I'd rather use something like pass and deal with the downsides. (Though I admittedly haven't switched yet.)
I'd rather use something like pass and deal with the downsides. (Though I admittedly haven't switched yet.)
We'll have another solution in the not too distant future that should cover things and be a documented format that anyone with the know how could use.
Also important to note, that if your account ever lapses due to lack of payment. The account is still read-only. You can export your data if you wish even when the account is read-only. We do not lock you out of your data, we just prevent normal use of the application (browser extension, editing items, adding new items, etc). But the data you've already entered is entirely accessible if you want to copy/paste or export.
Kyle
AgileBits
I don't think anyone who uses a password manager is exporting to CSV for security purposes.
I moved away from 1password at the time of the subscription palaver. I managed to move everything to Keepass but each entry has it's own folder.
I don't blame 1Password for the state of my Keepass db (although they pretty much forced my hand) but the closed nature of 1Password does bite you in the arse when you decide to leave.
[1] https://support.1password.com/getting-started-1password-x/
[2] https://support.1password.com/command-line-getting-started/
Users noticing it after the company is already "going out of business" does not qualify as such.
Of all the entities they could be acquired by, I think NPR is the least offensive of all. And they've stated the intent is not to change how PocketCasts works. The other partners are WNYC, WBEZ, and PRX (helmed by Ira Glass). These are all major publishers of podcasts who have a vested interest in keeping PocketCasts a good app, and growing it. I think this is a bad example.
> Neither has Q Branch, but they ran out of money and had to shut down.
They would still be around if they had subscription revenue. Guess who has subscription revenue?
> Is AgileBits going to be around in 10 years?
They started 12 years ago. If you asked 12 years ago if they would still be around in 10 years, the answer would be yes.
> After getting burned by this over and over again, I just think it's more sensible to stick to OSS options that will probably exist in some compilable state even in the distant future.
Well, don't go LastPass if you want OSS.
Not sure about other solutions, open or closed; I moved over to their subscription service a few months ago and haven't looked back.
We don't prevent people from writing 3rd party tools, but I would also be very wary of using them. Our stance is outlined here:
https://blog.agilebits.com/2013/03/06/you-have-secrets-we-do...
> We have to advise you to never enter your 1Password Master Password into anything that isn’t 1Password. We aren’t casting aspersions on the integrity or competence of any developers, but we simply can’t advise otherwise.
So as long as you're mindful of this advice from us, go forth and conquer.
Kyle
AgileBits
In practice, (a) falls apart if the user doesn't have the knowledge, experience, or time necessary to perform an audit, which is quite likely for security software. And I feel like (b) isn't great either, as there are plenty of examples of major flaws in open source projects that went undetected for long periods - heartbleed is just one example.
There are major unrevealed flaws in all software more complicated than “hello, world.”
I'm not expecting anyone to do the work for free, by the way. You could still charge money for cloud sync or even app extensions and still keep the main repo open. Maybe the code could be a few revisions behind to incentivize people to pay.
In any case, from looking around, it seems that KeePass and possibly Bitwarden fit this bill.
Bitwarden just works and checks the boxes for me. I haven't tried it yet, but there is also a fork [1] that allows us to use our own hosting.
I have made an exception for 1Password, as it is so good. I hate subscription for software, unless there is a clear benefit. In this case, I don't see the benefit.
Ben Woodruff AgileBits
opvault file access has open source tools. It would suck if they changed out from under me in the future (1password is the best password manager and it’s really not even close) but my passwords are at least accessible.
I use and love 1Password, but there's no way I'm switching to the subscription model. When my version stops working (either through incompatibility or serious security flaw), I'll begrudgingly find something else to use.