Quantcast
Channel: PasswordWallet – Michael Tsai
Viewing all articles
Browse latest Browse all 11

1Password Standalone Vaults and PasswordWallet

$
0
0

Dave Teare:

Now the thing is, I know it’s not realistic to expect everyone to be able to be able to join one of our memberships at this time. As great as 1Password memberships are, I know that our excitement for them can cause some people to become worried. After all, many have corporate policies or regional restrictions that prevent them from using a hosted solution like ours, and so they’re understandably concerned and want to know that there’s a future for them with 1Password.

These worries are compounded by the fact that 1Password 6 for Windows was designed from the ground up to support 1Password Teams customers only (and then later expanded to include family and individual plans), and we are unsure how this adventure will play out on the Windows side of the world, so we haven’t made any public announcements about when support for standalone vaults will be added, if ever. Many Mac users worry that the same fate awaits 1Password 6 for Mac, and that we will remove support for local vaults and force them to pay again.

[…]

We know that not everyone is ready to make the jump yet, and as such, we will continue to support customers who are managing their own standalone vaults. 1Password 6 and even 1Password 7 will continue to support standalone vaults. But 1Password memberships are indeed awesome and are the best way to use 1Password, and as such, I am going to continue to nudge you over when ever I can 🙂

This partial commitment is nice to hear, although it would have been nicer a few days ago when I asked about support for standalone vaults beyond version 6 and the response was:

I know it’s not the answer you want, but we will never publicly commit to Dropbox, iCloud, or local vaults for the future. Even if we bring local vaults forward in a hypothetical new version of 1Password which does not yet exist, that’s not to say that the subsequent version will continue that[…]

They seemed to be trying to thread a needle by specifically not promising continued support for local vaults, conflating this with not commenting on future product directions in general and the idea that all software eventually breaks, and then saying there was nothing to worry about because they have no plans to actively remove the feature. Reading between the lines, the strong implication was that they wanted at least the option to go cloud-only in version 7 without going back on their word.

I took this as a signal to start looking at other options, because the centralized cloud model, while very convenient for most customers and for AgileBits’ support people, seems inherently less secure to me and won’t work with Little Snitch blocking all network access. Additionally, it doesn’t work with 1PasswordAnywhere, doesn’t work with 1Password’s local backup feature, and maintains only a partial local cache (attachments not guaranteed).

So, by the time of Teare’s announcement, I had already investigated some alternatives, selected PasswordWallet (based in part on a recommendation from Wolf Rentzsch), and converted one of my vaults.

(Sidenote: During this process I learned that 1Password’s CSV export—with “All Fields” selected—does not actually export all of the fields, and that the 1PIF export format is undocumented. So migrating my nearly 2,000 entries would have been impractical if I hadn’t been able to write some code to massage the JSON-like 1PIF into a format suitable for PasswordWallet’s CSV/TSV importer. I feel stupid for having taken the time a few years ago to manually move my data from 1Password’s Notes field into custom fields/sections.)

For the near term, I will likely use a mixed setup. My main vault is in PasswordWallet, and I see no reason to convert it back. We also have a successful family setup that syncs multiple 1Password vaults via Dropbox, and that now seems like it should keep working for at least a few years. 1Password and PasswordWallet are both good apps, and I hope that both will be successful long into the future.

With that in mind, here are some advantages that I see with PasswordWallet:

  • There’s an automatic, encrypted HTML export that’s fully supported and more secure than the discontinued 1PasswordAnywhere in that the metadata is encrypted, too.

  • It’s just a regular app: standard document model, no browser extensions or daemons, regular text fields instead of Contacts-style ones.

  • The auto-typing feature is in some ways better than 1Password’s browser extensions because it can work with multi-page login sequences and varying Web forms. For example, it’s easy to enter both a credit card number and the CVV into an order page that the app has never seen before. This always took multiple steps with 1Password. Auto-typing also works in places that browser extensions and even Edit > Paste don’t, such as macOS’s secure text fields for opening disk images and unlocking keychains.

  • I like the model of having unlimited custom categories better than 1Password’s fixed categories combined with folders. In practice, nearly all my 1Password items were in Logins or Software Licenses, and folders were hard to use because they weren’t shown in the list view. There are also keyboard shortcuts to switch directly to a particular category.

  • Multiple entries can be linked to share the same username and password. For example, I can have one entry that opens Radar and one that opens iTunes Connect, but I only have to update one when I change my password. 1Password supports multiple URLs for the same entry, but that’s less useful when opening URLs from the app itself because you have to first search, then find the right link to click.

  • Along the same bookmark-manager lines, PasswordWallet lets you specify, per-entry, which Web browser it should use to open links.

  • The interface is much more compact, with more pixels devoted to useful information that I care about.

  • You can have multiple items open simultaneously in different windows.

And some things I prefer about 1Password:

  • The interface is much more visually attractive, and the menu structure and commands work in a more standard way.

  • It supports file attachments and one-time passwords. My attachments are now in OmniOutliner, which now has built-in encryption. I continue to use 1Password for OTPs.

  • It supports custom fields, which I initially loved, though I now wonder whether I would use them again given that they make migration more difficult. I have already migrated from WebConfidential to OmniOutliner to 1Password in the past, and I’ll likely have to do so again, eventually.

  • When it works, the browser-extension-based auto-filling is faster than watching PasswordWallet auto-type individual characters.

  • You can search within a folder. PasswordWallet makes you choose between searching for a category and searching all the entries for text. You can’t do both at once.

  • 1Password supports favorites and smart folders, which are occasionally very useful.

  • There’s a hotkey for searching it from another app, which is better than jerry-rigging something with LaunchBar or a script.

  • The multi-pane design is in some cases better than having to choose between a sheet and a separate window.

  • [Update (2017-08-21): It supports word searches.]

Update (2017-07-16): See also: Rui Carmo.

Rene Ritchie:

To put it bluntly, AgileBits is moving to a more sustainable business model that will allow them to better develop and support 1Password now and into the future.

[…]

So, if you’re already a 1Password user, avoid all the FUD and take your own hard look at the new direction.

I tend to agree that subscriptions make their business more sustainable, so it’s interesting that Teare seems to deny that:

Please don’t think our excitement for memberships has anything to do with money. […] We were doing just fine selling individual licenses and AgileBits was already steadily growing before 1Password Teams was even introduced. We created 1Password Memberships because we had a vision for how 1Password could be even better and we followed our dreams. The result has been stupendously awesome and better than our wildest dreams! Today, over 95% of our revenues are coming from subscribers, which is truly mind blowing.

When you look at that 95% statistic and this comment from AGKyle a year ago:

That said, we don’t have any immediate plans to remove the standalone products. However, if a vast majority of our users switch to 1Password Family or 1Password Teams (and as of today, an Individual plan!) then it doesn’t make a ton of sense to keep the standalone product around. So, it’s probably one of those speak with your wallet kind of scenarios.

it makes perfect sense why they were reluctant to commit to supporting standalone vaults in version 7. They also made it really hard to “speak with your wallet” because in the last year there was no paid upgrade, and they removed the standalone version from their store. And they rewrote the Windows version of the app without support for local vaults (yet).

A lot of people are throwing around accusations of FUD, but it seems to me that the source of the uncertainty was AgileBits itself: actions like these and public statements from employees such as Kyle. I see Teare’s post not as a “correction” of misinformation but as an actual policy change. Before, they implied that standalone might be dropped and refused to commit to it. Now they’ve committed for at least one more version.

Update (2017-07-20): Tim Bray:

I understand, and I support AgileBits wanting to become a subscription biz. But I still want to keep my data and password away from their servers. This all seems fine to me. I pay my monthly rent to Adobe and it’s for Lightroom & Photoshop, not for their unexciting server-side offerings.

So AgileBits, why not? Please go ahead and start asking for subscriptions. But don’t ask paranoid people like me to go anywhere near 1Password.com.

AgileBits has addressed the situation in Why We Love 1Password Memberships, but it’s really unsatisfying, totally ignoring the security concerns. And (I guess I shouldn’t be surprised) failing to acknowledge the business advantages for them in making this move.

Update (2017-08-02): AgileBits:

With this release, we finally have enough visibility to chart a course for the future, so we’re happy to announce that standalone vaults will be back on the menu in 1Password 7 for Windows. 1Password 7 will be free with your 1Password membership, but if memberships aren’t for you, paid licenses will also be available.


Viewing all articles
Browse latest Browse all 11

Trending Articles