Hacker News new | ask | show | jobs
by malepoon2 1272 days ago
1Password does encrypt URLs. It also requires an extra Secret Key [0] in addition to your password. This makes it much, much harder to use the data even if encrypted vaults were stolen.

They also have a development team that's very active. Lastpass had been coasting for years.

[0] https://support.1password.com/secret-key-security/

1 comments

They've been coasting pretty much since buyout
Look, I hate the "new" 1Password as much or more than most, but to say they're coasting is disingenuous; just last week they published their "op" plugin system allowing running "gh" and "glab" and a bunch of other common commands as subprocess of their "op" binary to inject the api tokens. I think the SSH Agent behavior is also post-money

They've also listen to our bitching about requiring the master password every 2 weeks even with biometrics turned on, and rolled that back to a configurable setting

They’re talking about last pass buyout. Not 1password