1Password moving from local storage to cloud subscription
motherboard.vice.com
motherboard.vice.com
I can't put all of my secrets in a file, encrypt it with software a site provides, let that site push updates to me for that software, and then give that site the resultant encrypted file to sync. It's not quite as bad as a pure web based password manager with JS crypto, and better still than a web based SSL transport-sec-only password manager, but still unacceptable.
Apple could still single-party screw me, but they're huge, and if they did this in even one documented case they would probably lose $100B in market cap, and Tim Cook has shown he will push back when ordered to do stuff like this.
2) Until recently, the direction they were moving in was good, even if their current position wasn't ideal.
3) It isn't so much that I think they could be malicious as that I don't trust them to have enough internal controls against external compulsion or an employee with prod access getting hacked.
There are some passwords I don't put into 1Password (PGP, etc), and I try to avoid having passwords-only as auth credentials for anything important. So it is more I would have hundreds or thousands of low to medium security site passwords at risk, which in aggregate would be a huge inconvenience. That is more because I don't have huge faith in the local OS security on machines than 1P as a particular risk vector.
For them, the risk of their un-backed-up computers crashing and them losing all their passwords is higher than the risk of the cloud storage being cracked. They already trust Agile Bit's security since that company writes 1password and hardens it against local attack.
Now, ymMv, but I suspect for 99% of users this is the right thing.
I was one of many to complain about their new Windows app when they started only supporting local vaults read-only. They assured me they wouldn't be forcing users off to the hosted version, but that's essentially what they're doing for anyone using the Windows version.
For what it's worth, the hosted version is nice - particularly for non-technical users - but not sure it's worth the monthly fee when I can use open source alternatives like KeePass with few trade-offs and also not sure it's worth supporting a company who is forcing the move to a recurring subscription despite the negative feedback from some of it's oldest supporters.
So, trusting the team behind 1Password's security, is there anything wrong with this beyond now there is a subscription rather than a one time fee, or is this just Vice's normal MO of being edgy, and taking a relatively insignificant controversy and making it something more than it is?
Also, am I wrong in assuming that the "local vault" isn't going away, and the only difference is now the subscription model and that they are syncing with their own servers rather than Dropbox or iCloud?
Unfortunately for them I purchase and maintain this stuff for everyone in my family, so they are actually losing several customers.
All native 1Password apps (mobile and desktop) support creating, reading, and writing local vaults, except 1Password 6 for Windows, which only supports reading local vaults.
The reason 1Password 6 for Windows doesn’t support writing local vaults is that it is a ground-up rewrite of the Windows app, and they have focused their efforts on cloud support since they see that as their main storage offering.
There’s been no indication (afaik) that they intend to remove local vault support from the other clients. Rather, they have indicated that they would like to add local vault support back to the Windows app but it’s not a high priority. See this forum post from April (https://discussions.agilebits.com/discussion/comment/365276/...):
> Windows is the rare exception where we have to build a brand new program and we're starting out with 1Password.com memberships first and hopefully add local vaults.
That said, I'm quite disappointed in the direction that they are taking and it certainly feels like a money grab to me.
1Password could expand to add things like ssh key support etc. and I would be happy to pay for an upgrade just not an ongoing tax.
For local storage, KeePass seems like an obvious choice, but I'm not sure that I'm as thrilled about its wide variety of plugin, etc. options - suddenly there's not just one set of developers with auditable code, there's the core, the browser plugin, maybe a few other things as well.