26 ms·
1Password for SSH and Git (Beta)
- MrYellowP 5y agoI still have no idea why people use these kinds of programs. I have no idea how companies managed to sell this security nightmare as a feature to actually serious people. A single point of failure. Yeah, great idea!
- sbarre 5y agoGenuinely curious, where do you store your passwords and sensitive info like SSH keys? I hear a lot of "cloud password managers are bad!" but I rarely see someone follow up with a better approach. Even better to them. I've been using a password manager for years and I've always thought I was making a good decision but then I see all these comments and I wonder if I'm missing something.
- karmajunkie 5y agoYou're not missing anything—some people just like to grumble. I've never seen anyone come up with a reasonable alternative that isn't "rely on your own faulty memory."
- MrYellowP 5y agoOkay, so you're an asshole. Let's set this straight. I don't store my passwords anywhere. I don't need to remember my passwords, they're the results of functions based on logical deduction and observation within the context of the "thing" I need the password for. And my passwords are all, without exception, beyond 10 characters.
- AndyMcConachie 5y agoI use KeyPassXC for almost all of my secret storage needs.
- howinteresting 5y agoDo you have family or friends with whom you share passwords? 1pass excels in that situation.
- karmajunkie 5y agoThat's still a password manager. GP was asking what alternatives to the entire class of applications exist that provide equivalent security for unique passwords and keys
- MrYellowP 5y agoI don't store them anywhere. I don't need to remember my passwords, they're the results of functions based on logical deduction and observation within the context of the "thing" I need the password for. And my passwords are all, without exception, beyond 10 characters.
- phantomathkg 5y agoI still have no idea why people think password manager is not a good thing. Maybe you should read this? https://www.troyhunt.com/password-managers-dont-have-to-be-perfect-they-just-have-to-be-better-than-not-having-one/ https://www.troyhunt.com/password-managers-dont-have-to-be-p...
- oldandboring 5y agoInformation security is nearly always about trade-offs and this is no exception. What you give: - a single point of failure (one complex password you memorize that locally unlocks a DB of credentials that is stored encrypted in the cloud). What you get: - all passwords are unique and complex (assuming you use a password generator, which all these tools have built-in) - the convenience of having all your passwords ready for use on any of your devices - the convenience of auto-fill - the convenience of being able to share logins e.g. a spouse or across your organization. - the convenience of being able to also store, share, and auto-fill secrets besides logins (identities, credit cards, free-text notes). Been using a password manager for 15+ years and I have never suffered fallout from the single-point of failure tradeoff, only benefits from the power and convenience I got as a result.
- tiernano 5y agohmmm.... this could make me move from LastPass to 1Password... after krypt.co got bought by Akamai and discontinued work on their developer stuff, i have been looking for a better way of managing SSH keys... this might be it...
- kafrofrite 5y agoI use both, almost daily (paid versions) since ~2015ish. IMHO, 1password is way better than lastpass. That being said, lately 1password has shifted some of their focus towards more enterprise features (secrets etc.) so I don't know for how long my opinion will remain valid :)
- eloisius 5y agoIf you're considering a migration anyway, I recommend you give KeePassXC a try before paying for 1Password. It also serves as an SSH agent. I haven't upgraded 1Password since they became a subscription model, so I'm not sure how it stands now, but KeePassXC was an upgrade for me. The browser integration is more configurable and I have fewer instances of not being able to use the auto-sign in with certain sites. Strongbox on iOS works beautifully with KeePass, and found it to be just as good as the 1Password iOS app too.
- kvnnews 5y agoI would second this. Keepass also has an ssh key agent plug-in which works great. I’d say it’s even better than the putty key agent since you are notified when keys are used.
- tonyedgecombe 5y ago>Set up the 1Password 8 desktop app That will be the Electron version. No thanks.
- ents 5y agoTo me all the new features are worth it. It does not feel as bad as "normal" electron shovelware.
- lucis 5y agoWhy?
- snide 5y agoI don't get the hate on Electron. Is it often bloated? Yes, sure. Has it allowed some of these excellent third party apps to make the move to Linux? Absolutely. I've been utterly surprised and excited by how much better 1Password has gotten over the last two years on Linux. We're seeing real parity with the OSX side of the house. Would I love native apps? Again, sure. But I really don't care. It runs pretty fast on my machine and has never really gotten in the way. Also, they have a nice CLI. I'm sure getting some of these features there is only a matter of time.
- trvr 5y agoI think a lot of the hate (myself included) is coming from the fact that we already had a really good native macOS app. Feels like something is being taken away. I do understand where you are coming from with Linux. It's better than what you had, no doubt. But that doesn't feel like the case to us macOS users.
- dangus 5y agoWhat features/usability/performance was lost with the switch to the Electron app? If the answer is "nothing," then really the argument is purely about aesthetics. I didn't even know it was an Electron app until months after I had installed it.
- rotten 5y agoNext they should add keys for cli tools: psql, mongo, mysql, oci, gcloud, aws ...
- nerdawson 5y agoI’ve been treating SSH keys in the same way I would a password. Each service gets a new key generated for it. From doing some reading though it sounds like I might be wasting my time. Apparently it’s fine to have one key for an individual machine and to use that for everything. What’s everyone else’s take on that? Are you reusing a single key or generating each time?
- geewee 5y agoI'm reusing the same key per machine - but it's mostly just due to convenience and laziness.
- fredley 5y agoA mix. Typically I'll use one key per machine and add those keys in the places they need to be. This is good as you're reasonably well protected if that machine gets lost or stolen. The nature of public key cryptography means there's no risk associated with handing over your public key to many different places. However sometimes it's practical to use the same (private) key in multiple places. I do this for access to low-risk stuff like ssh access to my raspberry pis. I wouldn't ever move a private key around for anything remotely dangerous though.
- bombcar 5y agoThere is a slight risk - if someone has your public key they can setup a MITM server and pretend to be the one you’re expecting - and watch what you’re doing, or redirect test to production or similar. It’s really very minor and ssh itself should warn that the servers fingerprint changed.
- Galanwe 5y agoWell they don't need your public key as well to do that kind of MITM so not sure thats really relevant.
- tempay 5y agoThis shouldn't be possible for any server you've previously connected to. Each machine should have a unique "host key" and OpenSSH prints a very loud message and refuses to connect if it ever changes.
- ReAzem 5y agoNow would it be possible to make something like this for GPG?
- BeefWellington 5y agoA simple wrapper around pass might do the trick. Someone just needs to implement an agent that does this (tho I'm sure someone out there is working on it).
- encryptluks2 5y agoGPG already allows you to authenticate and your SSH key is protected by GPG.
- ghishadow 5y agohttps://www.funtoo.org/Keychain https://www.funtoo.org/Keychain can do both gpg and ssh
- yabones 5y agoAh neat, the app exposes an ssh agent socket: export SSH_AUTH_SOCK=~/.1password/agent.sock So you would essentially replace Keychain, Gnome-keyring, or the vanilla SSH-agent with 1password. Very nice solution.
- api 5y agoDoesn't this give 1Password root on the universe? That's a general theme I see with all this SSO stuff. You have a few companies with root on the universe. Am I weird that this concerns me?
- otabdeveloper4 5y agoNo, you're not.
- sbarre 5y agoThe data that 1Password stores on their end is encrypted with your personal passphrase. So they can't see it even if they want to. Unless their local client was compromised (not impossible - but if your local is compromised you're in trouble regardless), even if someone hacked them and stole their data, they would not have your clear-text info. It's everyone's choice to make but I am personally OK with this security/convenience trade-off.. It's "good enough" for me - mostly because I trust them to know how to do this better than I could - if it means I can manage all my passwords in one place and access them from any device. 1Password also has useful (to me) quality-of-life features like integration with HaveIBeenPwned, it can also show you re-used passwords, and if you store credit cards or other info, it will also tell you when they're about to expire etc.. Plus you can store any arbitrary metadata with any record, so I even use it to store non-sensitive, but still private, info associated with logins, docs, ID, etc..
- api 5y agoI am more concerned with the long term social and political implications of giving a small number of corporations elevated privileges (or the ability to obtain them easily) on everything in the world. If the NSA asked for escrow or root everywhere people would freak out, yet central SSO mostly accomplishes the same thing and people are running toward it because convenience. Of course the same is true for surveillance. Private adtech does things with surveillance that would give people a heart attack if the NSA did it, and unlike the NSA they don't even pretend to be accountable to anyone we can elect. (It's the same because governments can compel corporations under their jurisdiction and there isn't a ton a company can do about it.) While some may find this debatable, I happen to think we just had a rather incompetent but still very concerning fascist coup attempt in the USA. Historically civilizations lose their collective minds periodically. Given that computing infrastructure is becoming the basis for virtually all communication and much of life, is it wise to centralize access control like this? I feel like younger people of virtually all political stripes are just blithely unconcerned with this and assume "it can't happen here" or "that's something that happened back in the early 20th century but not anymore, we have totally solved stable government." I think that's incredibly naive.
- ents 5y agoFor those not buying into 1password, what is the "correct" non-1password way to manage SSH keys?
- Siecje 5y agokeyring?
- irl_ 5y agoSSH keys authenticate you. They are an identity. You probably don't need more than one or two identities (maybe personal and work). You can just get a couple of YubiKeys and configure the OpenPGP applet, or the PIV applet, with an authentication key/certificate and use that for SSH. Take the token with you and you've got some pretty strong authentication. More modern SSH servers will let you use U2F security keys in the same way, which are cheaper than the full YubiKey. I've learned recently that YubiKey has really good documentation for how to set up their tokens to achieve different goals, it would be worth reading their docs if you're considering getting a hardware token for your keys.
- deleted 5y ago[deleted]
- jillesvangurp 5y agoprivate key never leaves the device it is on; public key is .. well public so not something to store in a password manager. If the device is replaced, you create a new ssh key pair or restore your old one from a backup. In case your device is stolen/lost, you revoke access by removing the public key wherever you used it. This too is something a password manager can't do for you. If you are in a cloud environment, you let it manage keys for you. E.g. we don't provision any keys to GCP vms and instead login via a gcloud command that provisions temporary ssh credentials. In short, I see no need for using a password manager for managing ssh keys. The public key is not something that needs protecting. The private key is something that you should not share between multiple devices or generally pass around. But of course being able to paste your public key from some tool is nice if that is a regular thing in your life. And if you switch between multiple key pairs, it's probably nice to have something more user friendly than very fiddly command line tools. I guess the latter is what 1password is trying to solve here.
- trabant00 5y agoMy SSH key and passphrase are the holy of holies security wise. It's such a simple, mature, battle tested, open solution. Why would I put that in a proprietary opaque solution that has had multiple recent serious vulnerabilities? And why would I replace the openssh agent with 1password agent? They don't even offer additional functionality over the open tools. "Autofill public keys in your browser for Git and other cloud platforms" - really? cat and copy - paste is now too hard? (the above logic is why I don't make any serious money)
- turboponyy 5y agocat key | xclip -selection clipboard # is even easier after you alias the second part (edit: or whatever the Wayland equivalent for xclip is)
- zaik 5y agowl-copy < key
- tzs 5y agoEDIT: Never mind. I misread and thought he was talking about password managers in general, not specifically for public keys. > They don't even offer additional functionality over the open tools. "Autofill public keys in your browser for Git and other cloud platforms" - really? cat and copy - paste is now too hard? In the case of browsers cat and copy/paste is often more risky than having code such as a password manager fill the fields. Password managers are less likely to be fooled by sites using tricks with their names to pose as other sites. If you are sufficiently careful to be sure you will not be tricked by phishing attempts then cat and copy/paste should be fine.
- detaro 5y ago... for public keys?
- bvm 5y ago> that has had multiple recent serious vulnerabilities? has it? could you detail them, i'm OOTL.
- irl_ 5y agoIt looks like 2fa is not required for 1password, and also that even if you did enable 2fa you can only use TOTP. Both TOTP and passwords are vulnerable to phishing as there's no cryptographic protocol going on there, you are just typing in the numbers from your phone. This seems like an excellent way to ensure that you reduce the security of your SSH login to either having a single-factor (password) or at best single-factor + TOTP, where you previously had a phishing-resistant cryptographic protocol. Is this really an improvement for security, or is it just a usability improvement (i.e. sync of keys) intended to work around policies trying to improve security (i.e. required use of keys)? (The other option is I skimmed the docs badly and maybe I've misunderstood something, it's possible.) Edit: I did skim the docs badly, it is possible to use a FIDO2/WebAuthN key for 2FA. https://support.1password.com/security-key/ https://support.1password.com/security-key/
- gonehome 5y agoYou can use a Yubikey for 2fa with 1Password
- dhess 5y agoI literally just enabled this 1 hour ago, for unrelated reasons. However, for those reading along, initially the 1Password web interface for my account only offered the choice of setting up a TOTP authenticator. I completed that, and still saw no option for enabling a FIDO/YubiKey device. I then went into the 2FA settings for my account, toggled the option for YubiKey support off and then on again, and returned to the 2FA settings page. Only then did I see the option to enable a YubiKey. I was then able to add my YubiKey and I can confirm that it's working with my 1Password account as a 2FA source.
- irl_ 5y agoOk, I assume that's with FIDO/U2F, so that's not so bad. At that point though, you already have a hardware token capable of holding SSH keys, so I'm still not convinced of the benefit.
- howinteresting 5y ago
- drcongo 5y agoAnd yet we still can't use the keyboard to navigate to the `Generate Password` button like we could in every version of 1Password before the current one.
- terabytest 5y agoI work at 1Password. Could you tell me a little more about this? I tested this in the latest version of 1Password 8 and when I'm creating or editing a password, I see a "Generate Password" button pop up beneath the password field. I can access it by either pressing the down arrow or tab. Does this not work on your end?
- yohannparis 5y ago1Password 8 is not the current version. On 1Password 7 on macOS, when the browser extension offers a "Generated Password" there is no way to configure how it is generated. You have to open the main app to create a new password.
- drcongo 5y agomacOS, 1Password 7, try this: Hit Cmd+Alt+\ and try to tab to the Generate Password button in the top right of that window that pops up. This was possible in earlier 1Password, isn't now. Tabbing moves you between the left pane list of suggestions etc. and the right pane. If there's something in the right pane, you can arrow through them, there's no way to get to the Generate Password button without taking your hands off the keyboard. Additionally, now when I do generate a password, it saves that password in my shared vault for all the world to see instead of defaulting to a private vault where only I can see it. It doesn't appear to be possible to tell it where to save that password until it becomes a login, but by that point 1Password has already leaked the password I just generated. That seems like a really terrible default, and the only way I've found around this so far is to try to remember to open the main app, go into my shared vault and delete the password that I never wanted saved in there in the first place.
- drcongo 5y ago
- leathersoft 5y agoThis is super neat!!!
- pletnes 5y agoMy public ssh keys go quite a few places. I hope this can help me keep track of where I’ve uploaded my pubkey, since then revoking the pubkey is much more efficient. Or even do it for me, automagically.
- bvm 5y agoIf anyone from 1Password is reading this: Can we use it on WSL?
- ShakataGaNai 5y agoYes this. Docs on how to use this with Windows Subsystem for Linux would be awesome. I only do SSH on Windows under WSL.
- adventureadmin 5y agoHow does it work with with `~/.ssh/config`? Mainly, say I have keys in the vault for many machines, if they all get added to the 1password ssh-agent sock, won't you get "Too Many Auth failures", unless there is a way to pair the key to a `Host`? Maybe `~/.ssh/config` can pair keys to a `Host` by fingerprint instead of file?
- zrail 5y agoThe documentation covers that. tl;dr: you can pin public keys to hosts https://developer.1password.com/docs/ssh/agent/advanced#ssh-server-six-key-limit https://developer.1password.com/docs/ssh/agent/advanced#ssh-...
- adventureadmin 5y agoAhh, well that's still an improvement, but it would be nice to not have to download anything.
- petepete 5y agoI use a Keybase encrypted git repo called secrets, it contains my ssh keys, config, pgpass and a few other files. I use stow to install them on a computer when I'm setting one up. Haven't run into any problems with this approach, my Keybase is protected with a Yubikey.
- kitsunesoba 5y agoSince krypto.co use case of SSH key handling fell to the wayside, I recently switched my keys over to Secretive[0], which stores keys in your Mac’s Secure Enclave or YubiKey and the case of the former, uses Touch ID to authorize use of your key. It’s very simple and works very well. Better than krypt.co did for me, actually — krypt.co would occasionally randomly break, but Secretive has been rock solid. Every time something tries to use your key you get a Touch ID prompt and a notification indicating what triggered it. This 1Password feature looks nice, but I’m switching away when version 7 stops working. AgileBits just isn’t taking 1Password in a direction that’s appealing for me… they’re clearly more interested in corporate users than individuals, and in the pursuit of a one-size-fits-all-platforms UI they’re losing the attention to detail and polish that used to be a major selling point. [0]: https://github.com/maxgoedjen/secretive https://github.com/maxgoedjen/secretive
- judge2020 5y agoKrypt pretty much works all the time for me, with the main reason I still use it being that WSL can't use the host OS's ssh-agent for logging in without aliasing ssh to ssh.exe. That and the Windows ssh agent itself can't use native Windows Hello APIs[0] to have an experience similar to secretive on Mac where the keys never leave the device and are protected by the secure processor in the device. 0: https://github.com/PowerShell/Win32-OpenSSH/issues/1804#issuecomment-850500721 https://github.com/PowerShell/Win32-OpenSSH/issues/1804#issu...
- majkinetor 5y agoSemi related, PRemoteM will maybe have in future Windows Hello: https://github.com/VShawn/PRemoteM/issues/181 https://github.com/VShawn/PRemoteM/issues/181
- tempay 5y agoI'm quite excited about this as a potential way to avoid the problems that once a key is added to an agent any process can then use it. It looks like this prompts for permission for each process that wants to use the key, but then doesn't prompt again.[1] I've tried using various tools for this but they've always been too clunky. YubiKeys work well with their requirement to be physically touched, except you continuously have to press them when using git commands (multiple times if fetching many remotes). I haven't been able to see anything about how this handles agent forwarding over SSH. Does anyone know? [1] https://developer.1password.com/docs/ssh/agent/security https://developer.1password.com/docs/ssh/agent/security
- rcarmo 5y agoI'd rather use Secretive (https://github.com/maxgoedjen/secretive https://github.com/maxgoedjen/secretive), to be honest. I've stopped using 1Password everywhere I can due to their product "focus", and am working my way through a set of alternatives (currently using Secrets on the Mac and looking at the KeePass ecosystem, which keeps improving monthly): https://taoofmac.com/space/apps/1password https://taoofmac.com/space/apps/1password Edit: It's been fun watching this get upvoted and downvoted in successive waves - for those who are curious, I suggest you check previous posts on 1Password and see if you can spot patterns in their advocates, since they were publicly called out on this a few times already (especially on Twitter).
- Ocha 5y agoI agree. They disabled 1Password for Firefox on iOS and force users to use safari with 1Password extension. Before you could access it through share menu and get forms filled out, but they removed that feature. Reached out to support regarding that and their answer was just to use safari.
- anubiskhan 5y agoIs that Firefox specific? I am still able to use 1password with Brave on ios 15.3.1 (iphone 12 mini)
- Yeri 5y agoI use Firefox on iOS with 1password (to fill in passwords) just fine.
- harlanlewis 5y agoI use 1Password on Firefox in iOS without an extension, just use the keyboard suggestion when a password field is focused as in Safari or other apps.
- reubenmorais 5y agoIt still works for me on Firefox, latest iOS.
- nilstycho 5y agoIt appears you need to have Beta 8.6 to use this. I was on Beta 8.5 on macOS, and autoupdate did not find Beta 8.6. After installing 8.6 manually, the instructions worked.
- egberts1 5y agoUmmm, no. No need for even more in-between software prompting for passwords. I’m sticking with certificate+publickey SSH
- judge2020 5y agoThe point behind all ssh-agents is to prevent any application with access to ~ being able to read your ssh key and exfiltrate it somewhere, or simply using it to drop malware on hosts listed in your ~/.bash_history. If it's in an agent and that agent requires user interaction before it performs SSH logins, you'll be made aware of the malicious activity.
- egberts1 5y agoAnd I keep my SSH agents entirely down and disabled too for many security reason. Stick with the publickey and more so the SK certificates. Each leg of the SSH hops should have their own set of SK certificates with their own distinctive SSH options.
- DonHopkins 5y agoA huge problematic deficiency of 1Password is that it lacks literal multi-line text field types. The items in its database let you define custom fields for them, but there is no literal multi line text field. There's a "File" type, but you can't simply define fields with multi-line text values. However, every item has exactly one built-in "notes" field, but that's actually styled markdown text. And you only get one. And its name is always "notes". It would obviously be extremely useful to be able to define an arbitrary number of arbitrarily labeled multi line text fields that are not interpreted as markdown text. It boggles my mind that 1Password doesn't support this. What were they thinking??? It makes it a real pain in the butt to store ssh keys and certificates and a lot of other types of information in 1Password. A single markdown "notes" field just doesn't cut it. It's not as if it's technically challenging or a security risk. It already has a "notes" field, so just turn off the "rich text" feature and allow me to make my own! I would have thought it was a pretty obvious and often requested feature, but as far as I can tell, it's impossible!
- varenc 5y agoAs one datapoint: I’ve used 1P for 11+ years, have over 1200 items in it, and I’ve literally never lamented the lack of multiline fields.
- rco8786 5y agoSimilar here. I've never even considered it something I might want
- tksb 5y agoWhile I agree about the specific ask for multiline support (and the decade plus hourly usage of 1p), it's abundantly clear that things are slipping with regards to the core product. For awhile there were no public links to any downloadable desktop apps for macOS while they pushed web + subs + and the MAS version. These days I'm just delighted when 1password doesn't open a totally different browser when invoked from the active one.
- CodeRhoades 5y ago
- ossusermivami 5y agoI'd love to get that SSH feature in bitwarden,
- eik3_de 5y agoI stopped using SSH keys to authenticate against GitHub years ago and switched to HTTPS authentication. It's super convenient to set up with the GitHub CLI: https://cli.github.com/manual/ https://cli.github.com/manual/ Is there any advantage of using SSH keys to authenticate against GitHub?
- otabdeveloper4 5y agoYes. SSH keys work literally everywhere and not just for Github.
- RubberShoes 5y agoI have used 1pass for years. I think I bought my lifetime license sometime in 2014? I loved it and even advocated for our 2000+ company to adopt it back in 2018. I would say in the past 2-3 years it has slowly become an absolute nightmare. I do not recommend it to anyone anymore. They have somehow screwed up the very basic functionality of filling in passwords on any browser I try. They continue to shift features around, break existing workflows, and even the basic tasks I rely on dozens of times a day seems to change with any significant release. 1Password got famous for building a great core product. It managed my logins I stored myself and autofilled them wherever I needed. It was clean and simple. Now they are so focused on growth and Product features like this that they have completely lost their way. As of this week I can no longer right click on a webpage and work with 1pass to find something. If the webpage attached to the original 'save login' prompt is not the one you are on - the auto popup underneath the login field has nothing to show and I cannot manually find and enter it. I have to go to the Desktop app, search, find, and copy. My team regularly wastes minutes on this each day. Our company reevaluates platforms every couple years, in the next 12-24 months I will strongly advocate we find an alternative.
- rco8786 5y ago> They have somehow screwed up the very basic functionality of filling in passwords on any browser I try UGH YES. When I started using 1P (2015ish?) it was simple and reliable, and I feel like I fight it more than I use it these days.
- chrisan 5y ago> They have somehow screwed up the very basic functionality of filling in passwords on any browser I try What browser/sites are you having issues with? I've only been using 1Password since the Lastpass changes last year or 2 (I forget) but havent run into a site I can't autofil. I actually found it works in places Lastpass used to let me down such as CapitalOne
- RubberShoes 5y agoChrome for work, Firefox for personal. Both macOS and Windows 10. I am in contact with 1pass on Twitter, followed their recommendation to turn off the legacy extensions Desktop App Required and it is still broken.
- vngzs 5y agoI think this is a bad idea for users. I don't think SSH keys are things you should share across machines in a password manager. If you have two devices, then you should have two keys (though this is the subject of some debate; see [0]). Using the 1Password SSH agent encourages people to have "one" SSH key across devices, which means that any leaks will disproportionately impact them. It's unfortunate, because there is some real innovation around the per-application usage permissions: > 1Password will ask for your consent before an SSH client can use your SSH key. Because of this, there's no concept of adding or removing keys like with the OpenSSH agent. If an organization wishes to solve the SSH pubkey distribution problem (the main reason one would copy a private key across machines), then they should use SSH certificate authorities like [1]. In fact, I think that would be a far more interesting 1Password product—HashiCorp Vault could use some competition for this kind of use-case. [0]: https://security.stackexchange.com/a/40061 https://security.stackexchange.com/a/40061 [1]: https://www.vaultproject.io/docs/secrets/ssh/signed-ssh-certificates https://www.vaultproject.io/docs/secrets/ssh/signed-ssh-cert...
- rickosborne 5y ago> I don't think SSH keys are things you should share across machines in a password manager. While I agree with the first half of your statement (don't share SSH keys), I cannot agree with the second (don't put SSH keys in a password manager). For my home use of 1Password, I absolutely want to keep backups of my SSH keys in 1Password. Because, in general, there's exactly 1 SSH key which can get into my cloud instances, and I've had enough laptops die suddenly that I'm not willing to risk getting locked out by not having a backup. You could say "well, just have a second device with backup keys" but again for home use, why would I buy another laptop just for that? Or maybe just "well keep an offline backup of your keys". Sure. In 1Password. Where I keep pretty much all of my sensitive credentials and info. > Using the 1Password SSH agent encourages people to have "one" SSH key across devices, which means that any leaks will disproportionately impact them. Eh. IMO, people who are inclined to use 1 key across machines are going to do it, no matter the process. I doubt this feature is going to make that any worse. But I guess we shall see.
- vngzs 5y ago
- minimaul 5y agoThis is 1Password 8 dependent, so unfortunately I doubt I'll ever use it. The 1Password 7 app on macOS is a beautiful native app. It "fits" in macOS, it follows macOS design paradigms. 1Password 8 does not. It is a weird self-designed UI toolkit that is well inside the uncanny valley scenario - it is a UI design that feels like it is trying to approximate all of the major platform desktop UIs without committing to actually feeling like any given platform - so it feels wrong everywhere. Honestly it would be better if it was totally different to any of the main platforms instead of vaguely approximating them. I don't care what devtools or toolkits they use to achieve what they do, I care about the end UI feel, and it's just awkward on all platforms to me. Additionally, 1Password 8 removes the single most used feature for me - 1Password Mini - and replaces it with Quick Access. Quick Access is much more awkward to use, especially with a mouse. Everything with Quick Access involves more UI interactions than it was before. The reasoning for this is that it "feels weird" to implement parts of the app twice - but for me 1Password Mini is essentially a browser extension equivalent for every other app on your system. Quick Access is an awful replacement for that. I really prefer 1Password 7 on macOS to 1Password 8, and I honestly prefer it on Windows too. The replacement of native apps with something that really feels like a web page in a window - with issues like context menus being stuck inside the window, or web-page style modals - is just not what I expected, and it's not what I want. Yes, it lets AgileBits bring updates to platforms more quickly because it's essentially the same backend & UI on every platform. However, as an individual user I don't need more from my password manager than 1P7 already does. Sadly, it seems the target for AgileBits (especially with the influx of VC cash) from the outside at least is just growth and the big payouts that come from enterprise deals - individual user usecases don't matter any more. Just look at how much of a production they made out of restoring categories as an option to the sidebar. And their core featureset - form filling - is less reliable than ever for me. I feel that there's absolutely a hole in the market here for a password manager product aimed at individuals or small families that works on at least macOS, Windows, iOS and Android - and feels native on each platform. edit: oh, and I utterly abhor the 1Password PR style - trying to make things seem weirdly casual on serious topics, but especially the misdirection/redirection approach they always take to critiques or support queries. Just look at their support forums for any thread on purchasing standalone licenses - they always drive the discussion into "isn't our online product amazing?". Critique of features in 1P8 always becomes "but for me it's amazing" in some way. It's frustrating as hell to engage with as they never seem to actually accept criticism in any way without trying to redirect it to something somehow positive.
- vimota 5y agoI've been a huge fan of 1Password for almost ten years now, recommending it to friends and family, but like some of the comments mentioned it feels like the product is trying to move upmarket while dropping support for core features. I've bought their license a couple times as the versions are updated, but they no longer support licenses and only monthly subscriptions. Fine.. I'm happy to pay that to get a great product, but as I was installing it on my new laptop they prompted me to move from my self-managed cloud sync to their hosted password management saying the cloud-sync will no longer be supported. I simply don't want to use the hosted solution, I'm not comfortable with the trust implied. I imagine they're trying to cut down on the features that allowed someone to use it without paying a membership, but then why not just include cloud-sync in your paid features? Why remove a such a core feature that allows users to use your security product much more trustlessly?
- andycreeth 5y agoI definitely understand the aversion to trusting 1password's cloud service, but it's worth noting that their security model is such that it requires minimal/zero trust of the server. Your vault is only ever decrypted on the client side, and the 1password service only ever stores/syncs the encrypted vault. This is why if you lose access to your secret key, your vault can never be decrypted, even by 1password - your secret key is only ever stored on your local device and never by 1password, not even a hash of it. 1password has a great white-paper on their security model if you're interested, and it's verified by 3rd party auditors.
- vimota 5y agoOh I get that, and agree! But despite that it still feels like a honeypot, centralizing every user's most important security info in one cloud service (read: honeypot). At least with Dropbox/iCloud sync you're relying on the same e2e encrypted setup but in a less centralized service (for example, if there's some bug in the e2e encryption someone would need to take advantage of that AND iCloud's encryption and target users using the combination).
- WhyNotHugo 5y ago
- YATA0 5y agoAnd here I am, logging into Linux boxes without entering passwords nor SSH keys thanks to the magic known as Kerberos. Open up my corporate laptop and login with my smart card and username/pass combo, then I can just log into any Linux machine I have authorization (group permissions) to. Been doing it this way for over a decade at this rate. It's like all of these password manager tools were created by people who've never seen nor used these existing solutions.
- tristor 5y ago> It's like all of these password manager tools were created by people who've never seen nor used these existing solutions. Maybe, but it sounds like your comment was written from a place where you've never had to actually implement one of those existing solutions. Kerberos is great. It's also a holy terror to implement properly, especially cross-platform, and especially if you need to federate identity. I've been down that path. While there are trade-offs with any decision, I wholly understand why so many organizations are going to solutions like Okta/Auth0 + Duo + password managers vs the "tried and true" methods of a directory server + Kerberos + SAML federation through Shibboleth SCIM combined with modern cloud SSO makes life much easier than trying to support Kerberos.
- YATA0 5y ago>Maybe, but it sounds like your comment was written from a place where you've never had to actually implement one of those existing solutions. I absolutely have implemented the aforementioned solution. Used to be a right of passage for middling UNIX syaadmins. >Kerberos is great. It's also a holy terror to implement properly, especially cross-platform, and especially if you need to federate identity. Not really, especially not really if you Active Directory. >SCIM combined with modern cloud SSO makes life much easier than trying to support Kerberos. SCIM with Active Directory (AKA Kerberos) works well.
- KyeRussell 5y agoLol. Kerberos? Smart cards!? What if I have less than a full team of full time employees able to be put aside to implement a solution? I, as a developer, could integrate 1Password’s solution in my org in an afternoon. Enterprise tooling isn’t for everybody. That approach is what gave us the needless proliferation of Kubernetes.
- up6w6 5y agoFor Bitwarden users, let's support the idea in the forum! https://community.bitwarden.com/t/implement-ssh-agent-protocol/833 https://community.bitwarden.com/t/implement-ssh-agent-protoc...
- _ktx2 5y agoI've been using 1Password for years now, the auto-fill always works. I don't use their command line stuff much, and I have some read some legitimate criticisms about how they communicate secrets on unix-like systems. Apart from that, I'm not sure I understand the dissatisfaction in the comments. Can someone enumerate what's wrong with 1Password? Are tools like BitWarden any better?
- bluehatbrit 5y agoI think the majority of it is down to the pre-SaaS customers of the product. 1Password used to have a life time license and would work without any need for 1Password servers. You could backup your vaults anyway you wanted and the various clients would work with a variety of methods for syncing etc. A lot of long term 1Password users bought this and still use it, but the company no longer really do much to support it having pivoted to completely focus on their subscription offering. Many of their long time customers, many of which are HN users, feel they're getting shafted by the lack of updates etc to those older offerings. From what I understand a lot of the older clients and plugins that worked with the local versions don't get updated anymore. However, I'm only a customer of their subscription offering so someone else might be able to elaborate more.
- kodah 5y agoAh, that makes sense honestly. I bought their lifetime license and I'm a subscription user. Kinda sounds like the right thing to do is refund the lifetime license holders if they've changed architecture and direction that drastically.
- bluehatbrit 5y agoThat would probably be the consumer friendly approach, or at least some kind of life time discount on the subscription platform. At the same time, a perpetual license is typically for the version you buy and that's it (old Adobe or MS Office approach) so I can see the argument for "you got it, and can still use it". As someone who moved from LastPass to 1Password (after they aged off the lifetime license) though I'm happy and given their growth I'd imagine most of their customers are happy enough with it.
- RegnisGnaw 5y agoQuestion: if I have this on Windows (1Password for Windows), is it possible to do this via WSL?
- fire 5y agoAhh, this is such a nice improvement over literally anything i've used for agent key management on Windows or Linux, and easily competes with using the Keychain integration available on OSX; It sucks that I can't really use the functionality due to the v8 requirement, and am once again in the position of paying for something where I don't get to actually use new and useful features due to really aggressive ( if not outright anti-user ) product direction. For some context on my bitterness: v6 stopped working with chrome based browsers a few years ago due to an issue with browser signatures, and the official guidance was to ( pay to ) upgrade to v7 rather than fixing the app, and so the software I had paid for was no longer usable in the way that it was when I purchased a license for it, effectively being downgraded through no fault of the end user ; Similarly, the Windows variant of 1pw has... kind of always just been a bad experience compared to the mac version, and while the controversial Electron-based unification for v8 promised to bring the experience in line with the Mac app ( not requiring purchase of another license type this time because I'd since bitten the bullet and paid for a subscription so I could actually use v7 ), it also required migration to the hosted vault system, as support for local vaults was completely dropped in the same version. I would feel a lot more comfortable using this otherwise legitimately fantastic functionality if it didn't also require me to migrate from a local vault to the hosted version. I already didn't want my passwords hosted online; I definitely don't want my ssh agent and its private keys to be bound to said hosted service, and nothing has yet come out of 1Password's survey for self hosting the vault server in order to maintain a vault that works with 1PW 8 locally. It's an unfortunate hill to die on, I realize; I just want to maintain control of my own stuff, using a tool that is actually nice to use ( 1Password is and has always been miles ahead of everything else in terms of the day to day user experience, otherwise I'd be able to justify looking at alternatives )
- nerdite 5y agoI’m not sure your critique of v6 to v7 migration is fair. Im sure v6 continued to work fine on that old version of chrome. But it seems perfectly reasonable for developers to be compensated for writing new code to work with new versions with new requirements. I also feel I should be realistic about the incentive structure. I want 1password to continually work on security, additional features, and quality of life stuff. That requires steady income. As to your local vault concerns. I think you have a really valid point.
- rage8885 5y agoI just wish they would implement the ability to disable 1Password for certain domains or even just local host (talking about the browser extension here). There is a menu option in the right click menu but it only works for a short duration and isn’t configurable ahead of time.
- mike503 5y agoTypo on the page: “Learn how to configure the 1Passwrd SSH agent”