In Its First Funding in 14 Years, 1Password Raises $200M Series A
news.crunchbase.com
news.crunchbase.com
The VCs at this point would be happy with a 3-4x return, because the risk is minimal - companies at this level of maturity, profitability, market dominance, and growth are highly unlikely to fail. So, if they picked up (for arguments sake) 25% of the company, giving it pre-money valuation of $800mm, all they really need to do over the next 3-4 years is build an $3.2B company, which, given 1Password's dominance/quality of product - should be relatively straightforward.
Their killer organic entry is: "Everyone" is already using them for personal password management, which means cost of training/installation/use is trivial to add the Enterprise element.
As a personal user, I consider 1Password the GitHub of password management - sure, there are lots of GitHub competitors, and you can roll your own - but, when there is one product that has completely nailed it - why bother going with anyone else.
When my current native install of 1pw stops working I'll be migrating elsewhere.
I haven't verified this myself, but standalone licences seem to be available for purchase in the app itself: https://discussions.agilebits.com/discussion/92275/how-do-i-...
Hence it's there, but intentionally dark patterned to near invisibility. They would prefer everyone on the pointlessly expensive sub.
edit: I'm wrong, it didn't support touchID in OSX https://community.bitwarden.com/t/touch-id-support-for-macos...
I think when they switched to subscription model they left people who didn’t switch on an old version
If 1Password's claim to fame is functionality beyond password management, so be it, but that doesn't define it as better but rather broader scoped.
Have I Been Pwned partnered directly with 1Password, which is probably why they're able to send out notifications directly; Bitwarden has to worry about being rate-limited.
I'm not too sure what's meant by MFA availability, but Bitwarden also lets you use it as a TOTP generator + use 2FA for logging into your vault, though those are premium features.
It only beats 1Password on price.
If you don't want to pay for a fucking awesome app, good riddance to you.
I run a self-hosted bitwarden server, which I love.
But the client is, in my opinion, not nearly as good as 1password. Its login detection is often disruptively wrong. The need to unlock the keychain each time you start a client is aggravating. The fact that the keychain doesn't lock itself when I lock the worstation is more aggravating. It's sensitive to server downtime when it should be able to work offline. The desktop app is either electron or something very similar and chews battery for me if I accidentally leave it running. 1password's secure notes are far richer. 1password's storage for software licenses is useful and bitwarden offers nothing similar that I've been able to find.
I'm not saying any of this to shit on bitwarden. I like it, and pay for it both in dollars to bitwarden and in time spent keeping the server running/patched. (Which I know is optional, but I really like having it self-hosted).
If 1password could offer me a decent linux desktop experience and a self hosted server, I'd switch back. I liked it that much better.
https://news.ycombinator.com/item?id=21172569 is a good discussion on it.
> 1. Information We Collect and Receive
> Service Data (including Session and Usage data):
> When you use our Services, we receive information generated through the use of the Service, either entered by you or others who use the Services with you (for example, schedules, attendee info, etc.), or from the Service infrastructure itself, (for example, duration of session, use of webcams, connection information, etc.) We may also collect usage and log data about how the services are accessed and used, including information about the device you are using the Services on, IP addresses, location information, language settings, what operating system you are using, unique device identifiers and other diagnostic data ...
> Third Party Data: We may receive information about you from other sources, including publicly available databases or third parties from whom we have purchased data, and combine this data with information we already have about you. We may also receive information from other affiliated companies that are a part of our corporate group. This helps us to update, expand and analyze our records, identify new prospects for marketing, and provide products and services that may be of interest to you.
> Location Information: We collect your location-based information for the purpose of providing and supporting the service and for fraud prevention and security monitoring. If you wish to opt-out of the collection and use of your collection information, you may do so by turning it off on your device settings.
> Device Information: When you use our Services, we automatically collect information on the type of device you use, operating system version, and the device identifier (or "UDID").
That's pretty much everything given they put an extension in your browser and can collect all of that info for every page you visit
> 4. Information Sharing
> ... We may share your personal information with (a) third party service providers; (b) business partners; (c) affiliated companies within our corporate structure
> Examples of how we may share information with service providers include:
The above basically says they share your info with anyone they feel like
So I don't know how you think my comment has no basis in fact. They spell out what they can do in their privacy policy. Why would they spell it out if they weren't doing it?
Compare to 1password (note I use neither service and am in no way affiliated with 1password but for comparison it's telling
> Your data is yours, and we don't want to know anything about it. We don't use it, we don't share it, and we don't sell it.
> We only collect the information necessary to provide our services and help you with troubleshooting. Personally identifiable information is never shared with third parties.
People on HN complain about Google collecting and yet we seem to have LastPass with access to all webpages you visit and also able to track every service you use them with an their policy basically says they collect and share your data (something even Google doesn't do. AFAIK google doesn't share data)
This is not helpful. Why did you hate it?
I now use Keypss, which is free and doesn't require the cloud.
The only reason they went to the cloud is because most people were buying one copy and sharing it with multiple people. It's a way for them to make more money, which is fine, but I really don't think a cloud-based password solution is necessary.
Edit: The 1password employees must be down voting me. It's ridiculous that I get down voted for a specific opinion about the topic.
This seamlessness is also critical for my less-technical family members on my plan. They want the better security, and recognize that a password manager is necessary. But if it was a pain to use they wouldn't put up with it.
You can use the pay-one-price license if you already have the motivation to use DropBox.
But on the other hand, for users who have DropBox already—possibly because they aren't using Linux—this does allow them to sync passwords without paying another $40 a year.
I had to Google a workaround (creating a dummy secure note was one workaround) for the times the sync wouldn't work.
I asked why there was no Force Sync button on their support forums, and was told that they took it out because they want their paying customers to report sync issues with an error report instead of giving them an instant fix via the button.
Needless to say, as someone who has been using and paying for 1PW (upgrades and subs) since around 2008, I was not impressed with that response.
To me, the Windows and Android clients seem to be second-class citizens compared to their Apple counterparts.
They don't have a proper Linux client
The whole point of using a password manager is that the passwords I create and use on my {desktop, laptop, work machine, phone} are immediately and seamlessly available to me on all of the other platforms.
As far as I know it is Cloud integration which enables this absolutely necessary and table-stakes functionality. Is that not true? Does e.g. Keepass provide this essential functionality without a Cloud integration of some kind?
Something like 80% of the value prop of my password manager use is one-tap login (with FaceID) on mobile.
Handwaving this away is failing to understand the product and market at a fundamental level.
edit: literally a paper notebook with my passwords written in it is a better solution in essentially every dimension than a non-syncing password manager.
IMO this was the more secure implementation (assuming 1password was only storing fully encrypted files on your 3rd party cloud preference) - even if someone broke in your Dropbox, they can’t decrypt your passwords without your master pass.
An end-to-end cloud solution provided natively by 1pass is much more user friendly and easier, but requires putting an order of magnitude more trust in 1password’s security architecture (which of course is closed source).
1. 1Password Cloud
2. iCloud
3. Dropbox
And at least 2 and 3 can be used simultaneously, which is what I do, with my main vault in iCloud, and temporary vaults, e.g., passwords for a particular job, in Dropbox.
As an end user, it’s abundantly clear that all encryption/decryption is done locally when using the Dropbox integration since you can see the files directly in your Dropbox. I guess I didn’t make the same assumption about the 1pass cloud service for some reason.
It's not as seamless as having the functionality built-in. You have to deal with logins, authorizations, etc. I wish it could be as easy as "Do you allow 1Password to use Dropbox? (Y/N)".
Just store it in your regular sync solution. Syncthing works great, and I don't remember any issues with Dropbox back when I used that. I'd imagine that iCloud or SkyDrive would work fine too, for the masochistically inclined.
That isn’t the whole point of 1PW though, or at least it wasn’t at the beginning, as I saw it. It was a way to avoid having to remember a unique, secure (read: probably hard to remember) password for every service that requires one. A place to store them all so you don’t have to remember, or worse, reuse the ones you can remember, and/or use easy-to-remember ones (read: less secure). It’s in the name: one password gets you access to all your passwords. Automatic form filling and cloud sync are definitely selling points and certainly convenient, but they are also risk vectors. I’d not call cloud sync essential; I get by fine without it. I just use the WiFi sync option.
Password managers without transparent sync and autofill UX are a half-product at best.
Also like I mentioned elsewhere, I do sync my vaults, but only using the local WiFi option.
There is only one way to exfiltrate information from a notebook, it requires physical proximity, and it's very likely that you would notice.
Every rational threat model for almost every human on the planet (excepting perhaps major political, cultural, or economic figures) would conclude in the paper journal being the better (safer) choice.
For what it's worth, I use it with an ssh plugin, so I only store the database on one machine, and connect using ssh on desktop/Android.
It's also pretty straightforward to set up something like syncthing, making it easier for average person.
> The only reason they went to the cloud is because most people were buying one copy and sharing it with multiple people.
It’s cloud-based because the majority of password management users want automatic cross-device updates without setting up their own server.
So? You can put the database on gdrive, icloud, dropbox, or any cloud service you want. I think most users understand the concept of creating a file, putting stuff in it, and putting it on a file syncing service (or usb drive).
Some people don't want to roll their own. You may, or may not agree with the concept of a fully managed solution, but for any non technical user, they want it to (borrow a phrase) "just work".
It's the majority of the addressable market.
Many do, many don't.
Even for those that do, there is a significant hassle in getting a file sharing service (gdrive, icloud, dropbox) etc onto every possible device they have.
I mean, I'm with you in that I'm personally pretty skeptical of the cloud-based pw solution. But I can absolutely understand the story about a much simpler user-experience that it offers.
What is this "significant hassle"? Surely it's not that much harder to install [sync app] + [password app] than it is to install [password app]?
>Many do, many don't.
I suspect the intersection between "people who don't know how to manipulate files" and "people who care enough about passwords and are willing to fork over $36/yr" isn't big.
Or no app, just add the browser extension and you're done. Seems a lot easier to me than downloading two other apps, one I have no use for other than syncing the other one.
It's literally twice as much work. Often more, because I need the password to the sync app's service. Where's that stored?
How many characters is it? Oh, it's a secure, 20-32 character password. What a pain to re-type it. Good thing it uses a ton of symbols which are a pain to type on my mobile keyboard.
> I suspect the intersection between "people who don't know how to manipulate files" and "people who care enough about passwords and are willing to fork over $36/yr" isn't big.
It's not "people who don't know how to manipulate files", it's "people who don't _like_ to manipulate files, and external services, and get them onto all of their devices".
Further, I expect the proportion of the first circle is constant and relatively small (<10%).
I expect the proportion of the second circle _was_ small, but is growing extremely rapidly.
The cloud synced updating features you're talking about work fine for me already with 1Password's iCloud-backed syncing, which is how most Mac and iOS apps sync data, it's just in that model Apple has control of my data, not 1Password (and I don't pay a subscription fee), so they make it incredibly difficult to configure that way.
Yes.
Note also I'm replying to this comment "It’s cloud-based because the majority of password management users want automatic cross-device updates without setting up their own server." Seems relevant that "cross-device updates" don't require a server (at least among Apple devices)?
I’d it was simply storage, the. It would be an add on, but it’s not. It seems like it’s more of a strategy to increase cash flow by converting to ongoing subscriptions instead of one time purchases. This is the same motivation that switched MS Office and Photoshop over to subscriptions. There’s no compelling reason to upgrade, so you get people to fork over a credit card and forget about their reoccurring charge. Cash flow becomes more predictable and possibly increases as well. This why service contract / subscription businesses are popular among investors.
I don’t blame them for trying it, but let’s not pretend this is good for users.
The truth is that my grandmother needs a password manager and she barely understands what minimizing a window does. "Just store your vault in dropbox" is friction and that matters much more to the huge majority of users than the fact that the vault is stored on a cloud service.
Yes, completely agree. Dropbox sync has lots of gotchas and edge cases, and was particularly bad if you edited files on multiple systems (my workstation and laptop, for instance -- I use both interchangeably depending on what I'm doing).
I can understand why 1Password built their own sync service instead of playing whack-a-mole with different cloud storage providers' quirks.
Anyways all of that said, the 3rd party sync solutions all suffered from varying degrees of funkiness that just don’t exist with the native solution. Their switching to monthly pricing was, objectively, very successful and didn’t cost majority of users more money. But there are a small number of people who it rubbed the wrong way, clearly, but any business action is bound to piss some small number of people.
I was going to just disagree with you without downvoting, because I specifically was looking for cross device sync and mobile support (and specifically looked for a mobile app that supported using FIDO as a second factor to protect the vault.
However, attributing downvotes to employees/shills shows an inability to consider that there may be a good counter argument.
A SaaS model works well for both sides, I think - consumers always have the latest version and their data is highly available and safe against local events (storage failure, fire, flood etc); the business has (relatively) reliay income stream.
Hmm, thinking about it, for simple image editing stuff I still use a version of Paint Shop Pro from something like 10-15 years ago, and it still works great.
I think then that it depends on the kind of software, and the expectations of the user: is it beneficial to store data in the cloud for easy access from multiple devices?; do you want security updates? do you want new features?; do you want support?
I also use Keepass, with passwords stored on a cheap VPS using SFTP. Works great on Android with Keepass2Android too. But of course, this is not something a general comsumer is going to setup.
I agree completely. I never want to pay more than once for Photoshop/Illustrator/etc. -- and the fact that Adobe has turned those into SaaS products really annoys me.
But products like an OS, browser, cloud-synced password manager, mail client, online git hosting, etc. -- for those, I would prefer to pay a subscription fee (to a company I trust to use it well).
When I first posted this, I had multiple down votes in the span of a few seconds with barely enough time for someone to read or even process my comments. It just seemed very suspicious.
https://1password.com/teams/pricing/
"Free family accounts for all team members - $60 value per person"
They sponsored Gophercon in 2018(?). I didn't even know they use Go.
Good luck to them and hopefully they will keep us from password disasters of the future. Now, if only I could convince everyone to use a password manager...
These also have another distinct change beyond simply pricing, they're actually hosted in those regions. So .ca is hosted in Canada and .eu is hosted in the European Union.
Kyle
[1]: https://support.1password.com/regions/#change-your-region
Why was it not as good as lastpass?
This is good for users as it likely mean not huge changes to appease corporate overlords, but continues the sad story of limited young, profitable, small-cap Canadian tech companies available for outsider, passive investment. There are quite a few in the category of 10-15 years old, solid revenues/profit and founders that are ready to step back; most choose private equity or sovereign wealth funds investments in the 100M - 1B range over going public because of the hassle and reporting requirements. The average individual investor doesn't have access to these deals which is a shame because they tend to be established, profitable return generators. I don't blame the founders; I'd likely do the same route.
1Password fixed that and numerous UI glitches around the actual password filling in that I was just living with. It is night and day a better experience ... and no invested interest in them (unfortunately!)
Then there's the risk of me putting everything in there and them jacking up the price. I'd either have to eat it or manually migrate everything.
There are other concerns as well. And I'm not saying I think they are dishonest. But when there are open source methods that are free and battle-tested for security, I see no reason to go with a paid option.
I paid for it once and then used it for years and years without updating. After a few years the browser extension stopped working (was no longer compatible with current browsers) so I decided to buy again. By this time they'd moved to a subscription system and I have no idea how it works.
It used to be simple... there was an app, and if you stored the password file in Dropbox, you got cross platform support. But now the UX is terrible. I don't know where my passwords are stored, I don't know if the entire thing will stop working if I stop paying, etc. What a shame. I used to recommend it all the time but since the update there's no way I could recommend it to anyone I know who isn't a techie.
From the link:
> Your data is yours. Even if you cancel your subscription and your account is frozen, you can still sign in to 1Password.com or in the apps to view and export your data.
In the end was more happy with KeePass as 1Password was too user-friendly for me and I wanted something more stupid for passwords.
Still, if you're willing to handle the availability and security concerns yourself, going self-hosted could work.
I really did laugh out loud as you make it sound so easy. Having said that the money isn't in the consumer side, but the Enterprise. 1Password is only just entering this market and there are huge potential.
I am grabbing AWS keys from MacOS keychain and can access creds I save in iCloud from any device. Uh oh 1pwd
It allows you to use smart unique passwords, syncs between devices, and uses the OS master key to hide the passwords.
It's not great, but it's probably good enough for many people.
If you have cross platform to support, and want the best experience ( or I should say equal experience ) than a decent third party Password Manager is the only way to go.
I would have thought Google would be interested in this market, but ever since the birth of Android, all the wanted is Chrome or Android Integration.
I wasn’t implying that at all. I said “OS vendors” and used my anecdote as one example of what I mean.
> should be relatively straightforward.
What happens if Apple implementes their own native password manager into macOS and iOS? I know I would switch to Apple's native assuming it worked as well as 1Password.
Ah, GitHub. The company which was bootstrapped and profitable like 1Password, but then took venture capital, became unprofitable, and had to sell to Microsoft. Let's hope they aren't the GitHub of password management.
There were also rumors of an acquisition at the same time, which were denied.
Not only that, but the GitHub product is getting much better under Microsoft.
So overall I think it was a win for consumers too.
The YC darling DropBox still isn’t profitable and probably never will be as they are becoming “just a feature”.
1Password will doubtfully never be profitable enough to be worth $3.2 billion. Whether they can pawn themselves off to the public markets first is another question.
And Google and Microsoft do exactly that already.
But if you define success as a company that can actually turn a profit consistently, Dropbox is not a success.
It doesn’t take too many deals with huge companies who need cross-platform to get to $200-300 million, and “worth” $3.2bn. Multiples from revenue have been a little interesting lately.
People made the same argument with Slack. How is that working out?
I don’t know about Android, but iOS supports third party password managers through the extension system.
I think competition in this space is good but I use and like Slack over Teams.
I know at least two companies who pay Slack over $20MM a year, and have over 100k users provisioned onto Enterprise Grid, and who are also happy consumers of Microsoft Office 365.
Being able to sell $1 for 95 cents is not a successful business strategy.
With its generated passwords there is no way to lose your passwords in a hilarious backup failure.
yes that's Keepass, cause it's open source and you keep control of your password database instead of on somebody else's server.
Imagine naming your product "'password'-as-your-password" then telling people "Oh you should really try using 'password'-as-your-password!".
Maybe they can rebrand to "123456"
I recently started using 1Password, and I love it. I finally jumped in because a colleague gave it glowing praise and my company gave us corporate accounts. After using it for a week through my company account, I created a separate personal account for myself. I happily pay a monthly subscription because it is a service I benefit from daily. It also lets me neatly manage personal and company accounts easily, from the same interface, while still keeping the vaults separate.
I see this as a good thing because someone will become the password manager for large companies, and that someone will likely become the password manager. I'm glad to see it's likely to become a service that I think is a good one.
I understand people are worried that the personal use will suffer, but I don't see how. (I understand why people say that - less emphasis on a smaller market - but I don't see how since the corporate offering is basically the same thing as the personal one, to an individual user.)
A) 1Password was already well on its way to doing this (a lot of large companies seem to be using it); B) I'm not sure that it follows necessarily that the largest corporate option will become the largest consumer option.
This company over the years has, multiple times, basically ripped the rug out from under its users (moving to online vaults, hiding native app, switching from a single fee to monthly charge) so I really don't see it as a positive.
From comments in here it seems like they'll be focusing on Enterprise. That just leads me to assume they'll listen to consumer feedback even less.
Why do you see this as a good thing - what good will come of it for you? You’re describing a tool which already does what you want;
With this investment, 1Password need to squeeze half a billion extra dollars out of you just to give to investors. What is it that their tool doesn’t do for you, which needs that kind of trade for them to be able to build it?
That's what happens when the scrappy young company with a valuable product gets acquired. Research and Development stops, Rent-Seeking skyrockets. Every time.
I am still struggling with the idea that a company that was profitable selling licenses for $12/yr needed to then rise to $24/yr and again to $36/yr within the span of two years and somehow not be considered rent-seeking. You said this is to cater to enterprise users, and yet it's not the enterprise users that are bearing the brunt of the price increase. Absent any visibility into company workings, this feels like corporate overlords acquiring a product and declaring, "You are profitable, but our shareholders demand at least XX% profitability, so you need to make more profit, effective immediately."
Please shed whatever light you can on this.
1/ Make the Windows version feel more like the macOS one. I switch between the two OS's all the time and it always feels jarring to open the Windows one after using the other.
2/ Add an option to cache everything locally. My phone has plenty of storage and there have been a few times where I have been with cell service or wifi and unable to pull down a document or credential I have stored there.
Mostly though I love it and can't imagine what life must have been like before password managers.
Certainly thankful in any case that there is a Windows version and I don't have to manually transcribe from my phone.
I'm just amazed that they have so many employees yet their window and browser apps are still really lacking.
Side nitpick: it's annoying that they're moving to 1Password X. I really don't want to run the desktop app AND an independent version in my browser. It's not as bad on mac since it can communicate with the desktop app to unlock, but on windows... ugh.
Well they're lacking an entire platform (Linux), so it's not even just about differences in polish.
I'm sure I've been in situations where I am trying to download a travel permit for example at a check in desk overseas and there is no signal.
I'll see if passwords are the same - maybe those are indeed kept locally.
1. Add a new 1Password item on device 1
2. Do _not_ open the 1Password app on device 2
3. At some point/the next day or whatever, device 2 goes offline
4. Now, while offline, you do not have access to the new item on device 2 because data wasn't synced because the 1Password app hasn't been opened after #1.
The problem seems, 1Password doesn't sync the data in the background (iCloud in my case.)
However, if you did sync by manually opening the app while online, all data will also be available offline later (including attachments.)
Maybe worth me submitting a feature request that facilitates making checked items available offline (like I think Dropbox/Google Docs iOS apps support).
https://discussions.agilebits.com/discussion/108049/ios-iclo...
Anyway, very curious what this means. I'm sure there's a ton of features I've not thought about in years it could use (like LastPass's IP/region blocks) but 1password has never felt like it was a fast moving feature company. Maybe this will get us that.
It seems that the fate of every decent Password Manager is to be acquired by some rent-seeking company and have its userbase gouged.
I suppose we can all start packing up to make the move to Bitwarden. Until it's bought.
Although, it does carry the trade off of me being reliant on a third-party for my password-sync and that I have to pay. Currently it's worth it for me.
I currently use KeepassXC hosted on Dropbox, which takes care of the sync for free. And mobile apps like Keepassium or Strongbox integrate them directly.
I'll probably have to switch if/when the firefox plugin stops working, but hopefully that won't be any time soon.
Our pricing intuition around software is so weird. That's $370 over six years. If you went to a theater and watched a movie alone every couple of months, you spent more on tickets than you did on 1Password in that time.
It's a lot easier when it's a monthly fee to get that money out of me.
"Four in 10 adults in 2017 would either borrow, sell something, or not be able pay if faced with a $400 emergency expense." https://www.federalreserve.gov/publications/files/2017-repor..., page 21. That's a lump sum expense, not paid over time, but I think it illustrates quite well that $370 is a lot of money for something most people don't even know they need.
According to CBS [1], the cheapest city to live in in the US Harlingen, Texas. The Nacho Supreme at Pepe's "homey" Tex-Mex "joint" [2] is $9.95. If you can afford to treat yourself to a plate of those nachos once every two months, then you could have afforded to secure all of your passwords.
[1]: https://www.cbsnews.com/pictures/10-cheapest-places-to-live-... [2]: http://pepesrgv.com/
You can secure all your passwords for free (with Keepass or Bitwarden for example).
1password doesn't have to justify its price versus not securing your passwords, but versus open-source password managers.
Solving a specific problem well in a market worth $X is not compatible with taking 10 * $X in funding — you will be forced to start doing something else so you can make ROI. Along the way you’ll probably alienate your existing market by price gouging (like switching to a subscription based service model for a simple app), so there won’t be any turning back either.
I'd switch from BitWarden to a native Apple solution the moment the Keychain UX reached parity with BitWarden, n=1.
Kinda reminds me of identity management / authentication. These also are features, right? But I feel a lot better about delegating that feature to a business whose core competency is that (eg. Okta, Google, …).
"Payment" also is a feature, but I'd never not use Stripe.
It is strictly for website address/passwords, so doesn't work for a more diverse robust security password manager.
And the sync is very flaky (when I create items within the setting application, they don't show up on my phone). And its multi steps to simply launch keychain since its not a true native app on MacOS nor iOS.
KeepassX and minikeepass on iOS are my go to for secure notes. I don’t see the need for super convenience with my credentials, I’m willing to do some work to access them.
Either way, I’m not handing over a database of login info to a SaaS company. Might make sense for large companies though.
Once the big horses are in the game, it's over. You cannot overcome the brute force of production and cash. Just look at dropbox impoding.
At least password managers are easy to switch.
1Password did this a couple years back, before they even took on funding!
Maybe your choice of example was a sly reference to exactly that, sorry if it was and I'm explaining your joke :). If that was your intent I hope my comment at least makes it clear to people who aren't as familiar with 1Password's history.
The nice thing about them is that they have always had a great consumer product (and the teams product has also been excellent). Since they didn't need to take on the funding, I wonder if having a fund on board will result in focussing on the wrong things (e.g. growth-at-all-costs).
What's the best service level for 1password for a small office, like 10 people or so, that want to just share basic passwords for things like social media accounts, mailchimp login, adobe password, and stuff like that?
You can always change it to 1Password Business later if you need more permission controls, user groups, etc.
If you need help with anything, please get in touch with our business team: business@1password.com
The article mentions all the things that 1password succeeded in doing on its own: bootstraping themselves, shifted their product to focus on subscriptions, even made their product work well with more enterprise-y needs. All while working out pretty well financially.
And now they need capital funding. For what? The quotes in the article seems to say that a developing a go-to-market strategy and hiring a sales team to do telemarketing requires 200M.
I'm still on the pre-subscription 1Pass and kudos to them that it still works, but like Dropbox this will become an enterprise service that will be too expensive for consumers. The good news is that password managers are now effectively a commodity, like cloud storage, so there are plenty of options.
Indeed it seems like only like $70mio go into the company, rest is cashout.
> 1Password plans to use its new capital to “aggressively” invest in its product and go-to-market programs so that it can continue to grow its enterprise customer base
If they get annoying, Bitwarden's not bad https://news.ycombinator.com/item?id=21175332
There's nothing wrong with subscription pricing, especially when paired with cloud syncing. Bandwidth and cloud storage aren't free and the app is definitely worth the $2.99/mo.
It was a great move for them, just not for me since I don't sync my passwords over the cloud.
It has detected Dropbox sync out-of-the-box and kept working with existing settings. But it won't refill passwords, unless I either subscribe or buy a license (a pop-up forces me to do so). I'm curious why you're not seeing the same behavior.
I don't use 1password, but I that's where the costs are.
Maybe they might have some life-changing enterprise thing up their sleeves. I don't know. We don't know. I'm wishing them well, I just am bracing for impact.
What are you basing this off exactly? The only case where failing to hit valuation targets can kill a company, is when the company is reliant on continued funding to operate. A profitable company is free to disappoint it's investors in any way it chooses.
...until those investors are not satisfied with those low returns, and installs a new board/executive focused on milking their existing customers.
> They now need to hit $1BB or die trying
And alluded to “those investors” being able to take over management of the company.
As 1Password is already profitable, and has not been acquired, I’m just trying to figure out what reason you have to make those claims.
>> They now need to hit $1BB or die trying
I didn't, actually. Note the usernames. My reply was regarding the more blanket statement of
>A profitable company is free to disappoint it's investors in any way it chooses.
Also, it's not too unreasonable to assume that a controlling stake was obtained considering that the article said "[this is] a gigantic Series A even by today’s standards", and "The company declined to provide its valuation". Elsewhere in the comments someone mentioned that almost 2/3rds of the money was a "cash-out", rather than an investment to the company. Both statements suggest that a large stake was acquired.
I don’t see any sources claiming the company has been acquired (other HN comments don’t count), even if it was I haven’t seen any evidence that the investors are interested in undermining the sustainability of the business model.
All of the doom and gloom comments in this thread are completely unsubstantiated, and seem to be mostly based on misunderstandings of how businesses actually operate. A company reliant on funding to operate needs to be very concerned with its valuation, a profitable company doesn’t to be to anywhere near the same level. Comments that amount to nothing more than “VC bad” should probably not get a free pass in a community supposedly devoted to “gratif[ying] one's intellectual curiosity”.
There are open source solutions that are nearly as good as 1p. I guess its time to start evaluating. Man I _just_ got my partner to starting using 1p too...
We are also considering using Bitwarden for Business at my company
the reason I don't use bitwarden myself anymore is because I started using syncthing and it seemed like a waste that I wasn't using it to sync my passwords as well. so I'm using keepass now. its not as pretty but the autotype feature is great and it means I need one less browser extension that I need installed
Edit: they have 174 staff!
Is it really a matter of getting $4X M instead of $X M?
I hope they'll re-release the standalone version before the last person out switches off the servers.
personally though, I don't use their offering outside of my work context. Currently, I think bitwarden is maybe the best platform for consumers as its open source, audited by proper security companies and generally very open. I roll with my self-hosted version and I've been nothing but amazed on how good it is to use, even on mobile. Lastpass had way more usability issues (like being totally broken at first on Firefox when they came out with webextensions) and bitwarden's mobile app is at least as good as the one's you'd normally have to pay for. Strong recommendation for bitwarden.
Such a shame 1Password caved in.
VC can corrupt product, and I have intentionally avoided VC funding for my products, but to say it "never ends well" is just hyperbole.
People complained when they upped their prices and moved to a cloud model (and in all fairness that transition wasn't handled perfectly), but honestly, the product is now way better, works on more platforms, and is totally seamless. I hope they use the investment money to continue to make the product better and to get it into more people's hands.
It is not. 1Password 7 for Mac is a UX regression IMHO. Most of my common workflows have become more clunky. There's useless UI elements I can't get rid of taking up prime real estate (Watchtower). And, while this is subjective, I think it's also uglier than 1Password 6.
Profit is fine so long as a user always remains in control. Given 1Password's history of pulling the rug, I can't guarantee that control.
I am using Lockwise and it uses the same technology and cross-platform sync. Since I already use Firefox this is a no-brainer to me, and it's free.
Is there an advantage to 1Password over Lockwise?
You also don’t have desktop apps in case you open an app that doesn’t support your password manager.
I really hope this story isn't the first warning sign that the decision was a mistake.
I'm using KeePassXC in combination with Syncthing, everything is hosted by me and without the need of any cloud. Am I missing something, or is it just the convinience of one package?
Apple use 1Password themselves.
I had a paid app that worked fine. But they tried really really hard to force you into subscription service. Thanks but no thanks.
Because I use iPhone and Mac and iCloud Keychain works really well, I don’t even think about it.
In the not-so-distant future, the idea of password management will be laughable.
* 1Password: https://blog.1password.com/accel-partnership/
* Accel: https://www.accel.com/interests/OurSeriesAIn1Password
I hope they are working towards a more holistic approach for personal security (encrypted drives, cloud backup, monitoring, most things are still very difficult for anyone but prosumer to manager).
You can also keep your password database offline (airgapped network, USB key/drive, remote/offline devices), and having control of the client + database means you know you can still access those same passwords a decade from now.
This app is a huge part of my day and I'm happy to evangelize it.
This is called a secondary.
After so many years I am happy for them. But some people think this practice is a sketchy
WDYT?
Sorry, but your passwords are some VCs property now, and how/where you use/access them from are a business metric to be sold.
Password management is a privacy and data sync problem.
As a consumer I use an Android device, Windows desktop, Linux laptop so OS or single ecosystem solutions don't work for me. They may be ideal for others.
For a business password manager I'd want to know who is storing my data and how it's being stored. It should be stored where the provider has no access to the passwords (data is encrypted client side before being sent through sync backend ).
Disclosure: TeamPassword is part of the business I run.
It's UI is definitely the closest you'll get to 1pass. I think a big reason I couldn't use it was the Android app is built off Electron and doesn't currently support Android fingerprinting.. So I'd have to fingerprint into 1pass to grab my Bitwarden pass..
edit: Err on my part, it's missing TouchID in OSX https://community.bitwarden.com/t/touch-id-support-for-macos...
If its open source thats great, but most people are not building the clients for iOS and MacOS at home. We trust the builds that they host to be true to the source.
1password lists its physical address on its home page (and I think every page).
Lastpass is part of Logmein, an established tech company in Boston.
I'm very wary of a password manager trojan horse, similar to the Kaspersky incident.
I would expect he actually reads Hacker News, so please provide us your backstory, much appreciated.
It's also raised at their official forum but no reply from the author.
https://community.bitwarden.com/t/who-is-hosting-bitwarden/1...
The author did take an interview in 2018.
https://community.bitwarden.com/t/touch-id-support-for-macos...
https://bgr.com/2018/07/10/apple-1password-acquisition-deal/
It's a company whose founders live in my small hometown and keeps appearing in my life in the most disconnected ways (despite living hours away). Just recently my sister-in-law was hired to the company. All along I'm super impressed by their model and great culture, but at the same time believing that it's -- in the words of Steve Jobs -- a feature and not a product.
Fantastic to see them doing so well.
https://www.theregister.co.uk/2017/02/28/flaws_in_password_m...