14 ms·
Heads up: I work for 1Password Any reason why you'd say unfortunately there? I see it as a pretty big perk rather than an unfortunately. But I would also like
by AGKyle 7y ago
Heads up: I work for 1Password
Any reason why you'd say unfortunately there? I see it as a pretty big perk rather than an unfortunately. But I would also like to understand a bit more so I can pass along any necessary feedback to our team.
Thanks!
Kyle
1Password Security Team
- shantly 7y agoSafe to say it's: 1) It's generally preferable that open-source solutions be as capable & usable as closed-source ones, and 2) having the best option be a subscription service is very, very "ugh", as has been constantly complained about here and elsewhere.
- AGKyle 7y agoRe: 1. Got it. Re: 2. It's not just subscription. Download the app (Mac or Windows) and in the options choose to create a new local vault. You'll be presented with a dialog to buy a license if you don't already have one. I get the complaints about subscriptions, but there are certainly pieces of software I am willing to pay a subscription for. One that is actively improved, secured, and is used throughout my day is one of them. Your opinion on this may be different of course. I really appreciate the input though. Thank you! Kyle 1Password Security Team
- Nullabillity 7y ago> but there are certainly pieces of software I am willing to pay a subscription for. There shouldn't be. > One that is actively improved, secured, and is used throughout my day is one of them. Not when those problems are completely self-inflicted by injecting Cloud Bullshit into stuff that doesn't need it.
- jamescostian 7y agoIf there weren't pieces of software that people were willing to pay a subscription for, then software quality would be horrible. The reason why 1Password is so good is that the developers are paid to work on it, and some business needs (such as having really good quality stuff so you can get recommended to more potential customers, and so that your existing customers don't leave) push you towards higher quality software. When working on OSS for free, the need to survive pushes you to work at a job, and your OSS work is done in your spare time, often to get things you want done, but not to make an amazingly polished and very user-friendly work. Subscriptions allow developers to keep improving their software. If you just pay for software once and keep using an older version, developers miss out on money that could keep them working and improving things. OSS is great, but money is important for developers to deliver quality and updates.
- shantly 7y agoI don't remember software quality being a ton worse before software subscriptions became common. Operating systems and certain development practices (maybe, less certain about that one) have led to some noticeable improvements, but that mostly happened before the shift.
- sbarre 7y agoThe major difference you may be overlooking is that now everything is connected and online, and as a result the software we use day-to-day needs much more active maintenance than before. When you had a computer sitting in your home that connected to the Internet via modem for 2 hours a day, your OS or apps could be riddled with hidden bugs and holes and it didn't matter as much. Now we are constantly operating in insecure-by-default environments, and (responsible) companies have to spend much more to monitor, improve and maintain their applications over time, as devices change, underlying operating systems change, new threats are detected and published, etc.. Hence subscriptions..
- pfranz 7y agoI really really don't like software subscriptions, but for a password manager there is obvious ongoing work just to keep it functioning. It's one thing to use a standalone app like MS Money for 20 years with various hacks and compatibility modes to keep it working. Over the time I've used a password manager I've seen OS and browser updates break parts like plugins or syncing. I've transitioned to using passwords more on my phone (and phone APIs have changed).
- oarsinsync 7y agoSoftware quality was a lot higher before the Internet was a thing. What you shipped had to work, as shipping patches was non-trivial and expensive. Most such software wasn't subscription based either.
- inscionent 7y ago*Citation needed
- nathancahill 7y agoHey Kyle! Been a long time paying user. 1Password has helped me help my family use better passwords. We all have local vaults, but I often recommend and help onboard companies I consult with to the hosted service. Thanks for building an awesome app!
- greenice 7y agoHow would you regain access to the passwords in the local vault if the phone breaks or gets stolen and prevent them from being lost? I chose not to use a local vault because I fear those scenarios more than the cloud sync via 1Password being compromised.
- AGKyle 7y agoYou can still make backups on all platforms. So it would be a matter of restoring a backup. Typically someone with local vaults also syncs (to either iCloud or Dropbox) so in theory as long as they still have access to that account they can sign in and access their 1Password data. I'd still suggest backups in addition to that, a sync file is constantly changing, and is not an actual backup. Hope that helps though! Kyle 1Password Security Team
- AGKyle 7y agoHi Nathan! Thanks for the kind words. I'll make sure to pass this along to our team. It's always great when we hear positives. Sometimes the negatives can overwhelm the positive in terms of feedback. If I can do anything to help you with the consulting side please reach out via our support team and you're welcome to ask for me. If I can't help you then I'll get you in touch with someone that is able to do so. Kyle 1Password Security Team
- tbyehl 7y agoAs an ex-1Password user, y'all lost me when you released a new Windows client that didn't support local vaults and let the old client stagnate while pushing everyone to switch to a cloud subscription. I waited and waited for local vault support to come back and finally migrated to something else. No other password manager is as good as 1Password but stringing that out for so long cost AgileBits my business, forever.
- AGKyle 7y agoSorry for the trouble. We had a greater need for the 1Password.com support in the Windows client. So when we started our rewrite efforts it focused on that. In general, we'd agree that it took longer than we wanted, and I'm sorry if that caused you to leave. In the end we were really doing the best we could given the demands we had and the time/resources available to do it. It sounds like in this case it wasn't enough. Kyle 1Password Security Team
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- _jal 7y agoNot the OP, but I dropped 1Password when it became clear you're forcing folks to cloud storage. I was sort of hoping the carefully chosen weasel-words about that used at the time meant you'd reconsider if enough of us made noise, but later releases made it clear where you're headed. It bummed me out - I really like 1pw. And I still don't have my password situation back to the same level of ease-of-use yet, but I switched to control the timing. Storing my password DB on other people's computers is simply not going to happen.
- AGKyle 7y agoThanks for the feedback. I won't pretend that we're the password manager for everyone. If we're not the right one for you then hopefully one of the dozens of others out there fit the bill. I appreciate you taking the time to respond and let me know your opinion on this though. Thanks! Kyle 1Password Security Team
- _jal 7y agoI assume you have numbers showing the total number of whiners like me are an acceptable loss, but I find dropping that feature inexplicable, honestly.
- StavrosK 7y agoFrom running a service, I assume the calculation they did was simply "number of people that whine to us because they lost their self-hosted files > number of people that whine to us because we don't allow them to self-host their files".
- AGKyle 7y agoI think this is probably the better way to look at it. We seen a lot more "I can't access my data anymore" emails before we had our own service. Those seem to have dropped a lot, at least based on my own experience when doing support, since introducing 1Password.com. At the end of the day, our 1Password.com solution is also more secure thanks to the Secret Key being used as well. Our local vaults are certainly secure, but 1Password.com is even more secure. No matter what we do we will have people who don't agree with us. The best answer we can have is be able to logically explain why we have chosen to do something the way we have. Whether the user agrees or not is up to them, but we try to be able to at least explain why we chose to go a direction and hope that the explanation makes the most sense for the most people. We don't always get it right, but we certainly try our best. Kyle 1Password Security Team
- olinad 7y agoNot the original poster, but I could think of two possible reasons: 1) As a user, you are providing a lot of trust into a private company to hold some of your most sensitive information. 2) Often, "open alternative" is misinterpreted as free. At the very least, one would need a self-hosted server to gain the same UX 1password provides, which comes with additional overhead (cost and maintenance) for the user.
- bogidon 7y agoI tried setting my parents up with 1Password. I realized that for someone without decent technical understanding it’s easy to get into weird states. E.g new account creation has a lot more friction than I would hope for. I don’t understand why the “generate password” button is divorced from the flow of making a new login. This was before 1Pass X so maybe things have changed, but my parents were so frustrated I doubt I’ll get them to try it again for years. My advice: if you don’t do this already take some time to get some older folk without a lot of technical experience using 1Pass effectively (real-life usecases too like shared vaults). Take their feedback seriously because solving for them will reduce mental overhead for more technical users too.
- AGKyle 7y agoThanks for the feedback. We've been doing a lot of user testing recently, so I'll run this by the team that do those tests. Really appreciate you taking the time to provide feedback here. You didn't have to but did anyway and it's appreciated. Thanks! Kyle 1Password Security Team
- pastorhudson 7y agoI’ll second the 50+ yr olduser testing request. I’m a very satisfied 1Password user/subscriber. It felt very intuitive to me until I setup my in-laws and other consulting clients who are small business owners. The biggest pain point is creating a new login on iOS in safari. I understand the iOS limitations on browser hooks, but walking a user through creating a new login on iOS over the phone was a test of supernatural patience. If they create the new login in the app instead of safari then they have to type a URL (or it won’t show up in safari) which for an older person who doesn’t really understand websites have addresses is like asking them to calculate the shortest superpermutation of n=7 “real quick”. I believe the family plan for 1Password is fantastic. And a bunch of us have/will signup and put our aging parents on it. So a little user testing by older people where you are trying to help them over the phone would go a long way probably.
- AGKyle 7y ago
- AareyBaba 7y agoYou introduced a feature without warning a while ago where 1Password would phone home for icons every time it is run (where previously users had the option of creating their own). When Little Snitch flagged this, I was very concerned that 1Password which I had entrusted with my secrets was phoning home without my consent. It took me a while to assure myself that 1Password was not uploading my data to the cloud. I don't see why a password manager needs to phone headquarters every time it is run. I have since blocked 1Password from phoning home using Little Snitch as a workaround.
- AGKyle 7y agoYou're certainly welcome to prevent that. We document every domain 1Password contacts here: https://support.1password.com/ports-domains/ https://support.1password.com/ports-domains/ You can map things up pretty good here. However, note that Little Snitch may not provide the most accurate domains when it comes to CDN services. So do keep that in mind that it may reverse DNS incorrectly. I believe they document this on their own site as well. There's at least this that I could find: https://forums.obdev.at/viewtopic.php?t=8859 https://forums.obdev.at/viewtopic.php?t=8859 We went so far as with the Mac application to provide a plist that documents each domain it contacts to give context within Little Snitch, but I suspect you're using 1Password X, which cannot provide the same feature. There's also an open issue to be able to disable rich icons as a setting there. I was a little unhappy that we didn't provide an option for that feature in 1Password X, and I'll bring up again with that team that they need to provide the checkbox sooner rather than later. Sorry you got bit by this though and thank you for the feedback! Kyle 1Password Security Team