I’ve even caught them editing their wiki page, trying to erase their past, which was reverted thanks to HN.
No cloud, only USB keys. The thing is, I lost two of these USB keys! Had to rotate my passwords ;)
[1]: https://github.com/dyne/Tomb [2]: https://github.com/zx2c4/password-store [3]: https://github.com/roddhjav/pass-tomb
https://github.com/mprasil/bitwarden_rs
This is a 3rd party implementation of the bitwarden api, which gives me more confidence in the 1st party product.
We have a team of developers using macOS and Linux, and we use the team functionality to manage both personal and company passwords. We made the switch to 1Password specifically because of Linux support [1].
[1] See 1Password X: https://support.1password.com/getting-started-1password-x/
https://addons.mozilla.org/en-US/firefox/addon/1password-x-p...
It's now as easy as adding the extension and logging in.
I haven't used it myself, but it was created by Wladimir Palant (creator of AdBlock Plus extension), I believe after they examined the LastPass extension and were rather unimpressed with its security practices.
https://palant.de/2016/09/16/more-last-pass-security-vulnera...
https://penguindreams.org/blog/password-algorithms/
I like not having my passwords tied to a device, private key I could lose, etc. With an algorithm, I can still avoid credential stuffing, since all my account use totally different secure passwords, but I can derive them without having to look them up.
I realize someone could figure out my algorithm, but they'd probably need several of my passwords and at that point you're talking about a targeted attack.
I'm on my third iteration of password algorithms. I use my password manager to store which algorithm I'm using for which site and try to update old ones to new ones as I encounter/use them.
There aren't that many exceptions to my rules, so I can usually remember those exceptions if I use them frequently enough.
Machine accounts that require rotation get their own special secure password that I don't use anywhere else.
It tends to be browsers which are gung-ho about automatically filling in login details.
Think I missed that, what happened? I don't enable 1Password autofill or any of it's browser extensions, I just see it as additional attack vectors waiting to be compromised.
> 1Password isn’t affected by this problem because it doesn’t include an automatic autofill feature.
Are you sure we’re talking about the same app? I’ve used 1Password for years, and it’s never autofilled for me. Maybe it was actually your browser’s built-in keyring?
1Password has a native app, which I use on both windows and osx, and I just don't install their browser extension for autofill features.
Though, given that I avoid autofill like the plague, I could easily be misunderstanding the issue too. I'm speaking of a subject I don't use, I don't think anyone should haha.
It's Dashlane that I was using, not 1Password.
After Dashlane I was using 1Password for a week but it was not for me, moved to Padlock and now with LastPass.
I have migrated to 1Pass and then from it to LastPass, thus the confusion.
I checked the history of my backups and somehow forgot about my migration from Dashlane that was the initial tool that would do autofills. Sorry for the confusion, I've should check that more thoroughly. A good sign for me it is time for a walk.
I use an installed 1Password app, and avoid browser autofill extensions like the plague. Browser extensions don't have a good track record I believe, regardless of company. I don't blame the companies, I blame browser extensions.
I see little benefit in autofill integration, I just click the button in my task bar, click copy, and paste. LastPass has been pretty sketchy in the past too, I don't trust them. I've been quite happy with 1Password, fwiw.
I've been using 1password for many years, and that's not how 1password works for me. There might be a setting to enable that behaviour somewhere, but by default, it doesn't autofill without prompting. That's true for every version, OS, browser plugin, desktop app, mobile, etc.
Edit: I just saw your comment that it was actually Dashlane that autofilled! Nevermind then. :)