You have better alternatives: bitwarden for those looking for a cloud solution, keepassXC who prefer to keep the data under their own control. Plus, they are both free/libre.
I always had issues with KeepassXC. mostly as a concept, I'm not sure if it made sense, but since we're talking about it, how do you cope with the concept that if you lose your phone with the database on it, an attacker can just keep a perpetual copy of your passwords free to brute force and do whatever they wanted? I can revoke access to things with cloud services or self-hosted services, but with all the database in the hand of an attacker he can try to break it indefinitely and undisturbed.. I think KeepassXC for this reason is the worst among cloud hosted and self-hosted solutions
AFAIK, the filesystem is encrypted on any modern device. An attacker would have to first break into the device and then break into the password database. And if they can break into the device it is game over already.
Also, the attacker would have to be really motivated to brute force into it, and if it happened that my phone got stolen and I was worried about your scenario, I'd be just rotating all the high-value passwords I have, which is something that I think can be done quickly.
I've tried Bitwarden, pass, and KeepassXC in the past. 1password is by far the most polished. If you consider how big the problem space is (interoperating with every possible broken website out there), support for TouchID/Apple Watch unlock, etc I think I'll take it over having access to the source I will never read.
It's not about what you reading it, it's about ensuring that someone else can do it.
Anyway, I hate to be Cassandra, I just lost count of how many stories I heard of people regretting taking "convenience over freedom" with critical software.
It's not about what you reading it, it's about ensuring that someone else can do it.
I fully agree with you on this one. However being free/libre doesn't mean that that "someone" will actually fix your problem. I've been a software developer/hacker/OSS enthusiast for close to two decades, but I'm mighty tired of 1. software that's impossible for me to fix myself, 2. its authors who don't care enough about my problem.
I've had one minor issue with 1password and I was blown away with how good their support was. They followed very good OpSec while not appearing intimidating to what they didn't know wasn't a non-technical user, they solved the problem on the spot, and they gave me a few months free to compensate for the inconvenience. At the same time, I've currently lost track of how many random Github issues I'm subscribed to, with some going on unsolved for years.
Being free/libre is just one dimension, orthogonal to other qualities software might have. These other qualities include simplicity/hackability, cost, usability, convenience, support, security, accessibility, respect for your time, ethical/mindful design, and many others. It's OK to choose your own trade-offs.
I just lost count of how many stories I heard of people regretting taking "convenience over freedom" with critical software.
All online vaults remain available offline; the client allows a full export, including in plain old CSV. Bitwarden has builtin import functionality; or I can write a few lines of code and put it in pass. Worst case scenario, 1password going fully evil and pushing a silent client update to lock me out? I go offline, restore the app+vault from a backup, and export. It very firmly fits into the category of "problems I can fix myself".
Fair point. I feel like adequately funding free software development is a larger unsolved problem, that's a bit beyond the scope of a forum thread.
Anecdotally, I like what the developer of Blink Shell[0] has done. The app is 100% free software[1] under GPL3, so you can easily build it yourself with XCode, upload to your phone, and use as usual from there, which isn't a big hurdle for the target audience. But I bought it. At the time IIRC it costed 20 bucks on the App Store. I bought it because it was incredibly frictionless to pay the money (Apple is good at that), and it felt good to support the developer of a tool I liked and used.
So it leaves me wondering, where are the big obstacles. All other things being equal, I will choose a free/libre solution, but we know things are far from equal.
Comments
You have better alternatives: bitwarden for those looking for a cloud solution, keepassXC who prefer to keep the data under their own control. Plus, they are both free/libre.
I always had issues with KeepassXC. mostly as a concept, I'm not sure if it made sense, but since we're talking about it, how do you cope with the concept that if you lose your phone with the database on it, an attacker can just keep a perpetual copy of your passwords free to brute force and do whatever they wanted? I can revoke access to things with cloud services or self-hosted services, but with all the database in the hand of an attacker he can try to break it indefinitely and undisturbed.. I think KeepassXC for this reason is the worst among cloud hosted and self-hosted solutions
AFAIK, the filesystem is encrypted on any modern device. An attacker would have to first break into the device and then break into the password database. And if they can break into the device it is game over already.
Also, the attacker would have to be really motivated to brute force into it, and if it happened that my phone got stolen and I was worried about your scenario, I'd be just rotating all the high-value passwords I have, which is something that I think can be done quickly.
I've tried Bitwarden, pass, and KeepassXC in the past. 1password is by far the most polished. If you consider how big the problem space is (interoperating with every possible broken website out there), support for TouchID/Apple Watch unlock, etc I think I'll take it over having access to the source I will never read.
It's not about what you reading it, it's about ensuring that someone else can do it.
Anyway, I hate to be Cassandra, I just lost count of how many stories I heard of people regretting taking "convenience over freedom" with critical software.
I fully agree with you on this one. However being free/libre doesn't mean that that "someone" will actually fix your problem. I've been a software developer/hacker/OSS enthusiast for close to two decades, but I'm mighty tired of 1. software that's impossible for me to fix myself, 2. its authors who don't care enough about my problem.
I've had one minor issue with 1password and I was blown away with how good their support was. They followed very good OpSec while not appearing intimidating to what they didn't know wasn't a non-technical user, they solved the problem on the spot, and they gave me a few months free to compensate for the inconvenience. At the same time, I've currently lost track of how many random Github issues I'm subscribed to, with some going on unsolved for years.
Being free/libre is just one dimension, orthogonal to other qualities software might have. These other qualities include simplicity/hackability, cost, usability, convenience, support, security, accessibility, respect for your time, ethical/mindful design, and many others. It's OK to choose your own trade-offs.
All online vaults remain available offline; the client allows a full export, including in plain old CSV. Bitwarden has builtin import functionality; or I can write a few lines of code and put it in pass. Worst case scenario, 1password going fully evil and pushing a silent client update to lock me out? I go offline, restore the app+vault from a backup, and export. It very firmly fits into the category of "problems I can fix myself".
Have you offered to pay them anything? At least a good fraction of what you pay to the proprietary alternative?
Fair point. I feel like adequately funding free software development is a larger unsolved problem, that's a bit beyond the scope of a forum thread.
Anecdotally, I like what the developer of Blink Shell[0] has done. The app is 100% free software[1] under GPL3, so you can easily build it yourself with XCode, upload to your phone, and use as usual from there, which isn't a big hurdle for the target audience. But I bought it. At the time IIRC it costed 20 bucks on the App Store. I bought it because it was incredibly frictionless to pay the money (Apple is good at that), and it felt good to support the developer of a tool I liked and used.
So it leaves me wondering, where are the big obstacles. All other things being equal, I will choose a free/libre solution, but we know things are far from equal.
[0]: https://blink.sh [1]: https://github.com/blinksh/blink
Would you please take a look at https://news.ycombinator.com/item?id=31296803 and share your thoughts?
I have a lot of thoughts on this but I'm not comfortable sharing some of it in public. Can you shoot me an email? kamil@rollc.at