Hacker News new | ask | show | jobs
by Sealy 3373 days ago
Interested to hear what the HN community thinks about 1Password
9 comments

Initially hesitated to switch to 1Password since some of our team used Linux but eventually we all switched to Mac so that went away.

Much happier with 1Password since we switched from Lastpass. Consistent UI, proper OS integration, multiple separate vaults, not to mention the security story seems better (I've seen several LP vulnerabilities of concern but not yet seen a 1PW one that worried me).

How well does it work on iOS? Does it auto sync between all devices like LastPass does?
I used 1Password for quite a long time but have since switched to LastPass mostly due to Linux compatibility and u2f integration
1password's Windows version does run under Wine, including the browser extension. It's been a while since I did it, but I think there was some sort of browser extension validation feature that had to be disabled. Not 100% up to the security standards of their other platforms, but it's functional.
I used it (1P) and it was super, but mac only - no Linux client. Just switched over to Enpass, and its very like 1Password, only they do provide a linux client. So far its great, very happy with it.
How is enpass's (cryptographic) design and security compared to 1Password?
LastPass does not have u2f yet, do you mean 2Fa? They have Yubi Cloud, but not u2f.
My mistake, yes, 2fa
LastPass currently does not support U2F officially [0]. How are you using U2F with LastPass?

[0] https://lastpass.com/support.php?cmd=showfaq&id=8126

I was really surprised that I was able to get 1Password for Windows working under Wine, even 1P Mini works with the browser extensions. It's not terribly reliable, though.
I like it. I'd give them a 10/10 if they'd offer a Linux client, too. An official API would be nice as well.
The database format is open, and there are linux tools for it:

http://www.lucianofiandesio.com/1password-in-linux

I've used 1Password on Mac / iPhone / iPad for years and it's one of my few must have apps. It's been great, other than a few annoyances with mobile app and upgrade pricing (sorted now, in a logical way). Syncing has always been solid and I've never had any corruption issues.

I've been tempted to do away with the extra clicks and just use iCloud Keychain and encrypted Notes, but 1Password feels like less of a black box at this point (maybe just because I've been using it longer). It also seems smarter about filling out forms than the browser-native options in Chrome and Safari — not perfect, but better. I don't use their subscription service, just the desktop and mobile app.

I'm a long time lastpass user, it does enough for me. Different strong password for every website I use except but never store email, banking or hosting accounts. On another note the cheapest premium 1password is three times the cost of premium lastpass.

Thinking about it I'm really only using it for convenience, security/strong passwords is in second place.

no linux support and shit android support means it's a hard pass for me.
Can you be more detailed about "shit android support"? I'm currently trying it out and didn't seem so bad, similar to how I currently use LastPass in Android in general. Apparently I need an extra click to actually copy a password there, but I also saw they have an integrated keyboard (https://support.1password.com/android-keyboard/), which I haven't looked at yet.
Yep. Complete deal breaker. I think I want a FOSS self-hosted solution.
I really like it. Much nicer to use than Lastpass in my opinion.
How much time have you spent using both? Have you ever used KeyPass? I see people recommending it and I wonder if you have any experience with it.
How about Enpass?
Uses SQL Cipher, which uses "Algorithms provided by the peer reviewed OpenSSL crypto library".

Given all the problems with OpenSSL, I really wished they used something like BoringSSL.

> Given all the problems with OpenSSL, I really wished they used something like BoringSSL.

For basic crypto algorithms, there's little to no difference. Most of the changes in BoringSSL are in higher-level code, like TLS and certificate management.

I've taken it as a sign that 1Password must be a fairly good choice as I very, very rarely see it pop up on here.
That could also indicate fewer people use it?
1Password has over 15 million users across Mac, Windows, iOS and Android platforms.
Wrong metric to use. Just because nobody talks about it doesn't mean it's a "good" choice. It might be better for all you or I know, but using how many hacker news posts you see for something like this is not a good way to evaluate a product.