1password is considering a self-hosted option to store vaults
1password.community
1password.community
I do wonder how the licensing and pricing will be handled though.
Bitwarden officially allows self-hosting for the personal use tiers, but it seems to have some license purchase requirements even for the self-hosted options (other than the free tier).
Is there any password management application out there that makes sharing passwords or password vaults easy but is also free? I’ve looked at KeePassXC and Bitwarden. The former isn’t easy to use for sharing and sharing permissions. The latter doesn’t offer sharing among more than two people in the free tier.
I moved from 1Password, and my main gripe with Bitwarden are the apps aren't as polished. If it's not too expensive I'd consider switching back (1Password family is $60 per year, so I assume this will be less).
I'm just really grateful this project exists. I've tried most of the major password managers out there and I feel like BW/VW is the clear winner, especially if you're willing to host your own server. If not, their pricing for an annual personal account is incredibly reasonable.
- Firefox Extension doesn't work fully in a private window in Firefox.
- Extension loses data when you click away from it.
- Extension is hard to navigate using keyboard - e.g. there is no way to copy specific username/password/otp code.
There is lots more issues.
The one killer feature which is preventing me from switching is the ability to use multiple self-hosted servers at once (so I can separate family vaults from business) [1], but "client profiles" are likely to be implemented some time soon [2].
Now that I've learnt that local vaults are going away in 1Password 8 [3], I'll probably make a move to Bitwarden sooner rather than later.
[1] https://community.bitwarden.com/t/log-in-with-multiple-bitwa...
[2] https://community.bitwarden.com/uploads/default/original/2X/...
The most glaring issue (for me, anyway; I fully understand I'm just a sample size of 1!) they have is relying on the pop-up UI of the browser, which I guess is stateless (state is lost when the popup closes, it seems?). The decision of using this UI was already wrong from its inception, IMHO, not sure why they thought it would be a good idea. But more surprising is that they haven't yet moved to the much more reliable and user friendly method of opening their UI on a new tab, which was a no brainer when using LastPass. Oh well. They said to have this in the backlog, so hopefully it gets some attention sooner than later... but in the meantime the end users are faced with silly issues like this, software that loses user data should not be a concern in the first place, and for sure they won't care about some technical explanation about how the browser handles pop-up windows.
(for anyone interested: https://community.bitwarden.com/t/persist-bitwarden-ui-and-m...)
(he recommends using your browser's built-in password manager, which isn't as convenient but is much more secure)
But this whole proposition totally breaks if I store my Amazon password in Chrome at work, and then later I cannot access it in Firefox at home, or the native app in my Android phone.
Basically, I want the browsers to implement something close to what Apple has for password management on iOS. Ideally go a bit further and expose hooks for creating/saving a new login, too.
Unless they already do this, and nobody has actually taken them up on using it?
My biggest complaint about the 1Password8 situation is that i've been "self hosting" version 7 for years using iCloud sync, and it has worked perfectly. I have my 1Password vault on every device for "free". With family sharing in iTunes, i had it for every family member for "free" as well.
With version 8 they're taking that away, and instead trying to push me to a $5/month subscription that essentially does the same thing.
I have faithfully purchased every version up until now, and had they kept local vaults/iCloud sync i would have purchased the next one as well. As it is now, self-hosted or not, i will be looking for something else. Afterall, all i really need is an encrypted file on a cloud share.
Unix Pass would be great if it didn't leak information about which sites you have logins for. "Easily" fixable by using Pass Tomb, but sadly that's not available on iOS.
Having said, I'm all for self-hosting and I hope it continues to become prevalent.
Most people have no clue about the amount of work required to runs things in a secure, redundant and resilient way. And no, a RaspberryPi in the corner, running on your LAN probably won't cut it. At least not for me.
1 - https://keepassxc.org/docs/KeePassXC_UserGuide.html#_databas...
1Password recently raised $100 million at a $2 billion valuation.
Looks like they're going down the Dropbox path. Shame as 1Password used to be one of my favorite apps.
Source: https://1password.community/discussion/115018/support-for-lo...
1. Mobile is paid I think
2. Not open source
“Enpass lifetime premium: $79.99”
Now the same deal is $80 which I think is still ok but on the high side.
I like their hands off approach. Password autofill/save etc are also far better than most other password managers (esp bitwarden).
For members of a relatively well-paid profession earning good wages from creating software, I wonder if the reluctance to support others earning money for quality work isn’t some form of cognitive dissonance.
// Pre-emptive “edit” before this comment has replies: Folks post a lot of arguments for “free” software any time there’s a comment such as mine — but justifications largely feel like post-hoc rationalizations conflating freedom of information and ideas with freedom from paying for value, ret-con’d stories we tell ourselves. I call BS — unless one is independently wealthy, to spend maker time on art or craft requires one to either earn money or enjoy patronage. Tools for work are more craft than art, and deserve to earn, especially as patronage or maker communes are in short supply. Not to mention the exercise of ethnocentric privilege implicit in demanding something of quality in exchange for nothing assured.
I absolutely would try to hook users on any SaaS. However, I go out of my way to avoid such products. If I can pay for them once, I much prefer it. (For something like jetbrains, I'm okay with a renewal fee because if I choose not to pay it, I can still use the older version.)
I make an exception for Bitwarden because I like the idea of my password manager having continual security updates. However, it's one of the most frustrating parts of the webification of services - I want to pay for things once, and choose if I want the expanded features at any given time.
110% agreement.
Further, the only thing I like less than subscriptions is IAP not of new feature sets but ‘pay-to-play’ where the mechanics of use are negatively distorted to gamify purchase impulse.
I’ve argued — here, since inception of IAP on Apple’s app store — that the worst thing Apple has done to consumers was normalize removing the ability to show only single purchase paid apps in the app store. An vast class of less fortunate consumers either resign to less utility or waste time on an artificial “grind”, to encourage another class of “whale” to drive corporate revenues.
I don’t mind extracting cash from whales who can afford it. I do have a problem inflicting artificial digital scarcity of utility or enjoyment on the masses to create the ‘hook’ for whales.
As for subscriptions, it’s not clear to me that the treadmill of software/hardware upgrades is benefiting core use cases.
I like paying for generational or disruptive change, “voting with my wallet” on what’s of worth to me, but after a couple decades of purchasing generations of Adobe software only when the features mattered to my work, I moved from Adobe to e.g. Affinity and feature sets I own instead of rent when these recurring subscriptions don’t appear to meaningfully benefit my productivity or output.
For instance, it’s remarkable to me how similar the principles are between today’s (re-)emergence of Markdown for document composition and the early WordStar / WordPerfect / AppleWriter tools of the 80’s. I also like the experimentation by these Makers in ability to purchase a ‘pinned’ feature set, or support ongoing refinement. (Editors whether text or code, like JetBrains mentioned, seem to have a jump on this clever — and rare positive — use of IAP.) It’s difficult to show what increased utility of word processing has come from the most recent 20 years of paying for word processing upgrades. Today’s dev efforts suggest the sweet spot may be 30 years back.
The flip side of this, economic models are still dissatisfying for affordability of basic bricks and mortar world rights such as housing. The least worst answer appears to be rent (with a dystopian jag into ad-supported!), and it may be the least worst for software is rent as well.
Except when the ongoing annual software rents have risen to the same cost as one-time purchase (again, Adobe!), contrary to bricks and mortar where the over under is often 7 years of possession and use.
Back to artificial digital scarcity — I’m concerned that advertiser funded access to quality writing is losing ground to monthly subscriptions for content. Are less fortunate kids going to be able to subscribe to NY Times, WaPo, Atlantic, Guardian, National Review, American Spectator, and so on, for $5 a month each? (News aggregations such as Next Issue could resolve this, but even as Apple’s “News+” this struggles.) Even more dissatisfying when a print publication goes down the same path as cable, first charging for something that was free, then eventually layering in the same ad content as when it was free.
Artificial scarcity based IAP, data-broker supported (ad supported is fine, individual data for content is not), and the descent into the ironic sounding “gacha” model for software or content happy meals (utilities, clickers, news, etc.) — something thoughtful has to shift before we’re living in a future less Roddenberry than Idiocracy.
If password managers don't (or shouldn't) have an attack surface, what could (or should)?
I could also describe all the data that google stores as "just a password protected DB with a web GUI"
I can tell you a "secret" you can download any version of 1Password, including version 3 from this website: https://app-updates.agilebits.com/
The $2 billion valuation of 1password tells the entire story. They’re overcharging for what they’re providing and I think tech people can “feel” that which is why tech communities hate the subscription BS.
By your argument why can’t I buy that and self-host it too, decide if I want to upgrade for more features myself?
I also think $5/mo for 1Password for Families is incredible value. Zero regrets on paying for this because it meaningfully enhances my families personal security posture through elimination of reused credentials and enabling TOTP (sharing of code generation) on many sites we use, that it is cross-platform so no excuses for everyone to not use it, and the UX is so simple you don’t need to be “tech people” to succeed.
How much you charge and how you charge is definitely divisive, but 1Password feels very much on the cheaper end of the spectrum, not “overcharging”, heck Discord Nitro is $5 (Classic) or $10 and gets you very little by comparison IMO.
>enabling TOTP (sharing of code generation) on many sites we use
Are you generating TOTP codes via 1Password or something? That seems like a degradation of security. I did a cursorary search and didn't find mention of 1Password providing such a "service".
It isn’t a degradation of security, in my opinion, it’s an upgrade, when certain accounts are involved.
For these shared accounts, such as those used by my family, and on services which don’t support account-per-person in an “organization” or “household” sense, this still provides for TOTP in a way my spouse and I can both login. Ensuring just the loss of the password isn’t enough to compromise the account is an upgrade vs. not having TOTP enabled.
Where we can both have our own accounts and use U2F tokens that’s a better story, clearly, but 1Password having this functionality is great!
Even by that blog post, they have to go out of their way and clarify that using this feature means you are not longer using two-factor authentication.
The technology to store passwords safely has a marginal cost of zero (it's software). People storing passwords in third party places increases the threat surface, always. Finally, it's "ecological" in that safety/security of this sort needs to be evenly distributed to work its best.
I'm not saying we shouldn't pay people to make things safer, we absolutely should. But this is a bad model for it.
Though there's enough potential public harm such that looking at "public health" models is not a bad idea. Most places you don't have to pull out your wallet to get a Covid vaccine, you shouldn't have to pull out your wallet to get good password safety, for roughly the same reasons -- the harm from one "infection" can spread quickly.
I’ve found enough bugs in the Mac product that I assume there are security issues I’m not aware of.
If you needed it on both Mac and Windows, the subscription was cheaper.
Whoa! Knowing nothing about the OP you assume that he is the member of the oppressing class clamoring for the output of his slaves? And, since you're writing this in English, I think it's safe to guess you're assuming the person you're attacking is a white, so you're basically accusing this guy of being an entitled white who can't give up his slave labor
I was with you on the rest of the post but charges of "ethnocentric privilege" are a weird, racist escalation hiding in academic terminology there bud
Occam's Razor applies here: everybody likes free shit. This isn't a property unique to the evil whites
Specifically:
>In common usage, it can also simply mean any culturally biased judgment.
Also relating to the "Global North" (who it's very likely that any given poster here belongs to) and "Global South", which don't have anything to do with skin color.
Given you've created a throw-away to comment this, I suspect you know you're actually the one making a "weird escalation" and are aware that you're race-baiting in a non-genuine manner.
> relatively well-paid profession earning good wages from creating software
AFAIK 1password doesn't practice location-based pricing, so how can you assume that "relatively well paid" people from different geographies of the world can all find it affordable?
https://www.bleepingcomputer.com/news/security/-particle-chr...
Yep! People see open source as a goal, rather than a sustainable product being a goal.
It's about freedom, not about price.
I will not shape my life and habits around software that can be discontinued, or suddenly changed so much that it breaks my workflows. I will not use software with proprietary formats or which has dependencies on external "cloud" services that can go away at any moment. I don't need that kind of aggravation.
Happy to pay any reasonable (or even slightly unreasonable) money for software, not an issue. Sell me each version as a stand-alone application that I can run forever without any external dependencies and I'll pay for it.
Try to lock me into a subscription model and/or make the functionality dependent on an external server, that'll be a hard No. Even if free.
GP here. I agree that all software developers and maintainers need to earn an income for their work. It's just that you don't know my circumstances, my geographic location, and the constraints I have to deal with when posing such a question. Believe me when I say that I have some real constraints that cannot be surmounted on this particular front. I don't like my circumstances, but that's just how things are right now and there's nothing I can do about it.
The license check is relatively easy to bypass, and there are also forks and reimplementations out there that already do so.
Is it really worth your time forking it to remove licence checks, when you could instead support the developers and not need to make any code changes?
Forking the code and removing licencing checks is perfectly permissible under the GPL. But it's pretty unreasonable in this case.
> but it seems to have some license purchase requirements even for the self-hosted options
which doesn't appear to be completely true, regardless of whether you think it's worth your time or or reasonable.
For a while, I used KeePassXC work my encrypted database file checked into my Dropbox storage. That allowed me to sync my passwords between devices but not give the cloud provider any way of knowing the passwords (since my KeePassXC master password was not stored anywhere besides in my brain). Unfortunately, Dropbox eventually changed their Android app so that synced files no longer were stored on the local filesystem, so adding a new password from Android or getting the new passwords from other devices would require manually uploading/downloading the file through the Dropbox app. I somewhat suspect this change was due to Dropbox eventually adding their own password management functionality to the app, but I didn't consider that until later, so I'm not sure how the timings lined up. In age case, after weighing my options I ended up deciding to just switch over to Bitwarden. (The migration was extremely easy; I was able to export the KeePassXC database file locally to XML file and then import that into my newly-creates Bitwarden account without any issues).
How does Bitwarden compare to Keepass?
- self-hosted on docker
- mobile app and browser extension
- sharing secrets and storing files
- api
I don't want to selfhost anything. I've spend enough years doing that. All i really need is an encrypted file that can be synchronized using a cloud of my choice.
Does anyone know if 1Password 8 on macOS will also be an Electron app? Their Linux Electron app is pretty good and definitely much better than having no 1Password at all. However, this would be a sad ending for what started out as a great, efficient, native Mac-only application.
I can understand why AgileBits would make this choice. For most users, Electron is probably not a big issue, if they'd notice at all. But as someone who loves native macOS apps, it just makes me sad.
And even then it looks like the JS is WASM compiled from rust.
It’s not implemented in JavaScript/typescript is what I mean. As such it seems to be lean on my system.
https://dteare.medium.com/behind-the-scenes-of-1password-for...
% tar ztf 1password-latest.tar.gz | grep "chrome"
1password-8.1.1.x64/chrome-sandbox
1password-8.1.1.x64/chrome_100_percent.pak
1password-8.1.1.x64/chrome_200_percent.pakEDIT: 168MiB resident memory on my system (just checked).
Though it malloc'd (but never used) 32G, that's worrying.
Keychain itself is getting better and more fleshed out UX, but it’s still not flexible enough to trust for everything unfortunately.
You may wish to look into Secrets: https://outercorner.com/secrets-mac/
It appears to check all the boxes that 1Password used to check.
I wasn’t actively looking to find a replacement, but I was certainly not happy to see them taking venture funding. That’s great in some contexts, but explicit pressure to grow revenue enough to support 500 people and pay back a bunch of venture capitalists isn’t very conducive to writing quality software.
If an app is Electron, it gets an extra and fairly rigorous level of "do I need it? What are the alternatives?" treatment, for this reason. Native, or even QT, doesn't get that kind of in-advance scrutiny, since only rarely do they cause any problems, even if I forget about them and leave them on in the background for months.
> maybe a lone develop that doesn’t need perpetual growth, will make a good, standalone, native Mac password manager.
How do you trust this lone developer? Password manager is all about security and having a motivation to chase money has more trust than someone seemingly doing it voluntarily.
And electron app, not sure why people still complain in 2021... unless you're machine is still running with 2GB memory...
Usability is so much more important than using extra 300MB of memory being electron.
I don't know if it's more important, but certainly, Electron apps' poor usability is another reason to avoid them.
While there are exceptions, they tend to lack usable right-click menus, use odd font sizes (everything's too big), have UI elements that behave differently from the platform standard, and, of course, lag, all of which make usability suffer.
Separately, Electron is itself a large piece of code and integrating it would increase the attack surface — of a piece of security code! Another good reason to switch if this comes to pass.
At the same time, the most audited code it there. Maybe you don't use a GUI browser.
In 2014 I switched to self-hosted password management with 1P and it changed my life. Today, my 1P vaults are a daily, indispensable part of computing. There are thousands of records and my overall security is dramatically higher.
Fast forward a few years and I heard that they had introduced a subscription.
Why?
It’s not their fault: everyone does it. But is this really a subscription service? The applications on my computer and phone have worked smashingly well for years. Is there enough of an ongoing need for development as to require a subscription? I’d rather pay a periodic upgrade fee as maintenance is required.
At the same time, independent and decentralized password management makes sense. I don’t want AmaGooSoft holding my passwords to everything.
In any event, I will continue to use older versions of password management to save on the subscription.
Mainly geeks are the ones that will self-host so it looks like a fair comparison.
> Assuming we're talking about the same feature, then the answer is no, they are not implemented as the new releases do not have support for local/standalone vaults and 1Password 7 will be the last version to support them. The new apps rely on the server to perform a lot of the heavy lifting so we will not be adding support for local vaults as they existed in earlier versions. ...
"We took away a feature that let people not pay us a subscription for no reason and are now maybe gonna think about re-adding it but making it more complex to setup so nobody uses it and we'll get more money."
Can anybody tell me why HIBP still supports them?
After hiding the standalone license this would put a lot of trust back into 1Password.
Supporting more customers and larger scale is inherently more expensive, but I still don’t understand how the product feels like it peaked about 5 years ago and has been treading water ever since.
I don’t mind paying $50 or even $100 for a good password manager that I could rely on for several years. However, it feels like these moves toward subscription software are aimed at extracting $300 or more from me for the same time period, all while failing to provide a decently updated experience.
I do routinely pay $150/year or more for other software packages like JetBrains IDEs, but those are constantly updated. With 1Password it feels like the move to subscription was a step backwards in features with a huge step up in long term price. No thanks.
My wife's boss uses Dashlane, and I got the impression that was a pretty good choice if you were looking for ease of use for non-technical personnel.
I have no idea why you're being downvoted for expressing your experience and opinions. So I will just add another data point to corroborate your experience and (probably) be downvoted together.
I've also been a long time user who paid for every upgrade, and every issue I had with them I received a hostile response or a completely dismissive one. Not sure which is worse.
This made me jump ship last year and now I'm a happy bitwarden user.
No, it's not perfect as you can see in others comments around here but at least I don't have the constant nag that their values are misaligned with mine: forcing a subscription model down my throat at almost 4x the amount of money that bitwarden asks with fading support for standalone licenses and local vaults.
A self-hosted password manager really shouldn't be exposed to the internet. If you are making it accessible over the internet, it's a far greater security threat imo. You're just not going to be able to keep it up to the same security standards as a large production install, like what the Bitwarden folks have going.
Needing to VPN or SSH tunnel into my home network each time I need a password is far too inconvenient.
Not to mention the spared effort in not needing to regularly back up your vault or worrying about keeping the service available.
I'm no expert on the subject, but I suspect these password managers use a sophisticated mechanism of authentication (for accessing the vault) as well as encrypting of the actual contents of the vault.
The effect of this means that Bob's encrypted vault cannot be downloaded by an attacker without the attacker first authenticating to the server.
What does change the dynamic is if you allow a third party to control the code that you run.
Further, allowing anyone to download my encrypted vault just feels really uncomfortable and unnecessary.
> Further, allowing anyone to download my encrypted vault just feels really uncomfortable and unnecessary.
It is unnecessary. I said you could publish your vault on github and still be more secure than a third-party provider. I didn't say you should do this. Of course you should try to keep your vault away from prying eyes. But you should not rely on this for your security. You should only ever rely on one thing for data security, and that is the integrity of your secrets, which should be small enough to be stored in your brain or in a device that allows them to be used without being read (2FA/E). That's the whole point of encryption.
If it's properly encrypted you can display your encrypted vault on a Times Square billboard and it doesn't matter, it's like that physics experiment[1], looks scary but there's nothing unsafe about it.
It's because neither of these conditions are really true - you'd have to assume that source code is only way to assess the security of software and that end-to-end encryption doesn't actually work.
The problem is you not only have to trust your vendor today, but you also have to trust them tomorrow. Every vendor is one acquisition or compromised senior executive or engineer [1] away from becoming untrustworthy even if they started out being perfectly trustworthy. Assessing present trustworthiness is hard enough. Assessing future trustworthiness is obviously impossible.
[1] They don't even have to be compromised. All they have to do is make a bad decision. Apple, the company that built an entire marketing campaign on trust, is now installing spyware on its devices.
If the "good will" is making them money, I guess you can count on it.
And you think your own hosted version that you're only looking after is that much better?
On that view, they should be willing to sell your passwords to anyone willing to pay them more than you are.
> And you think your own hosted version that you're only looking after is that much better?
Yes. Because I know that I won't sell to the highest bidder.
The main bummer is no Safari extension, which (together with no RES) is preventing me from using Safari as my main browser.
Looking back at the times ~10 years ago, it was a pretty good investment to buy software licenses before everything went SaaS.
You have to upgrade from within the IP7 app but only if you downloaded from their site, not appstore.
But it's because the official daemon takes more resource by using MS SQL server and Vault Warden takes such a tiny resource.
Personally i would never pay for a 1Password subscription. I did buy all the standalone versions/upgrades, since day1.
So long as the secret key to these bits is yours, not theirs, what’s the catch?
Passphrase compromised? If they're hosting, you know exactly where to go to access my passwords. If I'm hosting, I can tell you that I use 1Password and my master password and I'm still _relatively_ safe in that you don't even know where to find a copy of my password database.
Encryption broken (whether algorithm or implementation)? If they're hosting, they've now become an _extremely_ valuable target as they're holding a bunch of paid-for accounts, credit cards, banking details, personal identity documents, etc. Not necessarily super-valuable in a one-off situation, but if you could grab a million password databases at once... Which wouldn't include mine, because it's off on my own server.
Legal abuse? An overly broad warrant could vacuum up every database in their possession. Presumably the government can't open the vaults, but if they _really_ cared how sure are you? Would you be comfortable not changing all of your passwords (but can't change your identity documents...) if the NSA asked for a copy of your database? If my data's never in their possession, then I'd need to be targeted specifically with a warrant.
For something I'm using to store all of my accounts, banking details (both logins as well as account and routing numbers), personal identity documents, MFA backups, key backups, software licenses, and more... my question for you would be more "Why would I take any additional risk when I don't have to?" I'd rather not be within the same blast radius as all the other 1Password users.
Edited to add: Also, outside of the "why don't I want my data sitting beside everyone else's", more generally with regards to a hosted option is where my data goes if I have any payment problems, and availability of my data being within my control (if my server goes down, I can fix it--if they have a massive week long outage I just need to twiddle my thumbs potentially without access to... anything).
The above argument seems to turn out the same even for cloud-synced vaults.
If Dropbox suffered a massive hack, the malicious actor could take all the *.agilekeychain and *.opvault files stored there, brute force the master passwords locally, and have potentially complete control over some people's finances and online lives.
Would we be better off if instead of one company like Equifax having _everyone_'s information, we had a company per state?
That all said, I actually self-host my (now KeepassXC because 1Password's push to cloud) databases on my own hardware, so for me it's truly a solution.
In contrast, comparing 1password to "a stranger three towns over" or "the sidewalk" seems a bit unfair to me.
That's exactly what my project, https://app.srspass.com aims to do.
Even though I have a super redundant NAS setup, I'd really hate to depend on a vault and have it all disappear due to some disaster. With SrsPass, I just remember one password, have a recovery/backup phrase written somewhere that it gives me which adds 128-bit of entropy to each generated password and boom, that's my password manager. Stateless, deterministic, and by using argon2id, PHC winner, on the client side it is doing what most password backends should be, but often aren't doing, which is strong memory-hard password hashing.
Further, if it's deterministic, how is this different from just running your password through a hashing algorithm and then using the hash as your password? The only extra information an attacker has to figure out is what hashing algorithm you used and he can generate all of your passwords from your memorized one.
Right? That or I don't understand what you are describing.
Vault is much more ( and better ) than just password storage, but isn't that hard to use either.
Kubernetes Secrets aren't great or very secret, so just dumping stuff there from 1Password seems like... Of very limited utility. Having static secrets across multiple clusters and visible from a web UI, that's it?
I’d ultimately prefer to host my own 1Password server at home if there was an option though, data ownership is an increasingly difficult thing to achieve.
Do Bitwarden or 1password add to this?
They seem to be for enterprise.
I will definitely stay up to date whether this really comes or not.
I’m happy that I don’t have to manage a hardened up-to-date server just for this.
This is pretty fundamental security practise: don't give people stuff they don't need to have, and that means you face less risk of that stuff being lost or misused.
Although devil's advocate:
>users are going to have to run a version of their cloud server locally and use that for syncing instead of just having a vault they can sync locally or through the service of their choice.
I don't see that as inherently ridiculous if it genuinely was a full standalone version with no internet dependencies. Lots of local software going back ages and ages in Unix splits up "server" and "client" sides of things and it can be a sensible architecture in some instances and does not by itself mean anything bad. Like, I don't see what your issue would be vs "sync locally", if it's all under your control, potentially on the same system even, how would that not be merely another way to sync locally just a different implementation? And I don't see the value of "a service of my choice" vs literally just being able to run it as my own service. "Service of my choice" should mean who provides the VPS or colo or whatever, or what VPN I use to access my own local server. A true self-host eliminates the need for Dropbox or iCloud which is fine by me.
Of course this being modern AgileBits I kind of expect a fairly large number of asterisks here that neuter it in practice. But then again that they are even asking at all is something I wouldn't have predicted, I guessed they'd eventually attempt to full force everyone into their subscription model and that would be the end of my 1P upgrades/usage. Maybe it will be anyway if the application starts sucking even harder moving forward, but local host on a normal pay model could change my mind.
I have the advantage that I am a programmer, so I can deal with a bit of reading install guides and arcane configuration. I was surprised to learn just how reliable things can be. Open Source tends to move forwards, so I don't have features taken from me. In recent memory, both 1Password and Fantastical have taken my features in the name of subscriptions. I installed ZigBee home automation with a Hubitat. It has never failed me. Internet and Wi-Fi can be down and things still work. The unreliable part is Google Nest (invalidates tokens every now and then) and Apple Siri (randomly can't do things at times). In short, I can automatically scan and OCR documents, have file services, movie and music, and more, and it all just works.
/rant mode enabled
It has become obvious to me that the law is quickly becoming snitch based. With so much information being hosted online, it's just too tempting a target to not use it for other purposes. Google and Facebook are just the leaders in where this is going. There is just no reason for law enforcement to not scan for dissonant behavior at some point, just as they roam the roads looking for violators. As more jobs become remote, the argument will be "the roads of the 21st century are on the Internet." Difference before is if you get pulled over on the road, you can log it. You know when and where it happened. You have evidence of the encounter. You can see what was used against you and who.
The new system you requires you to try to prove your innocence. You won't know when or where you were targeted. You are not allowed to inspect the software or see the matching hash information. You must open your phone to prove the file is innocent, at which is is legal for the police to capture data. Finally, it is NOT against the law for law enforcement to lie to you [1]. This utterly stacks the deck against you.
All of this could be avoided if at the time of the event you could record what happened and challenge it, because ultimately law enforcement is a money making scheme. Cops are the largest thieving group in America, so treat them like it[2]: a car alarm doesn't stop them, it's just means most thieves will choose an easier target. So, private services doesn't stop a cop, but following cloud events is a lot easier than trying to get into my house.
My sincere hope is that the cloud keeps them busy enough to stay far away from me.
[1] https://www.youtube.com/watch?v=_IZlrf8CiM4 [2] https://www.washingtonpost.com/news/wonk/wp/2015/11/23/cops-...