HNHacker News
TopNewBestAskShowJobs

stimur

19 karma · joined April 29, 2015

[ my public key: https://keybase.io/stimur; my proof: https://keybase.io/stimur/sigs/dfuEuwjx9XrdbZhDU52Zb9ZtHxu5eOWPwivmJevElN8 ]
submissionscomments
stimur··on 1password is considering a self-hosted option to store vaults
(disclamer, I work for 1Password)

I can tell you a "secret" you can download any version of 1Password, including version 3 from this website: https://app-updates.agilebits.com/

stimur··on 1Password for Linux, Behind the Scenes
I know it was announced already here, but I think this deserves separate post
stimur··on 1Password Secrets Automation
[I work for 1Password] 1Password is not competing with Vault. In fact we have very good relationships and mutual respect with HashiCorp on many levels.

Also Secret automation integrates (acts as a provider) with HC Vault[0]

0: https://github.com/1Password/vault-plugin-secrets-onepasswor...

stimur··on 1Password Secrets Automation
[I work for 1Password]

1Password is not competing with Vault. In fact we have very good relationships and mutual respect with HashiCorp on many levels.

Also Secret automation integrates (acts as a provider) with HC Vault[1]

1. https://github.com/1Password/vault-plugin-secrets-onepasswor...

stimur··on Launch HN: Doppler (YC W19) – Easily manage your env vars and secrets
you can do similar things with 1Password CLI.

Here is short example: https://github.com/stumyp/ope

stimur··on Mindfulness and meditation can worsen depression and anxiety
Kind of reminds me of Murphy's law:

1. Things get worse before they get better. 2. Who said things would get better?

stimur··on Terraforming 1Password
Disclaimer: I work for AgileBits.

CloudFormation is a great tool, don't get us wrong. It is one of the first cloud IaaC tools.

And it has it's downsides:

- inability to address specific object in the state, similar to `-target ` option in terraform

- forcible re-deployment (`taint`ing) of the resouce is not possible too, well, not as easy as in TF

- when creating ChangeSet in CF, it is absolutely useless on nested stacks, all you see in it is "Stack will be updated", even if there is nothing to update

- targeted `destroy`s do not exist, as well as destroy `plan`s: similar to what `terraform plan -out plan.out -destroy -target aws_resource.name; terraform apply plan.out` does

- The work with state, renaming, reassigning, deleting and importing resources is missing in CF as a class

- TF refreshes state of the resources each run, checking their actual state and trying to revert any changes applied to them outside of the flow, CF assumes that nothing is changed and gets very surprised when it is drifted or simply doesn't match its expectations. ( I know there is drift detection, but does it actually restores the desired state? I've never had a chance to check that..)

When we deployed new TF stack, we imported part of the resources created by old CF template. And now I am a bit worried to clean it up, because it might try to delete old resources, even with '"DeletionPolicy": retain'. I have no visibility or control over its action. Basically: apply the template and pray.

ChageSets also failed me once, trying to do not what it was telling me in the plan. Terraform plan once captured into the file will do exactly what it promised me, when applied.

To sum up: both tools got their 'pro-'s and 'con-'s, and personally I feel more comfortable with the Terraform.

stimur··on Terraforming 1Password
Because we needed to re-deploy our database, which unfortunately requires downtime.
stimur··on Terraforming 1Password
Everything described in the blog post is using modules making infrastructure description abstract enough to understand and deploy/manage.
stimur··on Terraforming 1Password
They are completely independent, that was the goal.
stimur··on 1Password X: A look at the future of 1Password in the browser
our main app and extension work with Chrome, Safari, Firefox, Edge.

Password X in particular is new approach and its first iteration works in Chrome only. Which doesn't mean it will not work in other browsers as well in later versions.

stimur··on 1Password X: A look at the future of 1Password in the browser
AgileBits employee here:

> First fully hosted passwords

In addition to standalone data

> Now support for extension only

In addition to existing apps and existing extension.

> I guess their previous model was killing 1Password.

The guess is wrong. Sorry. We said the opposite publicly multiple times.

stimur··on 1Password X: A look at the future of 1Password in the browser
Sorry, you're right :)
stimur··on 1Password X: A look at the future of 1Password in the browser
Also I see that people for some reason think that this is the only future of our apps. - Standalone apps are not going anywhere. - The original 1Password extension, which is working with standalone app is there too and in active development.

1Password X is one more thing, additional possibility. Not a replacement.

stimur··on 1Password X: A look at the future of 1Password in the browser
I don't think we are. 1Password X is a purely in browser app. It doesn't have local access to your files, it is an extension. The only way for it to get data is from some server outside, i.e. cloud. Don't try to see the malicious intent where it was just practical decision.

At the moment this is the only way to get 1Password to work on Linux (except older OPW4 with local sync support under Wine). I personally happy about it. You don't have to be, if you don't use cloud. No one pushes you.