Some months ago I tried migrating from LastPass to 1Password, had a lot of headaches with the >having to run an executable in the background< as well as the horrid UI on the control panel.
During testing, I was also constantly being prompted to pay for the thing, (trial was just started!). At least importing worked (kinda, some non-form fills [CC, SSN] didn't import or just would get dumped on random places all over their UI).
The key-management thing they have for the safe is really annoying, having to keep a big string around whenever you need to log in somewhere real quick just doesn't work. (One thing is having OTP codes on your phone, other is needing to type a big, random, safe unlock string).
With that said, due to this acquisition of LogMeIn, I'll be looking into alternatives (Mainly Bitwarden as it's been in the "market" for a while already and seems to be recommended). Probably not gonna move yet but better be prepared.
https://techcrunch.com/2019/11/14/fourteen-years-after-launc...
Edit: Fixed typo. Would also like to add that their use of VC money appears less risky than one could assume.
Regardless, I don't feel personally comfortable with having my passwords in custody of a VC funded enterprise. I am looking into start self-hosting something like Bitwarden in the near future.
Out of interest before I go and google/write it, is there any 'automatic-as-possible' transfer tools/scripts ?
The 1Password cli is a nice touch I must admit.
We have guides here for migration from other password managers:
https://support.1password.com/import/
Let me know if that helps or if you run into any trouble.
Kyle
1Password Security Team
There is even a cli: https://1password.com/downloads/command-line/
Not having a native gui is not the same as "not working".
Pass is an open source project by the guy who made WireGuard (https://www.wireguard.com/), and there are open source apps for iOS and Android too, which you can build yourself for maximum security.
Setting this all up is not exactly easy, but once you get it going it's very easy to use, secure, and convenient.
Essentially, I accidentally publicly exposed my private key. I thought I was clever for writing a Python script to dump all my passwords and then re-add them after setting up pass with a new key.
A year later, when I accidentally deleted my private key (reformatted laptop, phone bricked before set laptop back up), I spent a few hours trying to figure out if I made a mistake that would let me recover my passwords. I was very motivated :)
Eventually, I realized that since I'd been using git to sync pass between my phone and computer (the recommended setup) I could access versions of my encrypted data for every account more than a year old and decrypt them with the private key I leaked. I got back almost all my data.
Luckily I was using a private git repository for defense in depth, but many guides recommend a public reposity because they say gpg is very strong.
It all works, but only if you don't do something dumb like I did. Now I'm on 1password and happy knowing that experienced people are paid to make it and smart security researchers like Troy Hunt (of haveibeenpwned fame) have said it's the most secure password manager they've looked into.
I'm perfectly willing to switch to Bitwarden, although I will miss the ability to securely share logins with my girlfriend's LP account.