Hacker News new | ask | show | jobs
by ordinaryperson 2204 days ago
What I don't understand is why the big browser makers -- Google, Apple, Mozilla and Microsoft -- makers don't just offer this service.

80% of the plumbing is already there, why not just extend the UI? Generate unique, high-entropy passwords and store them in a user account.

Or add this in the OSes themselves -- Apple already does a version of this with keychain. What's preventing them from just copying all the other features of 1Password and LastPass?

Seems like it would do a lot for web security.

6 comments

Mozilla does have a password manager: https://www.mozilla.org/en-US/firefox/lockwise/

"Securely access the passwords you’ve saved in Firefox from anywhere — even outside of the browser."

Mozilla offers via their new Lockwise tool which is built-in and syncs via Firefox Accounts. Apple does this too with iCloud and Safari using keychain sync.
1. Some do already as noted by others. 2. The password managers domains/problem space is covers parts that a browser never covers. I.e. Phone Apps passwords, Bank PINs. 3. Sync: Phone, Computer, Tablet, other people's phones, other people's computer, other people's tablets.
here is my guess:

One thing you need to understand is that when you start generating your passwords and not knowing them, you need to have your password manager everywhere or else your are stuck. And it turns out many people use browsers and OSs from different makers. So for example keychain might be fine if you have everything Apple, but if your work computer is a Windows one, then it doesn't work anymore. And I'm pretty sure apple is not going to make a keychain for windows any time soon, just like Mozilla isn't doing Firefox sync for chrome and safari.

(I work for a company that makes a password manager)

Chrome and Firefox store and sync my passwords across devices.
Personally, I need my passwords across devices and across browsers.

I use Safari for personal browsing and Chrome for all work/business browsing. As a consultant, when I’m on site at a client location and they give me a machine I make a Chrome profile and let Chrome sync passwords. But I also work in highly regulated industries so I don’t carry those accounts and passwords off site.

But I also share my passwords with a business partner, so I need something like 1Password to keep, manage and share secrets. And credit card, and addresses.

It I will say that none of the password managers out there have amazing UI. I can’t live without certain features I. A password manager, but I’d consider any new entrant that works better than Lastpass and 1Password. I do intend to try Bitwarden.. I think my password manager license renews soon (but it’s not very expensive).

I stopped using 1Password when Dropbox started the max 3 devices rule on the free accounts, I had my 1P vault in Dropbox.

I switched to self hosted Bitwarden on my own home. Works offline and if I need to update passwords while out I can reach the server through wireguard.

+1 for BitWarden, it's perfect for what I need. Instant sync across devices and browsers, TouchID support, no cruft or nags. It just works.
I do use icloud keychain but it doesn't work on windows which I use often too. I wouldn't trust google with anything.