1Password 8 Loss of Capabilities

The no local vaults isn’t the real issue…although I and others users prefer to do it with DropBox or iCloud to separate the password part from the sync part. The issue with it is that they’re removing a feature that users want because forcing the subscription makes them more money and they claim that the Secret Key on the server end makes it more secure…when in fact it is just a second password just like the DropBox password is a second password that needs cracking to get access. From a strictly math standpoint…they’re not lying as the really long but not as complex as it should be Secret Key results in trillions of trillions of centuries to crack as opposed to just trillions of centuries to crack DropBox and Master passwords…but in reality trillions of centuries is good enough.

Subscription or not really isn’t a major issue either…although I and others prefer they would offer both. I realize they need revenue to fix bugs and add features…but most of the features v8 adds are either aimed at enterprise clients or at reducing their costs…but we can live with that and the no native client and the no local vaults if we have to.

The no local backup is the real issue that people on their forums are disliking…not being able to have a local backup of your data that can be cloned, backed up, and restored when needed without support from their end is simply ludicrous…they originally said it would be coming in a “later release” than v8…but now their employees are saying a “later release of the beta v8”…so either they changed their minds about it, failed to communicate clearly, or are just trying to smooth the waters and hope people forget about it I don’t know…but they’re saying (albeit unofficially and not from corporate management) i5 will be in the release of v8…and that v7 will continue to work but without all the nifty keen stuff we died in v8 and won’t be maintained. If they were to state that both versions would be kept up to date with OS releases until some date in the future it would actually calm the waters more…but to me and others 5hey are clearly shifting business models to be primarily oriented at enterprise users…which is a terrible shame for a platform that started on Apple devices and would not be where they are today without the support of Apple users and it seems like a little more loyalty to long term users is in order.

At this point…I’m waiting to see what happens and gathering options just in case.

1 Like

Agile provided free incremental updates for a version but not after a new major version release, when the free updates stopped. They only restarted after you purchased the new major version and only for that version. I started back in 2008 and upgraded at each major version except, IIRC, version 5 which I skipped. I did go to version 6 when it was released, and then to version 7 when it came out. However, it is NOT cost effective to pay MORE for a subscription. I don’t need a Windows or Linux version so if “more OSs supported” is a feature part of a subscription, then I’d be paying excessive fees for an unusable feature.

1 Like

Having read and considered all the arguments, I’m with fogcitynative.
At this stage of the game, I ain’t changing and learning a new password program just to save a few dollars. When I started using computers in the 1980s, enthusiasts like myself were gladly paying $300-500 for what we then called “programs” for word processing, database management, etc. and then paying it again when new versions came out. I almost feel guilty paying only 36 bucks a year for quality password protection of my entire life’s work. (Just kidddin’ about feeling guilty, Agile Bits.) I know 1PW and I trust 1PW and that’s enough for me.

5 Likes

I am really late to this forum. I read most of the entries. But I will add a coupla cents here.
I first encountered Dave Teare at MacWorld years ago. Great guy. I signed up and bought the use of the app (not a subscription) -I guess if there is an old school in Macs.-then I’m old school. I physically move my vault to all my 4 devices. I will not put my vaults on any external internet service. I will not move to 8- 1Password 7 works just fine for me. And I also print up a copy and store it my safe and change it when I do a back of my hard drives stored in the safe. Maybe once every 3 months. Like someone else mentioned, will use 1Password 7 till an OS breaks it.

2 Likes

I’ve been a 1Password user since the days of having vaults locally and then shared via DropBox and iCloud. Finally the Family license with vaults stored on 1Password servers. I have no issues with our vaults residing on their servers.

I am reserving any thoughts or decision to a different software until I have 1Password 8 running on my M1 iMac with iOS and iPadOS versions on iPhone and iPad. My wife uses only the iPadOS 1Password.

My expectation is that 1Password 8 for macOS M1 will continue to be fine for my needs after a couple of update releases. I use so many of 1Password’s capabilities for: website passwords, credit cards, protected storage for wills, contracts, licenses, etc. that it would be an exhausting evaluations of other password sharing software.

Hope 1Password 8 satisfies my needs.

1 Like

Not going to pretend this news has been easy for me. The chief concern has been the accessibility of the Electron app which, though it continues to improve, simply doesn’t hold a candle to the AppKit equivalent. My worry that lock-in might hold my passwords to ransom, which was my chief original resistance to password managers, has been tested. The subscription–well, I’d already been forced coerced by the shenanigans over the 1Password 7 for Windows situation. And, really, like the student who has just handed over his credit card that its load may be substantially lightened by the payment of accommodation fees, I’m mostly over that now. Like others said, the loss of some sort of automatic, user-accessible backup is a big concern. And, yes, fill in the self-hosting option survey as I have if you’d like at least the option of data sovereignty in future, but by itself the choice of a client-server architecture isn’t the problem, IMO, as long as you can work with your data without a network connection or AgileBits. Note also that however well defended AgileBits are, there’s still the possibility that your password vault could be corrupted, if not accessed.

I am looking at other options, notably the KeePass ecosystem of apps, like MacPass for Mac and Keepassium for iOS. For now, however, I’ll try and make 1Password work. I do not intend to make the same mistake again, and use a cloud-based option that doesn’t give me the choice of real data sovereignty.

I started using 1Password many years ago, practically when it first launched. I was satisfied with its operation but started looking for an alternative when it changed to a subscription model and one that was somewhat pricey to boot.

I continued using the standalone version of 1Password until I came across the freeware software called BitWarden. I’ve been using it ever since and am a very happy camper. I gladly sprang for the $10 update which gives me all of the capabilities of 1Password without the subscription and relatively high cost.

Bitwarden on my iMac syncs with the iPhone and iPad versions, and I set up a subset of my main password group on my wife’s devices that stay synced there as well. It can even tell me if any of my passwords have been compromised and seamlessly autofills login dialogs.

Check it out at Bitwarden.com. I have no connection with this group other than being a satisfied user.

1 Like

I have also been trying Bitwarden and agree with your comments. It looks like a very workable replacement for 1Password. In my last post I asked about Apple’s keychain. I have had a look around and found a Canadian app called Minimalist which uses Apple’s built in security as a framework for their password management. I am getting to like it a lot. It sounds a lot like the early days of Dave and Roustem (also from Canada) at 1Password who, I think, used Apple keychain before moving to Agile Keychain and then OPVault. What's New and What's Next | Minimalist if anyone is interested intrying it.

2 Likes

Please keep us informed. It looks very nice but I’m going to wait to hear how secure and functional it is. I’m a long time 1Password but not hot on having my stuff stored on someone’s cloud storage. Thanks for the pointer!

I just looked at their page and it is subscription software except for a very basic version which is apparently their “trial” version. In addition it doesn’t look like you can just use a direct WiFi connection to sync between your desktop application and your mobile devices; you’re required to upload all your passwords to their servers. This latter requirement makes it DOA for me.

“It” being 1Password or “it” being BitWarden? The comment to which you replied discusses both apps.

My absolute pain point I constantly have, is the “Memorable Info” characters security question…

For example, say a bank asks you to create a Memorable Info term, so you do “sDas-dkns;fk58dsafl2d;Lfn”. Then when logging-in they ask for characters 5, 8, 14 from this. Currently, in 1PW on Mac you have to fiddle around with ‘Show in Large Type’ to see the corresponding number count to pick the correct characters, and on iOS/iPadOS the same function doesn’t even show the number count so you have to manually count along the correct amount. Who at 1PW thought that was an acceptable longterm solution, given it’s been like this for the last 2 versions at least?!

Does v8 do anything to improve this??

If not, then they’re really dragging their heals, as this ‘give character x, y, z’ thing is becoming ubiquitous all over the place now.

The recommendation was to " Check out … BitWarden" not 1Password. You probably missed my post of 13 Sep where I said I’ve already been using 1Password for 13 years so your confusion is understandable.

Interesting. I have not seen this ever.

Generally what I have seen is choose three prompts and provide answers. Again, 1P is not great at that; I do these manually. Usually I just manually create a password field, have it choose a random memorable passphrase, leave only the first or first two words as the answer, and note, of course, what the question was. And I use memorable because there are sites that also have dial up customer support that may ask me the answer to one of these security questions, and it’s a lot easier to answer with a real word or phrase than a random blob of characters.

3 Likes

In UK/Europe they’re literally everywhere.

When used on the phone to a CS agent, the idea is that their computer screen tells said agent to ask customer for characters 3, 8, 11 from the customers’ password/phrase/memorable info/whatever, which you give them. This is so the CS agents themselves never know or can see the full thing (as it would be a security hole if they could).

In online banking they do the same thing. You set a long string (i.e. pw/phrase/…or whatever the bank chooses to call that particular field!), then the online login asks for 3 characters from it, eg. characters 4, 6, 12.

Each bank is different, but an example may be something like this…

  • (page 1) Enter customer number: 192934942
  • (page 2) Enter password: mypassword129848495
  • (page 3) Enter characters 1, 6, 11 from your memorable word: (your mem.word is “3df57wi7G3Pa56”, so you enter: 3 + w + P in the three little boxes provided)

The page 3 stuff is the annoying one when using 1PW!

2 Likes

This is a pretty silly approach. One that (paraphrasing xkcd) makes it really easy for bots, but really difficult for humans. The exact opposite of what any good security system should be doing.

And it reinforces the fiction that adding additional passwords is somehow making an account more secure. Two (or three or fifty) passwords is no more secure than a single high quality password.

Two-factor authentication is not the same as multiple instances of a single factor (“something you know” - i.e. passwords). They need to add either “something you have” (e.g. a token or an authenticator app) or “something you are” (biometrics).

FWIW, my bank (Bank Of America) uses their mobile app as the second factor. If I call support and they require authentication, they push a notification. The app asks me to confirm or reject the request (and in the process, logging in to the app involves a password or Touch/Face ID). (There are other mechanisms if you don’t have the app available, of course).

2 Likes

Oh, we have that too. Typically in-app (but sometimes still SMS, unfortunately). This then makes the browser “Trusted” (until you clear your cookies or after a ~month or so). Trusted means you skip just to the page 1/2/3 things on each log-in.

Again, the point in my example is they may only have pages 1 & 3 – so only one item to remember – they just ask you for characters from it, rather than the whole thing. This also means, for example, a shoulder surfer cannot see you type in the whole pw – only three (randomly chosen each time) characters, means the shoulder surfer cannot just use those three to log-in themselves, should they happen to have your customer number.

1 Like

Has anyone here tried the new Nord Password application (NordPass)? Does it handle local backups and iOS integration? I’d love to hear a Mac/iOS based review. Other’s that I would love to hear about are ZoHo and Keeper. They seem to have Mac versions but I’ve never read a mac-centric review of them.

2 Likes

Most of the sites I use don’t really care about max length…and while completely random is better than words…if it is long enough the difference to crack is billions of centuries instead of 10s of billions. I went to passwords consisting of 3 unrelated words separated by a symbol and I only use the 3 or 4 symbols that almost always work. Add in a few upper case based on a constant pattern to enlarge the character set and a number series that again follows a certain pattern. That gives me low to mid 20s for length or more depending on the words chosen and while not as secure as it could be it is way more than good enough…and far easier to type if you ever need to since the symbols, upper case, and numbers follow a known only to me logical pattern.

With the full character set…length is really the only thing that matters…Steve Gibson has a how long calcuLator on his website at grc.com/haystack him.

Completely random are mathematically ‘better’…but better is the enemy of good enough for brute force cracking methods which are forced by the length.

Yes. And…in 2021 I am genuinely shocked when I register on a new site and am told that maximum password length is some ridiculously short value like 12 or 16.

When I use the memorable password generator In 1Password I have it set to separate with digits and a special character and 1 word in CAPS. That seems to satisfy almost every site’s requirements unless they have a short cap on length.