Don't use 1Password (2017)
blog.goodstuff.im
blog.goodstuff.im
If they were lying in their documentation, or the software itself, that would be a different story.
The primary contention of the blog post and the tl;dr is v6 of the product allowed for a 'local' vault until a particular build and AgileBits isn't being open about this change, which the author feels is some slippery slope to other, hypothetical compromises.
I didn't finish it either.
AgileBits are trying to change their business/revenue model and that transition is not suiting this user. Shame for AgileBits but you can't please everybody.
One thing I noticed is that he's not happy to have his encrypted password file in the AgileBits cloud. This is the way LastPass works too. I get some folks don't prefer this but I don't see it as a major risk. If you're using any reputable password manager (a set that includes 1Password IMO) then you're 100x safer than the mainstream even using the vendors cloud hosting.
Below is exactly what the cited page said on February 1st – as far as I can tell, this post offers absolutely no support for this claim.
> Dropbox requires:
> 1Password 4 on Windows [1]
[1] https://web.archive.org/web/20180201210656/https://support.1...
That's way bigger (and simpler to understand), to me, than the corporate drama that the author drums up to justify ditching it.
I used to use KeePass, but I think LastPass is much nicer and more convenient. I also like using the LastPass Authenticator app for 2FA.
I trust the security team behind 1Password more than a community of volunteers around open source password managers.
What I don't understand is why they are coupling the business model to enforced storage in the cloud. Could someone explain why the one necessitates the other, from their point of view?
I saddened that they're going to force me to stop using 1Password after all this time. I really like the software, but I don't like handing over a lifetime of secrets to a third party—any third party.