I just found out that 1Password is donating $300,000 to a project founded by a very controversial person, and I'm looking to move to a different password manager.
Has anyone migrated from 1Password recently to another tool/platform? Have you had a good experience with any tools in particular? Any advice, tips? I'm also interested in the corporate-use context; if I can convince my company to switch to an alternative with business controls, I'll surely try.
n00b question I guess but what is the value of a standalone password manager? Seems like most browsers and operating systems offer this capability nowadays.
Here you go, I made a quite wide-ranging set of notes here when I switched: https://taoofmac.com/space/apps/1password
I migrated from an older 1password to self hosted bitwarden (vaultwarden) using premade configurations which are available for Portman and Docker in the usual places. Mine uses caddy for the Web front, which automates letsencrypt certification. All the client app which talk to bitwarden talk to vaultwarden, but there's no guarantee into the future I guess. I just like self hosted.
The export is through CSV in clear. I wish they agreed to use some pkcs defined superencypherment and a json format so you could avoid the pass through plaintext.
Do this on a machine you trust, offnet I guess.
Bitwarden has corporate options. Password sharing under a reasonable model, group structure.
I moved to self hosted Vaultwarden (Bitwarden server reimplementation that's client-compatible). You can also directly run Bitwarden, but Vaultwarden is easier to self-host, especially OIDCwarden is nice if SSO is your cup of tea.
I don't like Bitwarden's UI as much as 1Password's, but at least it feels faster.
Does DHH actually deserve to be cancelled, or Omarchy "defunded"? I just read the OOOL on Reddit, and I have to say that I am not entirely convinced. https://www.reddit.com/r/linux/comments/1oa74wh/im_out_of_th...
IMO choosing products over politics is a pointless game. Use the best tool for the job.
1p is the best.
Oh, I was only storing and using it in AWS KMS because of the pricing issue, but thanks for the comment. I’ll look into it a bit more.
This anti-DHH movement is so weird to me. People seem to read summaries of his views, often based on interpretations that get exaggerated from one article to another until they become something else entirely. At least read the articles yourself, including his other work, so you don’t just cherry-pick the ideas that conform to your existing beliefs. Then form your own opinions.
unix passstore is perfect
Are people in your company moderately technical? If so, I highly recommend https://www.passwordstore.org/ coupled with a PGP key storage dongle (I personally use NitroKey). Then hosting is just a matter of hosting a minuscule git repo per user.
I imagine that a technical company can easily whip up a bespoke simplified interface for its non-technical staff too.
I've used it for about a decade at this point, and it's just perfect.
Here is the migration guide for 1Password. [0]
The CEO of Stripe also donated $1M to Omarchy.
Do we need another migration guide for Stripe since the CEO personally donated to Omarchy and then tell everyone to stop using Stripe and all of their services?
[0] https://www.patreon.com/violetblue/posts/how-to-migrate-1684...
There's a bit of a jump here from something appearing good to rapidly becoming very very bad. Here's what I read:
> 1Password has pledged $300,000 over three years in support of David Heinemeier Hansson's Linux distribution known as Omarchy, and is now a “distinguished corporate patron” of Omacom. What a nice brand partnership.
Supporting a Linux distribution sounds nice; I hadn't heard of that one.
But the very next paragraph:
> DHH has called for the ethnic cleansing of Europe; he is also an antivaxer, a Covid "truther," a proponent of the "lab leak" conspiracy theory, an 'anti woke' weirdo, and is virulently anti-DEI
> In an internal Slack message leaked to press today 1Password’s Roustem Karimov defended DHH as being attacked for his views...
Perhaps they could support a different Linux distribution.
It's also strongly concerning when someone defends someone with views like that, characterising them as being attacked. In general, toxic, racist, fascist views spread like viruses; when tolerated, through acceptance, they grow. A company needs to root them out. If we trust 1Password with our data, we are trusting a company with those views inside it with our data.
I really enjoy Proton Pass (but I have a paid subscription so I have passmail aliasses as well). I've been going full passkeys recently, no issues yet.
Before this I used Vaultwarden, but I was always a bit afraid of the self-hosting (of something this critical), and I really didn't like how you share credentials in BitWarden (through organizations), Proton Pass is much more intuitive with just straight up sharing of credentials or sharing whole Vaults. You can also share through public 1-time visit, limited time valid-urls. I use that a lot when I set up people's accounts.
What I don't like is the tight coupling to Proton's services, Pass should have had it's own credentials. But if you're not a Proton user that doesn't matter (or perhaps it doesn't matter t you in any case.)