5 ms·
It's beyond me why anyone would willingly choose a service like this when perfectly good (and free + open-source) services like KeePassXC and pass exist. Maybe
by eshack94 3y ago
It's beyond me why anyone would willingly choose a service like this when perfectly good (and free + open-source) services like KeePassXC and pass exist. Maybe in the corporate space, but I can't understand why an individual would choose to outsource their personal security to a for-profit corporation. Seems like this just introduces additional risk by outsourcing such an important function to a third party outside of your control.
- dcsommer 3y agoConvenience, of course. Secondarily, lack of awareness of alternatives.
- eshack94 3y agoThis seems accurate. I forget how much people value convenience
- dangus 3y agoI can explain why. I migrated from KeePass to 1Password. The short version of the story is that I used a mess of tooling to get a KeePass-based workflow going, and it resulted in data loss that I had to recover. I stored my database on a cloud storage provider, and then I would read that database with various clients on my various platforms. At that time, just about none of the (good) clients were cross-platform (KeePassXC that you brought up has no mobile apps). At that time, an open-source Mac client had a bug that caused some extra fields to be cleared/not saved. I put some important information in those notes and they were lost due to this one client being buggy. Luckily, my cloud provider kept a backup of previous database files. That's when I realized that having someone else manage all this was way better than saving a few bucks. I've used 1Password through a lot of new version changes and complete rewrites and I can't recommend it enough. It integrates deeply with all my devices, supports the latest developer frameworks on those devices (e.g., delivering a Safari for iOS extension as soon as extensions were added to iOS), and it's packed full of features that I never dreamed of having with KeePass. This optional opt-in telemetry seems way more reasonable and respectful than comparable SaaS services and commercial applications, but, alas, "telemetry" is a boogie-man word. Maybe that KeePass app that dropped my data could have used some telemetry to spot that error a bit faster.
- kitsunesoba 3y agoI've never used KeePass myself but for a few years it seemed like situation with Mac clients was something of a rotating door, with the client or fork that was most up to date changing constantly… seemed pretty easy to lose track of, with is not great for something where staying up to date is important.
- arbus5672 3y agoMy concern with this move isn't that "telemetry" is a boogie-man word but that it is a slippery slope that we have seen far too many companies slide down on. The progression seems to be: No telemetry -> Opt-in telemetry -> Opt-out telemetry -> Always on telemetry -> Yeah we sell whatever data you give to us to the highest bidder, what are you going to do about it? Speaking as someone who has this deployed at work and would be loathe to go through the trouble of having to swap this out, we need to send them a strong enough message at this stage so that they stop experimenting with this further.
- dangus 3y agoThe thing is, in real life, slippery slopes don't go on forever. They stop at some point. 1Password isn't going to sell data for completely morally neutral business reasons. They would get peanuts compared to the up to $8/month they get from each user in exchange for a legal, compliance, and security nightmare resulting in a bunch of lost customers. It's most likely that they just want to make it easier to develop the product. That's where the slope ends.
- arbus5672 3y agoAgilebits at the end of the day is a company and it does things for financial reasons. Us, from the outside looking in, trying to assign a moral value to those actions won’t make sense. They will go down that slope until going lower won’t make them any more money. Any money that they make from the sale of data will be profit on top of the 8/mo that they are currently getting. If there are enough users, getting the legal and compliance stuff sorted might be worth it since that would be a one-off cost to create a whole new revenue stream. Again, just making the case as to why they could do it, not why they should or will do it.
- chrismcb 3y agoI think everyone outsources their personal security to for profit companies. It do you build your own locks for your doors?
- serf 3y ago> do you build your own locks for your doors? writing down passwords isn't equivalent to owning a machine shop and having the skilled labor required to facilitate manufacture of a door lock, regardless of how hard the companies that profit from selling these kind of services tell you it might be.
- AwaAwa 3y agoWasn't there a recent incident of amazon locking someone out of their house because of misheard information?
- CatWChainsaw 3y agoAn Amazon delivery driver thought that the automated message of the doorbell-cam (I'm honestly not sure if it was ring) said something racist, or in a rude tone and construed it as racist, reported the "interaction, and algorithms algorithm'd.
- mfru 3y agothe biggest thing for me is convenience and that is why i am using bitwarden and not keepassxc or pass at the moment. but i am constantly tinkering on my workflow and pass seems to be really cool so who knows when i switch again!