1Password delisting forum posts critical of their new Electron based 1Password 8
1password.community
1password.community
I am a professional, and don’t mind paying their very reasonable subscription so they can continue to actively maintain the security and functionality of the software that literally protects my entire digital identity. I’m baffled by how many people in our industry are upset by their business model. If you’re making six figures writing software and think $3/month for a cornerstone of your security suite is offensive, you need to grow the fuck up, frankly.
Likewise, I don’t care how they moderate their forums.
The comments in these threads always feel so self entitled. Use another piece of software if those things are important to you. Plenty of us understand and appreciate the value these guys are creating for us. For me, nothing compares. I’ve tried Keepass, Bitwarden, Apple’s built-in thing, Enpass; they are all either amateurish or missing key functionality that 1Password has that I use every day. All the same, I’m happy they exist. Some day I may need them. I hope more pop up.
Anyways, if you’re a dev or employee at 1P I’m writing this for you. Sorry about the jerks. Plenty of us out here love what you are doing.
The complaints about it being a subscription are weak - software doesn’t exist in a closed system. Keeping up with all the platforms and the OS updates etc. takes perpetual maintenance even if they shipped zero new features.
And the features they do ship (family vaults, built in OTP) are really useful.
It’s a refreshing escape from the “free” ad-driven hellscape many of the HN commenters complaining are probably employed by.
You don’t need to cast aspersions against other people to make your argument. Why would you do that? Grow up.
What features and utility were lost? It has way more features and utility now that it had previously. The happy path is the 99% use case, but it also stores non web passwords, docs, and notes etc. just fine.
It's because 1Password was targeted at tech enthusiasts at the beginning and has migrated to a mass-market product over time. The desires of the tech enthusiast group differ (on average) from the goals of a mass-market consumer product. Every time they switch away from something enthusiasts value (perpetual licenses for a specific version, optimized native apps) the early adopters get upset. The average user doesn't care all that much.
> If you’re making six figures writing software and think $3/month for a cornerstone of your security suite is offensive, you need to grow the fuck up, frankly.
For me, it's not about the cost. It's about managing one more subscription. My credit card bill is full of little monthly subscriptions, and at this point I'm tired of adding new subscriptions at every turn. Subscriptions aren't a big deal for the first 5-10 services, but once you're juggling 20+ recurring charges for things that don't really need to be recurring charges, it's tiresome.
I would gladly pay a premium to have a one-and-done license (for a specific version, just like they did in the past) that didn't add yet another monthly payment for me to manage and another system I need to update when I get a new credit card.
I'm very happy to pay $50+ every year or two for a password manager with great UX and cross device support. It is not ok if any functionality is contingent on a subscription though. I really like the Jetbrains model, where if your subscription lapses your software just keeps on working — no updates though.
They have a fairly generous policy is case you'd account is frozen: https://support.1password.com/frozen-account/
This is why I only use password managers that save as KeePass databases, like Strongbox or KeePassXC.
The world is going in this direction, however: everything is turning into Cloud+SaaS to charge for use instead of bill once and forget. The next big thing will very likely be a service that makes extremely easy to aggregate and manage the 465 or maybe 3044 micropayments per year one will need to use his compu... er... stupid terminal a few years from now.
And here come the downvotes for stating a fact, yay!
This seems pretty ordinary for HN xD
It's a real stretch to call any of this "critiquing software".
There are plenty of people and organizations that I prefer the Teams, family and subscription model for.
Its just a bad experience. And yes, their audience has also used Keepass, Bitwarden and others, and see 1Password as the one capable of not fucking it up but simple did any way?
I get it that they don't see an obvious way to do subscriptions that people can't circumvent. It just also brings a lot of skepticism for what other economic pressures are going to guide their decisions, and when.
I, personally, am not happy about the way that this or the subscription update have been handled because, to me, it makes me question how they would communicate something far more serious. If they're delisting forum posts because of a decision to not update their app in the Mac App Store yet, how can I be sure that they won't delist forum posts when they have a data breach? How can I be sure that they're not obfuscating other things that are more important than forum posts to try and sweep bigger issues under the rug? It's like the old adage goes - "If you're willing to lie about something that doesn't matter, what are you willing to do about something that does?"
These moves are forcing me to, at the very least, start looking at a new password manager. 1Password is still the best, in my opinion, in terms of features and usability but that won't always be the case and transparency and respect for your users are far more important to me than niche features. If I can't trust your company over something small, there's no way I'm going to continue trusting them with some of the most important info in my life. I currently use both LastPass (not a fan) and 1Password. I'll be re-evaluating KeePass and Bitwarden because of this.
I'm waiting for someone to actually build a better 1Password, learning from the mistakes, rather then migrating to something else right now.
* their problem doesn't seem to be "we don't have developer bandwidth to add this nice feature," but rather (from my perspective) they're so lacking in discipline and execution. In other words, the PR to fix any such bugs would be so massive as it might as well be a fork
* and that's just on the bugfix side -- anyone who thinks manually created folders are superior to tags ... well, there's no PR to fix that
* them being open core(?) makes contributing feel like free labor for a commercial company. I have less heartburn contributing fixes to GitLab because they do have a for-real open source offering (the CE edition) that one can run without drama
They've managed to implement it in their clients in March this year [1], and I've been moving some of my shared credentials over to a self-hosted Vaultwarden server.
What other features do you think are missing from Bitwarden?
[1] https://bitwarden.com/blog/account-switching-phased-rollout-...
As a happy paying (both corporate and personal) Bitwarden user, the only gripe I had was the lack of multiple-profiles on the same device (which was recently added and works great). We came from KeePass though, so we're likely a more "spartan" user of password managers than some.
EDIT: was unaware of it of 1password integration with Fastmail. This is actually possible.
In the best case, a low level employee made bad choices. More likely than that, a higher level leader in one of those orgs is enforcing a policy decision of theirs. I seriously doubt a C level is involved in any way with this decision.
I just don't see how this decision has any bearing on my trust in what they're building.
1. Senior staff, including Dave (the owner of AgileBits), participate in the forums and are participating in the exact discussions in question while completely ignoring the questions people are asking. It would be hard for them to claim ignorance of what's going on.
2. This also happened during the subscription phase and it happened during the sunsetting phase of standalone vaults so this isn't a first-time incident or atypical of how they respond to stuff from a PR standpoint. It seems like, as a company, their position is to ignore the things that they don't have canned responses for and only answer the things they do have canned responses for and it's obvious that this is what happens to everyone participating.
Again... product-wise, 1Password is superior in almost every way to others. As a company, though, it's hard to continue to support them when it would be far more effective to just be honest and say "We've decided not to do x at this time because of y" or "We're going this route because of y and we understand that that's not for everyone but it's much harder for us to do x when only z% of people use the feature."
The subscription/cloud pushing added to that.
1Password used to let me buy the software and sync how I see fit. That is, it was decent and reasonable software. I was happy to use and recommend it.
That’s no longer the case and I feel like a fool for recommending it, having left those people stuck in a predatory model that I consider at best a bad deal and at worst unethical.
So yeah, I’m going to criticise.
And no, I don’t feel sorry for the staff of a company operating on a business model that should probably be illegal.
Since when is it desirable to pay for software on a subscription model until the end of your life? Sounds like someone else needs to grow the fuck up here.
It's not desirable as a consumer, but I'd rather just get everything for free and just the way I want it as well. It's a compromise. OP wasn't saying that they prefer it this way, just that if you're literally mad and offended by what they're charging, then you're both blowing things out of proportion and not reacting proportionallyy.
Other than that, feels good, I like it. I pay for it for home and work.
I still don't get the Electron hate? Seems a bit insane honestly.
To include Windows users in this fun, previously one could invoke a hotkey and 1P would offer to auto-type into almost any Windows dialog on the screen. Poof, gone
I bet I could come up with 15 other things if I thought about it. Engineering is filled with tradeoffs, and so they made the "we don't enjoy writing cross platform code" versus "we really made our user's lives better by having native code integration capabilities"
And the Windows app was in need of a serious update, the experience was not great.
We can't pretend that engineering for different platforms has no overhead. If they can now move faster shipping new features to all platforms on day one, users will win. There is going to be a transition period where things aren't at parity yet and that's understandable.
So you admit they are removing features at the same price point, but are somehow still confused as to why some folks are upset?
This feature still exists, and it is even easier to use. You no longer have to drag any windows around. The QR code just has to be on screen and you press the button. :) If you're having trouble with it please reach out as we'd like to troubleshoot.
> nor its ability to detect native application's bundle-id and fill in passwords based on the application currently in focus
1Password 7 didn't do this? It didn't fill in any 3rd party apps except browsers that had our browser extension installed. 1Password 8 actually not only detects these apps but also fills in them. https://support.1password.com/mac-universal-autofill/ If that is not working for you, please reach out.
> To include Windows users in this fun, previously one could invoke a hotkey and 1P would offer to auto-type into almost any Windows dialog on the screen. Poof, gone
Agreed. I miss the one too. I'm hopeful we're going to be able to bring it back soon.
-Ben, 1Password
But, electron: no. I use a Mac primarily, and I want Mac apps that take the platform seriously, and integrate well with it. Regressing from that means you lose my business.
Then there’s the SaaS model where my data is stored on US servers. If at any point the someone in the Internet decides to break BGP, sever an optical fibre, or any number of other shenanigans, I am left with what is effectively read-only access to my vaults. I have no option for self hosting to protect against hostile action between international parties that involves me or Agile Bits as collateral damage. We run our own optical fibre networks to ensure continuity of communications in the face of hostile/negligent behaviour, but with 1Password we do not have the option to host our own security.
Then there’s data sovereignty. Agile Bits is a US company, and the US government has shown its willingness to spy and sabotage in the past. Whether it’s intercepting sensitive data in transit (echelon/airbus) or building weaknesses into encryption standards or installing malware on equipment in-transit or sabotaging chip fabs to produce less random RNG, the US has done that.
There is no trust here.
Agile Bits even put out a “survey” to gauge interest in self-hosting as a means of shutting down discourse on the topic. If there was any intention of supporting self-hosting they would just release a trial product which would be a great demonstration that their business continuity plan would work because self hosting would be the same as Agile Bits hosting. Just run the containers on your own docker instead of Agile Bits cloud.
The most “entitled” comment here is yours, talking down to everyone else as if you are the only adult in the room.
They also used to be pretty bad about cross-platform support; no idea if that's still true.
Speaking for myself: because 1Password works everywhere I need it and it means I don't have to think about it. OSS is great at a lot of things. KeePass's user experience is indicative of a place where OSS frequently is not. If I have to think about my password manager, it isn't doing the job I need it to do; when I trialed KeePass, it made me think about it, therefore it doesn't work. For me, of course. Your mileage may vary.
I was a 1Password user before they moved to a subscription model, and I was mildly affronted that I would be stuck on an older version if I wanted to keep out-of-band syncing. More than mildly, honestly. Then I tried a bunch of alternatives and they were all, for my purposes, significantly inferior, either in the "I do not trust them to hold onto data" sense or in the features sense or both. So I tried 1Password again, realized that yup, it's still tops, and that $3 a month is way, way too little money to be agitated over. I have realized way more value from 1Password than I have paid either for the original purchase--which I used for quite a long time--or from my subscription.
I use it because it makes my life better. Surely you can understand that.
> And for large teams, LastPass has owned the market for a while now
I don't think that I know a single security professional in my circles who would recommend LastPass unless the alternative is "don't use a password manager".
Btw, "unlock on secure desktop" basically opens a desktop where no other app/windows can spy or modify the window. This is the envirnoment used when you have to do the UAC approvals in Windows.
Every Electron app seems to want around 400MB RAM minimum. It's not practical for too many of your day-to-day essential applications to be greedy with resources, it all adds up and not everyone has 32GB of RAM.
I used Matrix chat client, Element, on Android - it's an electron app, guess what? It uses 500mb-1GB of RAM. KDE NeoChat Android used 50MB. Electron is simply not a good fit for everyone.
Seriously, any devs that use Electron rather than programming for an operating system's natively provided APIs are lazy and/or incompetent and very disrespectful of peoples' computers and time.
At 1Password we actually did not mind developing separately for every platform. It's been done for years. We build it for ourselves and don't mind putting extra work for better experience.
However, the problem is that you end up with apps that behave differently, miss features, and have different bugs across platforms. Drives people crazy. Just one example: 1Password 7 for Windows shows different search results in a different order compared to the Mac app. Obviously it could be fixed but then a different issue pops up somewhere else.
Instead of adding new features we spent time fixing (making?) various bugs in different ways.
The new 1Password 8 still has a ton of platform-specific code but the core is the same across all desktop and mobile apps. It allows us to get the new features out faster and also spend time on platform-specific code.
In my case I preferred the more tailored to each platform aesthetic, but I can see how that variation could confuse people.
Still a huge fan and recommend 1Password to friends.
This is such an aggressively bad take. This is disrespectful of a lot of developers' time. Plenty of open source software I greatly enjoy wouldn't exist on Linux if it wasn't for Electron. Electron is not a choice I would make for myself but to say "if you use it you are incompetent" is just a bad take.
Citation needed.
If my competitors want to waste time and resources hiring people to create 3-4 versions of the same app for different devices/OSes, I gladly welcome it. I'll be a well established incumbent by the time they put out their MVP.
If I can solve an important business need, my customers don't care if I use 120mb of RAM to do it. They certainly don't see it as "disrespectful" if I can save/make them money in the long run.
However, the problem is that you end up with apps that behave differently, miss features, and have different bugs across platforms. Drives people crazy. Just one example: 1Password 7 for Windows shows different search results in a different order compared to the Mac app. Obviously it could be fixed but then a different issue pops up somewhere else.
Instead of adding new features we spent time fixing (making?) various bugs in different ways.
The new 1Password 8 still has a ton of platform-specific code but the core is the same across all desktop and mobile apps. It allows us to get the new features out faster and also spend time on platform-specific code.
Is it the most performant? No. Does your average user care? No.
So in the meantime, I don't really give a crap what the average angsty passive aggressive self-entitled developer thinks about the underpinning framework that my products are written with since frankly, you're not really the target demographic. (For most software).
I might consider respecting them when they start respecting my time and hardware.
The only Electron programs I tolerate are of the Too Big To Evade kind: Steam, Discord, LINE, and DMM Game Player.
The rest can (and have) all take a hike for wasting my electric bills.
Also, don't expect (let alone demand) to earn any respect from users if you don't respect them in the first place. It's really that simple.
Nope. :V
>but you spent years studying to get a computer science degree
Nope. :V
>later on started a family
Nope. :V
>decided to get a job in Human Resources.
Nope. :V
I'm just a stereotypical self-taught computer nerd of the 90s and early 2000s who saw how lean and effective software of yore were and yearn for those days.
Seriously, we have mundane access to tens and even hundreds of GB of RAM and 5GHz of CPU and what do we use it all for? To try and keep the stuff in the background happy, usually Windows or Chrome in this day and age.
The better hardware becomes, the worse software becomes to waste the hardware even harder. Fuck this noise, I want my childhood computers of badassitude back.
but there's solution even for those: fork it :)
I hope the people complaining about electron are the ones that at least put money where their mouth is and donated to those projects if they do expect native versions
It's very vary poor outlook on other people to think their lazy and incompetent. I'm sorry you hold these values but please try and get out of that toxic mentality your publicly showcasing here.
No you are absolutely wrong. Laziness is not a factor.
Have you ever had to develop and release an application across 5 operating systems all with different UI APIs while also offering a web based UI too? Perhaps it actually makes a lot of sense to consolidate your code base so you can focus on feature development instead of OS compatibility issues and managing many versions of your software across os targets? This is why electron is appealing. In my experience most people who dislike electron apps are speaking from ignorance. They usually have some sort of irrational prejudice against web technologies.
Yes, writing and maintaining codebases for multiple environments is tedious, but it's part of the job description if you are providing good, solid software for more than one operating environment.
If you argue it's too tedious to maintain six codebases, that is the definition of laziness and you ironically helped reaffirm my argument.
Either suck it up or find a new, less demanding job. Programmers of yore managed to do it and we were all better off for it.
Have you ever run a company or worked on a software team? It's a rhetorical question, it's clear that the answer is a solid no. It's not about convenience, it's about economics and getting shit done. Customers getting a product that works is better than them not getting a product because your company blew all its money trying to hire and manage six software teams, or getting a product that only works on some platforms. What a colossally bad take.
There is no such thing as unused RAM after a decent amount of uptime on any mainstream operating system running defaults anymore. If no application has requested it, RAM will get used as file system cache which speeds up the experience in general.
No, it doesn't hold for any desktop application unless you have very good reason to believe that application is the raison d'etre for that computer. If that application is the reason for that computer existing and being used, then maybe you can say unused ram is wasted ram. But if that isn't the case, if your application is auxiliary to the primary purpose of that computer, then "unused ram is wasted ram" is never true for your application.
Photoshop for digital artists or CAD for architects are examples were "unused ram is wasted ram" might be true. Fullscreen computer games are another. But a password manager app? The password manger app is an auxiliary program, not the reason for that computer to exist. The password app should never assume ram not used by the password app is otherwise unused.
Swap speeds are fantastic, but that isn’t an excuse to bloat out software to use all a customer’s RAM which they might want for other things.
Also I don't think the Windows app is an Electron app? I'm not sure how to see it but it feels very native to me. Do you think they have a native Windows app but an Electron mac app?
KPXC looks absolutely lovely but for me it lacks one feature: fold up the tree in one click. This sounds a bit naff but:
We have a KPDBX that is used by several people concurrently - mostly Windows via a drive letter, so direct access. One or two use it via a local clone that they sync remotely back to our central copy. One of those insists on ignoring the tree structure and searching instead, causing the tree to expand somewhat, and then syncing that state back via their "save". I found a plugin for my Windows sporting colleagues that folds the tree back up on open, also KP has a right click option to recursively open or close the tree.
KPCX does not have either option and I generally prefer to find an entry by browsing to it.
Not all people work the same way: some open so many tabs on so many browsers that their machine eventually crashes, and they leave KP in a right old state. Others close tabs when their title is occluded or the tab is no longer needed (you can always reopen closed tab). Some leave RDP sessions open for ever on every box ever and some don't.
Anyway, you get the idea!
I just need browser integrations to work and for it to be open source, I was pretty surprised how well the autofill works on Android. No way am I putting my passwords on the cloud, that makes zero sense to me.
As a nice example of the downsides, due to a few clicks while removing a friend's trial account, 1P irrevocably deleted their data immediately. Which was not clear and was not desired. (Not a bug per se, just "wait what, heck no I didn't mean to do that / didn't know it would do that immediately and with no explanatory prompt")
If they hadn't worked so hard to kill off their local backups, it would've been easy to restore access. Instead nope, and they lost quite a few customers immediately.
Quite right. I use self hosted Nextcloud to get files around. For my sins I own a MS partner firm but I use Arch (BTW)!
Dynamic DNS will always help you to get a presence on the internet unless you are behind NAT and even then, there are remedies (VPNs for example).
Keep it free kids!
Developers making desktop applications should be made to use anemic ~10 year old computers so they know what their application will feel like to common people. Builds can be done on a headless server with plentiful ram; the requirements of the build environment needn't factor into what computer a programmer is given to test their work.
It’s too bad that perfectly serviceable machines like that are being relegated to closets and trashcans due to sheer inefficiency of modern software.
Thinkpad X200, I'm betting. Lovely machines until you open Firefox.
Every performance problem was obvious. Every fix was a clear improvement. And when things were acceptable there, the app absolutely screamed on modern phones. We had startup times faster than Android's launch animation with a little bit of care. Our users loved it.
The equivalent for web development would be to set the network throttling (two clicks in the Chrome DevTools) to the 3G preset, packet drops and all
Whenever you mention that 1P8 is backed by Electron (I myself am very neutral towards that fact), they will quickly correct you and tell you it's backed by Rust instead.
For whatever reason, they are choosing not to just own the truth. This is a real shame because new 1Password 8 is really good, and I recommend it.
This is subjective. For me I feel everything is a bit more clunky, especially when using the standalone extensions. I have it constantly that the extension doesn’t unlock, the desktop version not showing up when I hit the global shortcut, rendering delays and and and
Been using 8 since the pre release to give it a chance but much much prefer 7. I never had this many problems with 1Password and I’m a loyal user since they very early versions
7 was a perfect product that worked flawlessly, 8 is an ok product that does its job. Can’t say I like AgileBits though, too much shady behavior: the subscription migration (hiding one time purchase licenses completely), removing standalone vaults, showing ads within the app, and now this crap
> FYI, Support for Apple Watch was not dropped. The old Apple Watch app could not be included in 1Password for compatibility reasons. We are still exploring how we can include an Apple Watch app in 1Password 8.
So the Apple Watch app is no longer included, but support wasn't dropped?? I don't understand why they cannot just tell the truth about things. Why do they seem to be doing so many things that erode trust when their entire business is based around it?
I wish Futo would pay for a great fully open source (and reproducible build, multiple competing vendor backend, self hostable backend, etc.) project. Keepass, bitwarden, enpass are tolerable.
Something which could both integrate with hashicorp vault and with some shared sessions/no sharing of passwords thing would be cool too (via weird proxy tricks or a browser trick; basically to let a browser log into my session without the user/computer ever seeing the password, only auth delegation.)
The communication could've maybe been better, but overall it's hard to say that the rug was pulled out from under you when you were not using a subscription nor obligated to receive updates. The old binaries still work fine.
For mobile... it's incredibly fast. I have never had an app scan my face and unlock. It's worth shouting out those devs.
Bitwarden is a superior replacement in every way.
I'm going to regret sticking my nose into this, because BW is the Internet's darling, but that is demonstrably untrue unless one's password management needs are extremely simple
One can dislike AgileBits as a business all they like, but BW has a long way to go before it's a superior replacement
That said I still like BW enough to be a subscriber.
I do hope they succeed, and I'm glad vaultwarden exists, but in my line of work execution matters and they have not yet demonstrated that they care about execution to the same degree that 1P does
I am a Bitwarden premium user for my personal password management, but we use 1Password business at work.
Some things Bitwarden is missing:
- Integration with biometric auth on Linux
- SSH key types & SSH agent integration
- API token types
- Equivalent to `op run --` in their CLI client
- Shared vault / folder management in Bitwarden is clunky,
especially with CLI
I'm sure there's more, but this comes off the top of my head. It has a lot going for it, but small things (especially with the CLI tool) make it hard to say it's superior in every facet.I love Bitwarden, but they very clearly employ fewer people and have fewer features.
What I'm complaining about above is the claim:
Bitwarden is a superior replacement in every way.
which I'll add, was compared to 1Password 5. Certainly that may be true for the grandparent poster, but I've put various features that exist in 1Password 8 (as a current user) that are missing in Bitwarden.I'm happy to disagree and say that if you want a product that only does vault storage, and neglects all business or non-user/pass combo needs - great, you can have that. But to suggest somehow that Bitwarden is that product and should remain so - well I'm afraid you're not looking at their business model. They already have SSO options (see https://bitwarden.com/products/business/), audit & compliance, etc. I am being very frank about features that are missing from Bitwarden today that actual customers are looking for.
Your response to the commenter who pointed out ways in which BW is inferior was to ignore the user benefit and say they don’t drive even revenue.
I'm sure that story has improved since then, but it was frustrating enough for me to switch back again.
Also migration from 1Password to Bitwarden was a mess when i did it about a year ago. For example, it removed all file attachments - without even mentioning it! (which i didn't notice right away, which could have easily resulted in data loss.) The migration of all the "fields" in an item of course can't be done exactly one-on-one, which resulted in a huge mess.
I too hate the Electron versions of 1Password though. Profit seems more important than quality to them lately.
I'm currently slowly migrating all passwords to Bitwarden/KeepassXC. Hopefully Desktop browser integration will improve.
We just switched our whole company over. I'm not sure of the basis for the key criticism, as 1Password 8 feels more responsive than 1Password 7 -- which used to take several seconds to appear on the desktop if it was locked.
2. It opens quicker, whereas 1P 7 seemed to sometimes take several seconds to open. By comparison, 1P 8 is always instant, and that's important if you're trying to login to a website via the browser plugin and your Vault is locked.
3. It looks more integrated with Windows 11, as the UX and iconography matches. Also the bigger scale on text and clickable areas makes it nicer to use on a touchpad. I also prefer how the login screen covers the whole screen now. It wasn't always easy to see which monitor popped up the prompt in 1P 7 if you have many.
Some minor criticism:
It's less "nice" to customize your Login items in 1P 8. The label editor and UX to add extra items to Logins is not as good as in 1P 7, but I can't quite put my finger on it. I think it is because the editable parts don't clearly turn into text fields when you press them.
The other side of this, is that it will not work with LibreFox, which isn't signed. Frustratingly, they had the option to disable checks for years in 1Password and removed it.
KeePassXC is the way to go. Similar experience on android and desktop to 1Password (non-SaaS) local vault.
I don't love some of the changes with 1Password 8, but Electron has nothing to do with it.
I would take this as a signal that, in the eyes of many of their users, it's not fine.
Many responses here are recommending against 1Password.
What's a good alternative, specifically for families, as I've moved members of my family to LP?
I'll specifically need some recovery mechanism for them in the event they lose access, as they're still getting used to this workflow. Its not ideal but what's needed realistically.
Edit: here it is: https://blog.lastpass.com/2022/08/notice-of-recent-security-...
One thing 1PW has been sporadically weak on is delivering consistent high quality UX across the plugins and main application.
It would make a difference to me if BW supported these forms of auth.
One simple change would be to for the site to pick some character that is not legal in user names for that site and make it so that if the login form is submitted with a blank user name but the string in the password field is of the form <string1><X><string2> where <X> is that not-allowed-in-user-name character, then the site tries to do the login with <string1> as the user name and <string2> as the password.
People using copy/paste could then store their user name and password together in that format in the password manager, and only have to to one copy/paste to login.
Enpass has given me good cross platform support, especially like that I'm not a 2nd class citizen on loonix systems. My only gripe would be that it's not open source, but I think the company does a good job of allowing you to keep and sync your data locally, without constant pushes to whore it out to 'the cloud'.
[1] https://www.seancassidy.me/lostpass.html [2] https://betanews.com/2016/01/16/lastpass-lostpass-passwords/
The claim that they're censoring critical posts on their forum is fairly baseless until they've had a chance to respond — Occam's razor would suggest there's a much less nefarious reason for posts not showing up.
Finally, the Hacker News crowd has a clear bias towards shitting on Electron apps in the war against perceived crimes of not being performant on ancient systems. I'm sympathetic to that way of thinking, but it's not justified grounds for how much flak 1Pass is taking here.
that said, as someone who has offered them repeated and what I feel is constructive feedback during the Mac and Android beta periods, I can attest they DGAF about what you think about their things. That sweet private equity money invites you to pound sand
In my personal stuff I use Firefox, in which the 1Password experience is not great. I also use it on iOS for personal use on safari, an experience I would also rank as "not great". In a job that I started working with recently, I use Chrome exclusively and it works very well on that platform. So it seems like not a whole lot of effort is being paid to having a unified experience on platforms by 1Password.
I understand it's kind of a hard problem, but the discrepancy seems rather large from my experience. Too large for what they are charging and continue to charge.
That being said, I can't say that there are preferable alternatives currently. My current company uses Lastpass and while the chrome experience is OK, it isn't a massive UX improvement over 1Password either.
--- edit fix some wording issues from starting the sentence one way and finishing it another ---
Any chance you are not using 1Password 8 today?
The problem with 1Password 7 or earlier versions is that the surrounding environment changes and the older versions do not receive updates to keep up. This certainly makes the overall experience worse with time.
It’s specifically after it has locked itself, the little icon with a padlock appears in the username field, click it, touch ID, it unlocks … and the icon remains as a padlocked 1p until I either reload the page, click out and back in, or wait something like 15-20 seconds.
- Customers complain about regression in quality related to the move from native to Electron
- 1Password reply: try the latest 1P Electron
To conclude: the reason to use the new Electron version anyway, is that the old efficient native version will (soon) become even worse than the Electron version, since it's no longer being updated.
Electron apps can be published to the app store, so Electron is kind of a distraction here.
This past year was the first time since 2009 that I’ve actively looked at alternatives, and there are none. 1Password is in a class entirely its own.
Are there things I wish that were different? Yes. Do I wish they’d bring back features that they’ve dropped? Absolutely. But it’s still the single best product in its category. Nothing else comes remotely close. And they are years ahead of #2.
What’re you gonna do?
¯\_(ツ)_/¯ works on my machine?
EDIT: Ooooooh, just read the support thread and now I understand. Goddammit, I wish I knew all this before I upgraded. Seems like there's a trust issue with people trying to get an answer as to why three months in, it still can't be downloaded from the App Store. They suspect Apple isn't approving it due to some shadiness and/or security issues. I really hope not, but their responses and the way this has happened does look _well_ shady.
I made a post in their forums complaining that their on disk file storage left your list of domain names in cleartext so someone with access to your files could see where you have accounts, which reduced the benefit of them encrypting the actual passwords, something they made a big deal about in their marketing.
They moved the post from the high traffic forum section about 1Password to an obscure forum section about random topics. (Their justification for leaving the domains in cleartext was that it was needed to make the browser extension work.)
I still use the product but the company is flawed. They are just less flawed than others.
When it comes to security and privacy in cryptographic terms, they seldom make a misstep. They rightly uphold Kerckhoff’s principle. They do the most important technical things right and reliably. They deserve credit for that.
When it comes to all of the soft/human/marketing/product management decisions, they have some really bad calls under their belts. They deserve criticism for that.
I think the beginning of the end was pushing an update to the iOS app that deliberately took away previous functionality if you didn't have a subscription account.
The update to version 8 forces a login to the app and I could not use my own storage to sync vaults, out of the blue it just happened, I wasn't a paying customer
The workaround? Create an account, export your vault(not in the older version, the export formats are limited), and off I went to Bitwarden
Everything in 1Password minus the toxic optimism, standards compliant migration (1Password can't import from BitWarden, but other way round works) and one fourth of the subscription costs. BitWarden is easy to manage - I got my mother to install it on her Android device, and she can easily manage passwords. Their shift to an expensive subscription genuinely disappointed me with subpar applications. When alternatives work, why consider 1Password? Best option is to stay away from them.
Or to put it another way, you claim 1Password is not standards compliant. What standard should they be?
My experience is that Bitwarden has a clunky user interface, and I just don't trust them (yet) security-wise. I have no problem paying for an interface that my family can use.
1Password and Bitwarden are both really good options. If you are more in the Apple ecosystem, and prefer a great UX, then go 1Password. If you trust bitwarden, and are in other ecosystems, I think that's great too.
Throwing around phrases like "toxic optimism" and "standards compliant migration" is a bit low.
https://www.nytimes.com/wirecutter/reviews/best-password-man...
(Read more here: https://1password.community/discussion/102118/import-from-bi...)
Here's more I found: https://support.1password.com/cs/import-mac/
Something on github: https://github.com/torshinalexey/bitwarden-to-1password-csv
I found this on Reddit: https://www.reddit.com/r/1Password/comments/r9cfd1/comment/h...
If 1Password expects me to pay for their services, they make it impossible for a non-technical user. As for the Wirecutter review, it's hard to decide on a publication that makes money from affiliate referrals.
1Password is uniformly bad; either way you look at it. If its value for money, Bitwarden offers the best one. I am NOT affiliated to either company but speaking from a user perspective.
Not only is Electron heavy, but also inherits all the security vulnerabilities of Chromium.
This is compounded further by the fact that Electron uses its own bundled version of Chromium and so needs to be separately updated, before the app is compiled by the devs.
So many app developers are not even aware of this and so will not bother updating the SDK.
Most password managers support CSV import/export. I moved all my passwords from LastPass to 1Password in a minute.
It's not possible to easily export attachments, so if you have private keys up there as attachments rather than in plain text, QR code screenshots, CSV's or similar. These will not come out trivially. There are some open source Python scripts up there for exporting attachments out of 1Password and BitWarden but I could never get them working.
Whatever they think they're doing taking a native app which rarely (if ever) had such regressions and rewriting as an electron app, they've embarked on a boondoggle.
Since I’m mostly on Mac – has anyone made a transition to OSX keychain? I’ve used it a lot back in the day but I can’t really remember… But modern day iOS/os x seems to have a lot of integrations
I can definitely see a potential targeted attack. Since you could reverse the 1P bundle and see what packages it uses and then try to insert some malicious code.
And then gain access to millions of 1P vaults.
Are all the comments on this thread just people commenting based off the headline?
The thread does show up in the search results, but if one were interested in seeing a thread with 6 pages worth of replies, and untold number of views, in order to know that topic is ... receiving a lot of attention ... then you'd have to come to HN :-)
But at this point isn’t much holding me back from switching to BitWarden. I already use it for my business. I guess it’s time to switch my personal too.
Edited to add: I would mention that I personally use KeePass and love it to death though - my SO and I have vaults we occasionally sync and it's a wonderfully simple and easy to use application for anyone with confidence in keeping the password vault secured and a backup ready.
The screenshot just shows the thread as visible from the "latest post" view, but doesn't actually show up in the Mac forum area.
That said, it seems to be some custom(?) forum software, so there could also be a perfectly reasonable explanation that just looks shady
No offense meant just passing it on!
Thank you for warning others not to follow in my footsteps `o/`
A) Create separate apps for each platform B) Make one app that can run on all platforms with minimal changes
Electron is a very popular way to build a webapp and make it look like a real "native" app. It is great in concepts: companies can build one app, and they only have to make minor changes between platforms.
In practice, Electron apps hog a lot of memory and can appear slow. Electron is basically a web browser rendering a web page. When you have your regular web browser running, along with a handful of Electron apps, you're really running several comletely separate web browsers all at once. On top of that, Electron is built off of Chrome, and Chrome is a huge memory hog.
So, companies that create Electron apps go that route to save time and resources, hogging up users' resources. For 1Password, it's supposed to be a tiny app the mostly just lives in your OS's menubar or taskbar with a minimal UI until you need to open up the larger window. Instead, there's a whole instance of Chrome soaking up memory in the background while your app is idle.
For instance, Slack is a famous Electron app as well as Zoom. If there were a framework where they could share common resources couldn't it be as theoretically efficient as having separate tabs in Chrome? I know we are well beyond something being possible in practice that does something like this, but it feels like it could be theoretically possible to use way less resources doing something like this.
afaik zoom is written in Qt
It might also be a security risk: how do you prevent one app from shipping an infected Chrome 104 that will steal the secrets of another app?
Overall, it just seems simpler to not worry about any of these issues by shipping isolated binaries
This almost never has anything to do with electron and everything to do with the development of the application.
> Electron is basically a web browser rendering a web page. When you have your regular web browser running, along with a handful of Electron apps, you're really running several comletely separate web browsers all at once. ... Instead, there's a whole instance of Chrome soaking up memory in the background while your app is idle.
This is just not true.
The difference between 1Password 8 (Rust and electron based) and 1Password 7 is minimal. More to the point, they tried to use Swift UI for 1Password 8 and failed (SwiftUI is another favorite community beating bag). Apparently, the only true path that certain people would have accepted is keeping a rapidly technical debt increasing Objective C and AppKit code base.