4 ms·
[I work for AgileBits, makers of 1Password] Thanks for the feedback! Filling into sites and gathering the necessary information for this I think is far easier
by AGKyle 12y ago
[I work for AgileBits, makers of 1Password]
Thanks for the feedback!
Filling into sites and gathering the necessary information for this I think is far easier than determining how a password change takes place. We have an algorithm that we've developed over years that is constantly changing in subtle (and not so subtle) ways to make filling more accurate. Some of the biggest changes in a long time will be coming in the 4.2 version of the browser extension, currently in beta.
But you're right, sites and their password change processes differ greatly. Some require the old password, some require only the new password. Some only require the new password once (admittedly rare).
I think at best though we'd only be able to do this if we went to the password change page for the site and attempted to fill the data in for changing the password. There's no way we could bulk update as that would probably require we hard code each individual site rather than relying on an algorithm for filling data into the site.
It's a tricky thing, but we're always trying to come up with new ideas and ways to accomplish those ideas.
Heartbleed was the first use case for Watchtower, but you're correct in that it'll be available for other situations as well. Now that the foundation is there we can leverage it for other issues in the future.
Thanks again for the wonderful feedback!
Kyle
AgileBits
- masklinn 12y ago> Filling into sites and gathering the necessary information for this I think is far easier than determining how a password change takes place. Maybe start talking it out with browser developers and big websites stuff so there's a way to standardise an endpoint or in-page meta-information allowing for automated password reset?
- ColinDabritz 12y agoThis could be a real win. If there was a way of marking a standardized form with some meta data or tags to say "hey, this is safe to use automatically in the expected way" such as the typical form with old > new > repeat new or something. One little HTML change and it advertises compatibility. That way, classy sites could enable a 'safe enough/good enough' flag that any software could use. There is also the thought that it may be worth hard-coding for the biggest sites. The high profile sites are the most vulnerable when a vulnerability hits, there are big existing databases of user names around, and these can be exploited automatically and quickly on relatively high value targets (gmail accounts, amazon, facebook, twitter etc). Even top 10 would be helpful, but top 100 seems approachable, especially since the bigger sites are probably more consistent. The payoff here could be big next time around. Also if the framework were around for doing this, you could target a particular site or three that just had a major breech, and push the rules for reset out with the breech notification. I know it's a huge amount of work to do manually, but even a relatively focused effort could have payoffs, and if working with big sites can start a 'automated password reset' standard rolling, others might adopt it. Just thinking out loud, I know you've got to juggle priorities and features with limited time. Thanks again!
- threatofrain 12y agoAre you guys ever thinking of a Linux version :(
- AGKyle 12y agoThinking about it? Sure. We've had a lot of requests for it. It's a pretty big job to write a whole new version of the application. It's also a big question of whether we'd sell enough copies to maintain it. Traditionally Linux users haven't been big on purchasing software, particularly closed source software. I'm not sure how much this has changed, if anyone has some real solid stats on it I would love to see it. I was once a Linux user (started on Redhat 4, but fell in love with Debian) so I know what the past was like, but have been out of the Linux world for long enough to be unable to know how things have changed in this regard. Either way though, I don't have any pull on this, but I can pass the request along. I think we (AgileBits) would all love to see 1Password on more platforms. It's just a bit of a careful process to go through. We hear the requests for Linux loud and clear. If it's something you want, please let us know. Include any thoughts for how you'd use it and what you envision it being. It's far easier to take to the powers that be ideas and thoughts than just requests. Now though, the fun part is that the current Windows beta (version 4) will work in WINE and I do hear from users that the browser extensions will also function using the beta. Obviously this isn't an ideal solution but it might hold you over well enough. If you'd like to try the beta, you're welcome to sign up here: https://agilebits.com/beta_signups/winnewsletter.html https://agilebits.com/beta_signups/winnewsletter.html Let me know if that helps! Kyle AgileBits
- kolev 12y agoWell, maybe you should try a Kickstarter campaign and see how it goes... I'm sure you have to invest a bit to create a video and all, but I'm sure it will be a successful campaign.
- threatofrain 12y agoI'm afraid I don't actually know any numbers on Linux users' willingness to buy software, but I am aware of the reputation that Linux users generally prefer their ecosystem of free apps. However, I bet that many Linux users are also Windows or OSX users, and if a password manager is to be effective, it has to be omnipresent. That's why I have begrudgingly paid for LastPass, while my dual Windows / OSX license for 1Password 4 has sat unused. I tried for awhile, but I couldn't stand the gap in coverage. So I narrowed it down to RoboForm and LastPass, and I chose the latter because it seemed more popular and I hoped that to predict company longevity. Because as nice as lifetime licenses are, once software is no longer supported, esp. for things like intelligent form-filling, chances are you won't want to use your software anymore.