I’m Disappointed with 1Password
tdinh.notion.site
tdinh.notion.site
I'm still very happy to pay 1Password to be responsible for my most important data.
As I type this, according to Activity Monitor there are 4 1Password processes using 0.0% of my CPU and about 225MB of my RAM.
I'll take a TUI at <30 MB tops any day. Or CLI.
Does anyone recall what the pre-Electron version used on macOS?
I'd say my one general gripe with 1Password's current major offering is that it's awkward to backup my passwords outside of 1Password. It's possible, but requires figuring out my own solution rather than just having something baked in.
But I cancelled my account a couple of weeks ago. Their product has been worsening over time, and the last adventure of aligning themselves with the (wrong kind of) crypto bros was the final straw for me.
I'm not really familiar with Bitwarden but it is open source and I managed to import all my data in one go from 1Password so I'm testing that for now. IT feels good to support open source at least.
It's a bit less slick than commercial offerings. Form fills don't work quite as well. Maybe once a year, it glitches.
Import from Lastpass was surprisingly easy. I ran them side by side for a while.
If you can, switch AND support this great product!
Now my passwords are somewhere I control, in a format I can read with open source tools, and sync is done by Dropbox/maestral. It's like being back on classic 1Password but slightly more stable and slightly less polished in the UI.
But even with that limited knowledge, 12 points in 45 seems more than necessary to get something to the front page, at which point it has a mind of its own.
And the low quality of previously great password managers certainly strikes a chord with me... BitWarden is the only one I can stand these days, but it's not great.
https://news.ycombinator.com/item?id=29993961
Transitioning to subscriberware + converting your beloved native apps to Electron + raising a bunch of money so you can abandon your loyal users to chase the enterprise market is a trifecta that is catnip for this site’s front page.
Then it changed to the subscription model and a move to storing the passwords on the cloud. At the same time, the company also hid the standalone license option from all the main and help pages where one would look for it (and it required asking in the forums to get a link).
There’s a lot to write about how the company built a good reputation in the beginning and then worked very hard to dig itself deep underground.
The problem I have with both right now is that neither have arm64 clients for Linux.
Regardless, use Bitwarden. It's free and open source. Sure, it has paid options, however, they are options. Nearly all functionality is available for free.
A, the kind of foolish of not wanting to devote half a gig of RAM and slowdowns on a basic, and quite barebones, service, like a password manager.
I think I used Bitwarden for a week before I decided to pay as the experience was above and beyond what I had with 1Password.
Think I've had it 3 years now.
It used to be a solid app and now its browser integration have been more and more messed up for me these last few months.
I’m having the same issues detailed here.
I have only updated about 3-4 passwords out of 100s of items I store. This has been a realisation for me.
1pass, leaves the account in read only mode since it comes from your local storage anyway.
I need to get familiarised with the Bitwarden UI, its not very similar to 1pass, so there is a adoption curve. Hosted Bitwarden with the rust variant option is an option to consider.
- acount
- password
- password generator for random passwords
- browser plugin
- OS app
- notes
- paid version gives you password versioning and a couple of other goodies.
I've used it on all 3 major platforms and my iphone for years without a hitch.
One time purchase, indie devs, support for use on Windows / Linux etc. Been very happy thus far.
What do you mean? Secrets looks to be Apple-only no?
Bitwarden works fine.
Honestly, I don’t feel like most here are really the majority of their target audience.
I’ll continue using it though. I haven’t found anything that works as well for me.
I’ve switched to KeePassXC and Strongbox on iOS. It’s every bit as good as 1Password was for the last ten years, and I don’t have to worry about the future of the product locking me into crappy “growth” decisions. I’ll be donating a similar subscription fee to the maintainers of KeePassXC that 1Password would ask for.
Subscriptions for individuals is different from subscriptions for companies. Companies want to optimise time, individuals may want to optimise cost
personally, I am inclined to pay for IDEs as I spend more than 50% of the time on it, but not so much similar amounts when I use tools no more than 5-10 times a day.
But it's a password manager and I use it. Perhaps I will bother to investigate alternatives and switch before my next renewal.
I bought a standalone package of 1Password at one point in the past and they completely screwed me by locking to an
arcane version of the app which none of today's browser extensions support.
Happy that I bought into Bitwarden at a really low cost of 10 bucks per year which was a no-brainer to me.
This is absolutely ridiculous. Bitwarden have one of the most unfair (for the company) free tier that I ever used. It has everything I ever need from a password management, to the point where I only pay to support the company and not for paid feature.
In time, they moved to a cloud-driven, subscription-based approach. I found this disconcerting since I could no longer see and control where my data was located or evaluate its encryption myself, but I was impressed enough with 1password's track record to believe that it retained a strong security culture. They began emphasizing their web- and browser-extension-based options more, especially for Linux, for which they did not have a desktop client at the time.
Notably absent from this was an export feature. It remained in the Mac desktop app, but was completely missing from 1Password X. I noticed prominent 1password staff apologizing for the apparently unintentional lock-in situation created for some users by adding new platform support without also adding data export for those platforms. They promised it would be addressed soon. It wasn't.
Last year, I went to evaluate whether it was even still possible to export passwords from the Mac client. I wanted to know that 1password was still a good tool, because my daughter was turning 10 and it was time to establish strong security habits. I wanted to be sure that what I was recommending still made sense. I was nervous. I had not actively used my Mac in years. I went to use the export feature, and found that it simply did not function. Extremely alarmed that I now had over 1,000 unique passwords stored in a database that I had no functioning means of exporting, I contacted support and outlined my issue and asked how I could get a plaintext copy of each of my passwords.
I received a reply from a self-described "Astronomer of Support," who said:
"Can you please let me know a little more about why you are wanting to export your data? Once I get a better understanding, I would be glad to help further from there! :)"
I found this very troubling. I had supported 1password for years. I had recommended it to friends and family. I had bought it for some people. In a couple jobs, I required it of my reports. I did this on the belief that 1password had a strong value on privacy and security. I felt extremely foolish. While I had adopted 1password on the grounds that it had a locally-stored vault whose encryption was easy to audit, none of that was true anymore. The export feature I was told would be forthcoming on Linux had not materialized, and the feature on my Mac no longer functioned. 1password support was asking me to explain why I would even want access to my own data by some means other than their application in the first place.I asked the support guy how this would affect his troubleshooting, and he told me he just wanted to understand my use case since plaintext exports are a security hazard. Then he told me to download and run a program to upload a substantial amount of information about my system. There was no question as to whether I was OK with this, or an offer of any alternative.
The answer, as it happened, was straightforward: I had an old version of 1password. I don't know why having an out-of-date version stopped data export from functioning, but it did. I was able to troubleshoot that without relying on the lengthy dossier that 1password's diagnostic tool had compiled, and the support guy could have done the same. Had 1password still been a company that valued people's privacy, he probably would have simply asked me to double-check the version number in the very first e-mail, rather than ask me pointed questions about why I wanted my data anyway, or telling me to install new telemetry software and give all this new data over to him.
I wrote an email back to 1password support explaining my issues as a long-time customer who strongly values privacy. To their credit, they read and replied to my e-mail, mostly to tell me that they use end-to-end encryption and directing me to their whitepaper. I was offered a free year of service.
By then, I'd imported my data to self-hosted Bitwarden, and I've never looked back. And in the year since then, I've only heard more and more negative comments about 1password, a company that was once spoken of very highly in the places I hang out.
OTOH I've helped a relative to migrate from 1P to Bitwarden who had only a single vault for browser logins with name, password and url items and the process was quick and easy.
In recent times it was expanded with direct access from settings, TOTP support, notes per password etc.
And what maybe some people don’t know, it even has Windows support and a Chrome extension to use it within Chrome based browsers. (I myself am a Safari user though)
At least with iCloud Keychain I will be certain it is well integrated into my Apple devices.
KeePass is looking better with every release, but I have switched to Secrets since I like the UX and don’t want to run any kind of sync service myself.
This would be nice, but it'd need to be fully-featured, including Windows support (Linux too, but i'd be doubtful) and non-Safari password autofill support (or they could re-introduce Safari to Windows, i'd be fine with that).
Windows support: https://appletoolbox.com/how-to-manage-icloud-keychain-with-...
I’ve had this issue several times a year as long as I can remember so I’m not sure it’s related to anything new. Usually solved by restarting Chrome, sometimes 1P too.
the "sync" isn't really a problem. you are making too much out of sync. passwords don't change much. you don't have to change/edit your entries every other week.
i keep a live copy on my phone and a copy on the desktop. if i have to add an entry, i add that to the phone and use kde connect to send that file to the desktop. takes 2 seconds. when i open the desktop keepass, i am greeted with the updated file so its not a big deal.
with keepass there isn't an issue with trusting vendors. they do not have internet access so what are they going to exfiltrate?
[0] https://apps.apple.com/us/app/dashlane-password-manager/id51...
https://www.passwordstore.org/
Worst case scenario it's basically just a wrapper for GPG, so you can always get at the password if you have access to your GPG keyring.
I've also never had to directly install it on Linux, it seems to come pre-installed on most distros recently (I think it's a part of GNOME or something, even though I don't use that).