1Password for a long time, because it will work on the occasional Windows machine I need to use. However, it doesn't integrate as well as Apple's native key manager. I've been on the fence about just giving it all to Apple, but it's, like, the one thing out of literally DOZENS of services that I use that Apple does NOT control, and it's kind of important. So I'm really conflicted about the whole thing.
- jamil7 5y agoConsidering the same but keychain always feels kind of like it’s forgotten about with one person in a dusty basement at apple working on it. Importing is weird and convoluted and requires some third-party scripts. I don’t get why they don’t just leverage their unfair position and access to private apis to make a really polished first party password manager.
- account-5 5y agoWhat am I missing with these paid/subscription services? I personally use KeepassXC (Linux/Android). It's shared via cloud, I have a keyfile off device so I'm satisfied it's pretty much completely locked down. Is it browser integration? Genuinely have no idea why I'd pay for this, or why I'd trust a company with my passwords especially when it's not local.
- caymanjim 5y agoI wouldn't use any password manager without browser integration. It's the single most critical feature to me in a password manager (ok, beyond secure storage/access). I haven't looked at Keepass lately, but unless it has a browser plugin and automatic sync between all devices (multiple computers, phones, tablets) without me having to roll my own sync solution, it's a non-starter for all but the most hardcore geeks.
- account-5 5y agoFair enough, KeepassXC does have an official browser plugin, at least for desktop. Never use them myself, separating responsibilities. Personally I don't think Dropbox/Google drive is rolling your own and works for me.
- caymanjim 5y agoIs there a single reason to use 1Password instead of Bitwarden? Bitwarden has a better UI, supports all the same platforms (including browser plugins), lets you easily manage true separation between profiles (unlike 1Password, which essentially forces you to use a single master unlock for say work and personal), and most importantly, lets you self-host. And it's free. 1Password is consumer-hostile and an inferior product.
- selykg 5y agoI would not say Bitwarden has a better UI. Though I guess that's an opinion thing, but oof, is Bitwarden's UI bad. It's almost actively painful to use for me some days. The extension isn't as bad as the desktop app, but the iOS app is absolutely atrocious. I still use it because I'd rather pay $10/yr instead of $36/yr. But I wish Bitwarden would take some time to actually make the app not awful in the UI/UX department.
- smoldesu 5y ago> And now that we’ve started to roll out the next generation of 1Password apps, it’s time to say goodbye to standalone licenses. Well, that's the end of my interest then. I had some curiosity after seeing the Rust integration, but I'm not going to pay a subscription fee to sync the smallest part of my day-to-day life. The convenience really just isn't there for me in a subscription. And no local vaults? Double no, please.
- politician 5y agoI've been looking for a reason to switch to gopass completely. Thanks AgileBits!
- rgovostes 5y agoScott Forstall, who led iOS until 2012 and oversaw the creation of the App Store, once said that he installed a new app every day to see what new ideas developers were coming up with. The mass migration of apps to the subscription model has killed this sort of exploration and discovery of new apps. As one example, I recently looked for a flight tracker and many wanted more than $30/yr for a tool that is (to me) an occasional convenience. I worry less about how much I pay to use an app than how much I'm paying when I'm not using the app. It sucks when I'm too busy to use my language learning app and yet somehow I still end up owing the app developer every month. By the time I end up canceling I might have wasted $60 or more, which certainly doesn't motivate me to install the next app that prompts me to subscribe. I don't know the solution to adequately compensate developers for their work but I hope the subscription mania goes away.
- jackson1442 5y agoI think the model needs to go back to paying for updates/support. Would be great if this was a native behavior on mobile app stores as well (you can kinda do this with Bundles on iOS but it's still kinda hacky). Haven't paid for this software in the past 365 days? Go to the community forum. You can pay 60% of the license charge for another year of updates and support.
- shapefrog 5y agoDevelopers used to be motivated to release the next versoin and make you buy their app all over again. The upside is now you dont have to buy a bunch of applications for $120 (a year if you always want the latest version) and you can just pay as you go. But like you I have had a few subs that ran over and now I avoid where ever possible. Adobe were the last to annoy me, previously I am sure I had paid up for a few months and then unsubscribed. Now its a 12 month commitment when you take out a subscription. Off topic; but if you want a flight tracker, and like to tinker, try feeding flightradar24 (or any of the other), while you feed them you get their full membership. A pi and a usb tv card are all you need to get started!
- GekkePrutser 5y agoOr better: support adsbexchange.com instead. They don't introduce the delay that flighttracker24 do and they don't hide military and business jets. They're really non profit.
- farmerstan 5y agoI have the last non-subscription version on my Mac, PC and phone. They sync through Dropbox. The chrome extensions stopped working a few years ago so I got into the habit of just manually searching, cutting and pasting my passwords, and saving new ones. I don’t even think about it and it’s very easy. Paying $3/month to have it automatically populate the user name and password fields isn’t worth it for me, especially when the browser does this pretty well once you input it the first time.
- jakemauer 5y agoThe main 1password extension for chrome stopped working with the standalone app, but the original extension is here under a different name: https://chrome.google.com/webstore/detail/1password-extension-deskt/aomjjhallfgjeglblehebfpbcfeobpgk https://chrome.google.com/webstore/detail/1password-extensio... I use it dozens of times a day and it works great. It's not as nice as the modern one that works with the subscription/hosted service but it'll certainly be better than what you're currently doing to muddle through.
- fortuna86 5y agoThey cut off Brave support but it still works in Chrome on Macs. Just a matter of time before all browser support is gone.
- dfdz 5y ago> This worked well for nearly a decade but by 2013 the cracks were already showing. By then we had client apps for all platforms, with each one requiring their own separate purchase, often across multiple app stores. And paid upgrades to major new versions were so incredibly painful for everyone involved that we rarely had any. I think they are being fairly transparent. Starting in 2013 there old business model stopped making sense. They were selling individual products for each platform, while trying to integrate all platforms at the same time. The natural solution was to move to a subscription model for a unified service. This provides a mutli-platform solution and generates a continuous stream of income. As a consumer, I actually prefer this model for a security app since it means that it will continue to receive regular updates. There is lots of competition in the space of password managers so I am not worried about them increasing the cost of the service to more than a few dollars a month (if they did this I would just switch to another service).
- mapgrep 5y agoI think one of the best things the U.S. government could do would be to buy and nationalize 1password and give everyone a license. Canadians too, since it was one of your companies :-) I am being intentionally outrageous but do genuinely feel that a good password manager is foundational to good digital security and I find it baffling that it does not come bundled with operating systems or in some other way offered for free. It's such a basic thing that could be done to increase collective resilience to digital attacks. (And if 1password doesn't want to sell there should be funding for an open source equivalent with a default server hosted by either the government or a trusted nonprofit.)
- Barrin92 5y ago>or in some other way offered for free bitwarden is free (and open source) and it has just about every feature that the paid ones have. Sync across devices, desktop and mobile clients, notes etc. One of the best pieces of open source software of the last few years and I have no idea why people are paying subscription fees.
- deleted 5y ago[deleted]
- Osmium 5y agoI appreciate the need for them to do what's right for their business, and that the HN crowd is probably not representative of their broader customer base. With that said, they've lost a customer here. I would prefer not to pay a subscription, but I might have (though if you do the math, I've had paid upgrades frequently enough I'm not sure they'd have made more money off me with a subscription). The sticking point is the lack of local vaults and removing the native app. Very disappointing. The reason I used 1Password to start with and not KeePass was because it was Mac native. It is so deeply depressing to have faster and more efficient computers year-on-year and have all that efficiency wasted by moving to Electron apps. It sounds absurd to say, but there's a real ecological cost to less efficient apps too; it really does add up in aggregate. The lack of local vault is the ultimate deal breaker, not because I think 1Password are untrustworthy, but because I'm reassured that I don't _need_ to trust them in the same way with a local vault as I need to if they're hosting the vault themselves. I think what's most disheartening about this is that the customers who dislike this the most are also likely the customers who've been with them the longest and helped them build their business. I know I've been using 1Password since v2. Given that password management is so central to our daily productivity, jobs, personal lives, I'm not surprised people have some very strong opinions about this. I hope the 1Password management read these threads, but I doubt it. I will stick with 1Password 7 for as long as I'm able.
- lycopodiopsida 5y agoI am a subscriber, an I was a standalone customer before. I've tried to self-host bitwarden-rs, but found the UX and browser extensions being subpar - and I want my wife and parents to use a password manager, too. It runs well. However, I do not thrust their cloud (or any cloud) completely. I still have a local vault, which is synced locally on WiFi with passwords to my router, NAS, bank cards and accounts, mail accounts. The idea is that should there be a breach at 1password.com the critical accounts do not leak and the damage is limited. Edit: Local vaults are not available anymore: https://1password.community/discussion/121638/what-is-the-future-of-local-standalone-vaults https://1password.community/discussion/121638/what-is-the-fu... I have to look for another solution, then. The all-in-cloud bullshit is not acceptable.
- jlhawn 5y agoI'm seeing a lot of "I could do this myself" in this thread. Okay. Then do it. Make your own password manager. Make your own browser and iOS/Android keyboard extensions for it. Make your own cloud backup/sync of your encrypted passwords. Do it.
- stakkur 5y agoBitwarden.
- aphexddb 5y agoLike many others this feels bad to me. I was previously forced to upgrade to 7 so the Chrome extension worked and as a result purchased (again!) separate Windows and Mac desktop licenses. In trying to navigate the site to find out how to buy a desktop only client I encountered the multiple dark patterns to make this nearly impossible. It is no wonder that “97% of people prefer the subscription” since standalone was basically hidden. I love the product experience 1Password provides, I simply prefer managing my own vault (via Dropbox). Based on feedback here I’m going to evaluate Bitwarden. Sigh.
- darknavi 5y agoPlease, if you haven't already, fill out this 1Password survey. They are considering self-hosted vaults but want more data on who/how it would be used: https://survey.1password.com/self-host/ https://survey.1password.com/self-host/ Hopefully they will get the picture.
- aphexddb 5y agoThank you so much for posting this link! I had no idea there was an avenue for product features.
- evo_9 5y agoObligatory BitWarden link: https://bitwarden.com/ https://bitwarden.com/ A good open-source alternative, I've been running it for a few years after I grew tired of 1Passwords shenanigans.
- Mindwipe 5y agoWell that's the end of me using one password. Trying to buy 1password 7 with a local vault was literally the most miserable software experience I've ever had in decades, so I'm not surprised not many people were using it.
- Crontab 5y agoI really dislike subscriptionware. I don't want to depend on software that I might lose accept to if money gets tight.
- tommypalm 5y agoI gave up with 1Password around version 7 because of the push for subscriptions and switched to Secrets (Mac and iOS) - https://outercorner.com/secrets-mac/ https://outercorner.com/secrets-mac/
- kup0 5y agoI am a 1PW subscription user and am happy with the product (however, seeing they are moving to Electron means that is very subject to change...) but Saying that "customers voted with their wallet" and chose subscriptions is disingenous Ever since they've had subscriptions they've made the standalone license page extremely difficult to find on their site. They really didn't give regular users a "choice"- they dark-patterned them into thinking subscriptions were the only option As forthcoming / down-to-earth as these posts from the company seem- they are full of spin. Their impossible-to-find standalone license page is a topic they seem to be avoiding. Edit to add this small addendum: It just really bothers me on an emotional level to constantly run into this juxtaposition as a user of software/hardware: liking a product but being extremely disappointed in the company offering it.
- dvcrn 5y agoI fully agree. Been a standalone user for years and a coworker asked me recently how I got the standalone license because he didn’t think it existed anymore. Even with me knowing it exists, I wasn’t able to find it on their site to send him. (Hint: you have to upgrade within the app, but only if you downloaded from their website, and only if no 1p account or trial is present) Add other dark patterns like the extension being 1PX only by default and doesn't work with standalone. You have to cram through their website to find the legacy extension and even that isn’t straight forward. They tried very hard to hide all info of a standalone existing. (Personal annoyance: locking new features like the redesigned autofill overlay to the subscription-only version even though the Safari extension fully supports it for standalone, but not the others.)
- hakcermani 5y agoAgreed! Also a standalone user for years. (have about 400 passwords and security Qs in 5 vaults). Can even live with subscription (its just forking out a few bucks more), can even live with electron - at least a Linux client will be avaialable rightaway, but why no local store, Dropbox sync was working perfectly !
- kup0 5y agoYes I also ran into the legacy extension issue. The site was confusing as hell, and it seemed purposely so
- justinph 5y agoI've been a happy user of the same version of 1Password 6 for many years, the last non-subscription version. It still works on MacOS Big Sur, and the classic extensions work in Firefox and Chrome (though not safari on the mac). When it stops working, I guess I'll have to look elsewhere.
- xanaxagoras 5y agoThe hits just keep coming. First I have to move off the apple ecosystem, now I have to move off of 1password.
- fortuna86 5y agoIt's so frustrating. The privacy company and the security app are the betrayers.
- therealmarv 5y agoKeepassXC + use your internal browser password manager. Never pay again and comfortable (and secure) on desktop and smartphone.
- fortuna86 5y agoDoes Keepass have 1P import and 2fa code output functions ?
- frugalmail 5y agoMigrated from 1Password to Bitwarden, much MUCH happier.
- stanislavb 5y agoDue to forcing me into the Subscription model, I migrated to Bitwarden recently and never looked back. It’s been working flawlessly for several months now.
- bromuro 5y agoI subscribed because I had to. I have no time to follow the last changes of a company and its app. The current app is already bloated by features I don’t use, so I hoped for another evolution of this software. (i also don’t like the web platform with all those emoji and cheesy design)
- kabdib 5y agoThree bucks a month? They just committed suicide.
- KiDD 5y agoI absolutely hate that it moved to subscription and have since migrated completely to Apple iCloud Keychain since it now supports OTP 2FA.
- 4r4r4r 5y agoThere is no reason to pay for this when KeepassXC and Syncthing accomplish the same thing reliably and for free
- js2 5y agoFor folks looking for a pay-for-it-once app with Mac, iOS, Android and Windows clients, that can sync via Dropbox or Webdav: https://www.passwordwallet.com/ https://www.passwordwallet.com/ I've been using this for probably a decade now. The UI is ugly as sin, but it works well. I use the Apple Keychain for almost everything, but for my critical passwords, I have copies in PasswordWallet. PasswordWallet has one feature on macOS that I've not seen in any other app: auto-type, for those times you can't paste into a password field. I use it rarely, but it's nice to have when I need it. (I have no idea if the Android or Windows clients are any good. I use it only on macOS and iOS.)
- fortuna86 5y ago> For folks looking for a pay-for-it-once app That's what the folks at 1P told us all too..
- lowbloodsugar 5y agoI am fine with the subscription but I need local vaults. That said, macos has been making 1Password less and less differentiated, so guess I wont be renewing my subscription.
- tuxone 5y agoGot 1Password 6 full license for OSX and loved it. Of course I bought also the Android app. Then switched to an iPhone and bought the app again, peanuts. Then I had to start using again PCs and bough the windows full license for 1P 7. I still use 1P 6 on macOS even though the missing support for Safari sucks (that actually made me switch to Firefox!) My point is, there is literally zero added value with the subscription, it’s like buying cars with loans, in fact by buying full licenses I saved money. I hope that 1P 6 and 7 will last me as long as possible, I don’t see any alternative at the moment. IMHO all other options are less secure and/or less convenient.
- dkonofalski 5y ago>there is literally zero added value with the subscription Hard disagree. Any security-focused software will have plenty to keep up with between OS changes, browser changes, site changes, new UI patterns, and even simple bug-fixes that you don't get from single purchases.
- tuxone 5y ago1P 6 running pretty well on last macOS makes your statement wrong. The fact that you pay a monthly fee doesn’t guarantee you anything you described. In fact there are plenty of feature requests that 1P team has just ignored over the years. Not only there is no upside but actually the missing local vault is an horrendous downside.
- dkonofalski 5y agoIf they stop updating 1Password and the app has vulnerabilities then there is a huge advantage to it and, therefore, my statement is not wrong.
- nreilly 5y agoWith the Apple iCloud Keychain supporting one-time (the google Authenticator style) passwords from the next major Apple OS release, I have no reason to continue to use 1Password.
- csilverman 5y agoWell—that’s it for me, I guess. Used them for years, but I’ll switch to the standard Apple password manager. I believe in buying my software once. Not monthly.
- deadpanPotato 5y agoThey said that 97% of their users are already on subscriptions. I get that local vault users are disappointed, but there's an app for you and it's called Bitwarden. I think 1Password made a smart business decision. By cutting loose the need to support local vaults, they can focus more development energy on other things that 97% of their users will appreciate. It's a numbers game. That said...Electron? Ugh. I already spend half my day grumbling about the Slack app.
- tuxone 5y agoThis is a slap in the face to all of their long time customers. To me it looks like a risky decision more than a smart one. Note that new customers just go the subscription path because that is the only option advertised.
- _dot__dot_ 5y ago> They said that 97% of their users are already on subscriptions. It is quite obvious from the response here that 97% of their users who are actually paying attention to these issues are not on the bandwagon. They should rephrase it as "we could fool 97% of our customers into switching after years of misdirection and misinformation".
- almostdigital 5y agoI've been buying licenses since version 3 (2013) even after they started to hide the option. Sad to see 1Password use dark patterns to push people towards subscriptions then twisting that into that people don't want licenses, at least be honest about it. +1 customer lost.
- benguild 5y agoUgh
- kgarten 5y agoApple user for over 20 years. I loved my powerbook 4g and loved the first iPhones. Even though they were not the first mobile nix systems (love for the n770 Nokia tablet with Debian and root!).], I felt empowered being able to hack them easily, getting shells running and recording/analyzing sensor data on them. I feel more and more uncomfortable in the Apple / iOS ecosystem. It’s getting closed down and commodified. Even when there is something cool in terms of tech, they know how to spoil it. Instead of dealing with Pegasus head on and starting to fix the security culture of iOS/Mac, they make our systems less secure (less open and less hackable). I find it sad that there are no viable alternatives for non-tech users. I switched last week to a Librem 14 with Arch Linux, KeepassXC and a pixel 5 running grapheneOS, Miiband 6 with GadgetBridge, a System 76 for work. I honestly love it, there are some hiccups, yet it feels exciting, similar like switching from Microsoft to Apple did 20 years ago. Also moved from programming objective c / swift to rust, elixir and flutter/react. That seems where the innovation happens today for me. As I work in research I have the Privilege to easy switch … we need better alternatives and I feel even stronger about supporting open source and projects and companies that care about it (pine, purism, system76, mozilla, …).
- Khaine 5y agoThis is disappointing. I have been using 1Password for a long time. I'm not opposed to the subscription model per-se, particularly for critical software to ensure it is supported. But I don't want or need my passwords in the cloud. I don't want or need it to be an electron app. I want a simple, lightweight, highly secure, with good UX password manager. 1Password used to fit that bill. With each successive change it moves away from that.
- sleepybrett 5y agofuck these guys. seriously. I've been using this product since 3.x. I chose it because I could use a wide variety of syncing solutions. It did what it said on the tin. Gave me a place to store my passwords that was secure. I was a happy user buying upgrades whenever they came out until 7.x where it took me over an hour to figure out how to buy the non-subscription/cloud version and instead find the link for the standalone version. I paid for versions that I honestly didn't have any features I cared about simply because it kept doing what I wanted it to do. Gone are the days when you can buy a hammer, and use it to hammer just as many nails as you like until it breaks. Now we have to rent a goddamned hammer apparently. Even that wouldn't be so bad if I could still keep my passwords out of their cloud provider. They've fucked up, they don't think they have. So what are the options for someone who just wants a simple place to store a bunch of passwords encrypted in a secure way. With decent clients for ios/mac/windows/linux that lets me be the only person who has their hads on those encrypted bits?
- ashton314 5y agoI hear good things about Bitwarden. https://bitwarden.com/ https://bitwarden.com/
- fortuna86 5y agoI spent an hour setting it up, the export worked well from 1P but you get to the very end to find out that "features" like a functioning F2A code generator or image storage are premium features that require, guess what, a subscription. Damn it. It's only $10 a year but i'd rather buy it outright the way 1P allowed me to in the past.
- sleepybrett 5y agoI like to keep my 2-factor generator separate. There are already a lot of keys in my 1password kingdom. Good to keep some things in a different safe.
- fortuna86 5y ago
- canadaduane 5y agoI feel like Buttercup [1] doesn't get enough attention. Open source, available on all platforms, and has imports from multiple other password managers. If several people offered a small monthly donation for some time, we'd all be in a more competitive situation with password manager companies whose interests drift from our own through time. [1] https://github.com/buttercup/buttercup-core https://github.com/buttercup/buttercup-core
- joelkesler 5y agoThis is terrible news. I am thinking the push to subscription related to their recent fundraising round. I am happy paying upgrade price for each new version of 1Password but I hate the idea of a subscription. Dropbox syncing works well for me. 1Password has done almost everything they can to stop people from using the standalone version. I am disappointed and angry.
- brailsafe 5y agoI'm chillin with 1Password 4 or something. Presumably some MacOS update will break it due to their use of some hacky undocumented API (like Omnifocus2) but until that day comes I'm quite happy syncing to dropbox. I don't like the insecurity of having to pay for something that stores critical data on an ongoing basis. If it's optional, I can make that choice. I do also like a native mac experience. That said, I'm sure a lot of people value their current offering for a variety of reasons, and it obviously makes good business sense. I've been burned by subscriptions in the past though, and I don't want to deal with that again if it can be avoided.
- Valkhyr 5y agoWell, f** 1Password then. I am currently still using them, but once my current apps are no longer supported, whenever that might happen, I will move to another solution rather than paying a subscription for the privilege of storing my data with them.
- MindTooth 5y agoWhen we talk about local vaults, does that also include iCloud?
- MarcysVonEylau 5y agoJust use Bitwarden...
- paulcarroty 5y agoI'm using PasswordSafe probably last 2 years and happy with it. Open source, multiple vaults support, good UI, easy click-to-copy after search query. https://gitlab.gnome.org/World/PasswordSafe https://gitlab.gnome.org/World/PasswordSafe
- system2 5y agoGod bless KeePass with sFTP plugin.
- gspr 5y agoI'm still baffled why anyone on HN would be using anything other than https://www.passwordstore.org/ https://www.passwordstore.org/ A dead simple (in the good sense!) CLI program that lets GPG deal with encryption and git deal with synchronization and distribution. It's perfect. And FOSS, of course. You don't even have to run your own internet-facing git repo for synchronization across devices. You can just put it all on GitHub or whatever.
- sqldba 5y agoI like 1Password so much I don't mind paying for a subscription. But I have to draw the line at no local vaults because there's no other way to keep work data separate without violating company policies.
- peterkelly 5y ago> Every so often one needs to go back to the drawing board and rebuild things completely in order to soar to ever greater heights. No you don't. When you have an awesome product that people love, you just fucking leave it alone. These "rebuilds" always make things worse. See also: Spotify.
- antioxidant 5y agoI’ll switch to Bitwarden! Wait… Bitwarden is cloud only? Wait… Bitwarden doesn’t allow offline editing? Wait… Bitwarden has a self hosting docker which will end up using more RAM than an electron app? Uh, I guess I’ll use KeePassXC then.
- phs318u 5y agoI recommend this every time a similar news item gets posted. Password Safe (designed by Bruce Schneier). I use the iOS and Linux apps and keep them synced via DropBox. Been around for years (I've been using it almost as long). Still getting updates. Still works. https://pwsafe.org https://pwsafe.org
- rStar 5y agoi don't see any real security model here. online only is insecure by design. Hopefully for customers who stick around the user experience continues to be first class, at least, but I have my doubts about that as well. I don't know anything about this company or who makes the decisions, but as a user, in my opinion, 1password used to make every decision in a way that I would have considered correct. 1password made good decision after good decision after good decision as they grew as a company over the years. Every decision was user and security focused, and the product was consistently excellent. those days are over, apparently. from my perspective, there has been a massive shift in company/product values since the shift to the subscription service. I wish them well.
- aecrimus 5y agoFor somebody who's in the Apple ecosystem it seems to me that a password-protected Numbers file should suffice. Are there security implications that I'm missing?
- 8fingerlouie 5y agoAs others have said, i much prefer to keep my password vault and hosting of it separate. Being forced into a 1P subscription feels like a downgrade to me. I've been a faithful customer for years, and have used iCloud synchronization for years as well. My entire household uses the app (through family sharing). Self hosting it is not an option for me (i know how to, and that's why it's off the table), and purchasing a $5/month subscription feels like it's overpriced for what it delivers. I can get 10 months worth of Family365 subscription for what 1P is asking for a year, and that gives me 6 accounts with 1TB storage each and the entire Office suite. The thing that seems to annoy people the most doesn't bother me one bit though. If it works i don't care if it's electron or not. I'm instead evaulating Secrets[1] as a replacement. It requires a $20 in-app purchase to unlock full functionality, but even with 4 people buying it, it's still only 1,5 years of 1P service. For now i will try to get the kids to use iCloud Keychain instead. As for "what's the rush". 1P7 will receive updates for now, until it doesn't, and at some point an update to MacOS or iOS will make it stop working, at which point i will have lost access to my passwords. I much prefer to be in control of when that happens :) [1] https://outercorner.com/secrets-ios/ https://outercorner.com/secrets-ios/
- AwaAwa 5y agoSo ease of access is really the number one driver. Perhaps I'm just old, but I remember when security was never supposed to be easy. When easy, it is taken for granted, and therein lies the failure of security. So essentially this cloud model gives everyone the illusion of security. Probably nothing new, since its all theater at a certain point. This is not to takeaway from all the technical details of 1Ps approach to this, but (once again) in light of what we have seen from the "Trillion $ darling of privacy", enabling scanning of personal content one has to wonder how long before the same is applied by 1P. Remember your vault can store just about anything. I am sure it is only a matter of time before the case is made that we must think of the children. Irony of all this, I'm someone who is paid to migrate customer security to the cloud. Runs counter to my thoughts on the matter, but not those making the financial decisions on all sides. I certainly don't fault 1P for making the prudent financial decision that 95% of their customers have made. As part of the 5% I shall wring as much out of 1P7 as possible and eventually move elsewhere.
- _dot__dot_ 5y agoAs far as I am concerned, this is a `bait and switch` tactic. It is unethical. And it is a surefire way to shoot oneself in the corporate foot and destroy customer trust. Nobody who values security enough to use a password manager would leave their passwords at the mercy of the next corporate turnabout, when said corporation is evidently untrustworthy. This is the same lizard-brain self-interest unleavened by any shred of higher brain functions that people like Shkreli exhibit: `the suckers have switching costs so let's jack up the price obscenely while reducing the actual customer benefits.` Some people should be kept away from MBA programs.
- josephd79 5y agoI switched to Bitwarden a long time ago. I pay for a premium sub now, should probably upgrade to a family plan @ $3 a month just haven't got around to it yet. Worth it.
- fortuna86 5y agoThe thing I genuinely don't understand, and I really hope a 1P employee can answer for me, if it's true that 97% of your customers are subscription and have online vaults, why not just leave the other 3% alone? We pay for your service, we love it, why not reward that? It's not like maintaining standalone licenses and local vault storage is hard, it's already there. Just maintain it.
- justinmking 5y agoCan anyone confirm for me. Is it still possible to buy a stand alone license for 1Password 7? I had heard if you download the Mac app from their website it was possible however I can’t see a way