The Mac client is very nice to use. The Windows client works well but isn't as nice looking. The browser extension is awesome- AND you can put MFA keys in there as well.
EDIT: And I forgot to mention the main reason I chose 1Password so long ago. Their iOS app is awesome and their mobile Safari integration works quite well.
It would be very nice if they did support Linux and people have been asking for it, but there is a passable workaround- and frankly one I'm willing to work with because it works so great everywhere else.
When I tried it out I wanted 1password family so I could share some accounts with my partner. 1password 4 doesn't support their cloud datastore; the version that does will not run on Wine.
However, I could use the webapp on linux. It was a bit annoying but I could have dealt with it. The other complaint I had was the UX for Android. Having to switch my keyboard every time I wanted to enter a password was very annoying. Hopefully that gets better with the recently announced Autofill API for Android O.
1. Giving code running in your browser access to your password database carries some risks. Browsers have a massive attack surface. 2. Autofill extensions use heuristics to map secrets to forms, and sometimes put secrets into fields they shouldn't. 3. Autofill extensions cause your browser to prompt for your master passphrase. Other extensions may be able to emulate this behavior or otherwise intercept your passphrase.
Anyone who isn't using a password manager should do so. A password manager with autofill is a huge step forward from nothing. But disabling autofill offers some further benefit.
1Password's extension does not prompt for my master passphrase, I have to click on it to enter it (if I haven't already). It also to don't try to fill forms on page load, I have to instruct it to do so. By default it will usually submit a form upon fill but I often turn off that setting.
As for browser vulnerabilities, I'm not familiar with any information about extensions being particularly vulnerable to browser exploits, it seems like when browsers get "pwned," anything in userland (if not the whole system) is up for grabs so avoiding the password manager's browser extension doesn't gain you anything. I'm not saying there's no risk, just that trade-off is worth it. Agilebits argues that using the extension is safer because it avoids keystroke loggers and clipboard sniffers [0]
[0] https://blog.agilebits.com/2014/08/21/watch-what-you-type-1p...
LastPass also unfortunately has in-pane banner pop-ups which I do not trust at all. Blind and automatic autofill is dangerous. I'm not sure if you can enable that.
Another feature I like is the detection of compromised sites and password rotation reminders.
Now imagine you stepped away from your machine while still logged in.
Autofill is convenient, but there are negative consequences.
The issue with 1Password is that it's not accessible in Linux and no U2F (yubikey etc) support AFAIK...
[1] https://trezor.io/passwords/ [2] https://blog.trezor.io/satoshilabs-launches-trezor-password-...
same with things like yubikey
It seems like it would be better to just fake a keyboard output instead? then you could have something that could work on all platforms in all situations
Hardware faking of the keyboard would work fine though
Its not great and it crashes some, but it does work.
Passforios is being actively developed and is shaping up well.
PasswordSafe's safe is an open source file structure and thus there are many different ways to access it with different features for each. I have PasswordSafe on both my Windows PC and android phone and I'm using PasswordSafe professionally for my organization's passwords and found that there are reliable Mac options so those with Macs can access the safe.