4 ms·
I've been a huge fan of 1Password for almost ten years now, recommending it to friends and family, but like some of the comments mentioned it feels like the pro
by vimota 5y ago
I've been a huge fan of 1Password for almost ten years now, recommending it to friends and family, but like some of the comments mentioned it feels like the product is trying to move upmarket while dropping support for core features.
I've bought their license a couple times as the versions are updated, but they no longer support licenses and only monthly subscriptions. Fine.. I'm happy to pay that to get a great product, but as I was installing it on my new laptop they prompted me to move from my self-managed cloud sync to their hosted password management saying the cloud-sync will no longer be supported. I simply don't want to use the hosted solution, I'm not comfortable with the trust implied.
I imagine they're trying to cut down on the features that allowed someone to use it without paying a membership, but then why not just include cloud-sync in your paid features? Why remove a such a core feature that allows users to use your security product much more trustlessly?
- andycreeth 5y agoI definitely understand the aversion to trusting 1password's cloud service, but it's worth noting that their security model is such that it requires minimal/zero trust of the server. Your vault is only ever decrypted on the client side, and the 1password service only ever stores/syncs the encrypted vault. This is why if you lose access to your secret key, your vault can never be decrypted, even by 1password - your secret key is only ever stored on your local device and never by 1password, not even a hash of it. 1password has a great white-paper on their security model if you're interested, and it's verified by 3rd party auditors.
- vimota 5y agoOh I get that, and agree! But despite that it still feels like a honeypot, centralizing every user's most important security info in one cloud service (read: honeypot). At least with Dropbox/iCloud sync you're relying on the same e2e encrypted setup but in a less centralized service (for example, if there's some bug in the e2e encryption someone would need to take advantage of that AND iCloud's encryption and target users using the combination).
- WhyNotHugo 5y ago> I definitely understand the aversion to trusting 1password's cloud service, but it's worth noting that their security model is such that it requires minimal/zero trust of the server. It just requires absolute blind trust on their client apps... > Your vault is only ever decrypted on the client side Which is a closed source blob, so, again, requires absolute blind trust.
- andycreeth 5y agoYup completely valid. In the context of the original post I was replying to, trust of the closed source client code was always required and that hasn't changed, so it didn't feel relevant to mention. I agree with you that there is significant merit in choosing an open source solution for passwords/secrets management.