Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
i just accidentally changed my facebook pw without saving it to 1p so i had to reset it. they just happily emailed me a reset link which worked without requiring my totp or a recovery otp (and i was logged out at the time).

so what's even the point? might as well keep this poo poo in a text file if all anyone needs is access to my email account

this is why i keep my email account out of my pw managers

Adbot
ADBOT LOVES YOU

Armauk
Jun 23, 2021


Cold on a Cob posted:

i just accidentally changed my facebook pw without saving it to 1p so i had to reset it. they just happily emailed me a reset link which worked without requiring my totp or a recovery otp (and i was logged out at the time).

so what's even the point? might as well keep this poo poo in a text file if all anyone needs is access to my email account

this is why i keep my email account out of my pw managers

Solve multiple problems at once and delete your Facebook account.

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

Armauk posted:

Solve multiple problems at once and delete your Facebook account.

wish i could my dude. wish i could.

upon further evaluation, 1pass is proving to be really lovely at handling password changes. it's not saving my changes from browser to vault properly and i've had to reset twice now and it would have been more if i hadn't been copying my passwords into keepass as i go. loving lame.

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
at least EA made me use my totp after i reset my password

christ, first fb then ea i think 1pass is actually trying to do me a solid by not updating these new passwords

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
i have deleted around 50 accounts, it loving owns

just forget i ever existed, thx

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
ok i did a thorough evaluation of 1password and here are my thoughts

Pros:
  1. Good looking app.
  2. Categories are good and it's nice having templates for different types of entries
  3. Favourites and tags are also useful. I'd love folders too but most PWMs use one or the other vOv.
  4. Multiple TOTP and passwords and websites per entry is very useful. I can basically map my domain creds at work to one entry, add all my totps, etc. (Yes I give no fucks about my work creds lol)
  5. Watchtower works really well - it's nice to know if my passwords suck or were pwned or if 2fa is available, etc.
  6. Sharing passwords with family is extremely useful - we do have shared accounts for things like food delivery so it's nice.
  7. Works well with iOS password integration (I really wish windows would implement something like this so i wouldn't have to gently caress around with browser extensions).
  8. Separate Archive and Delete features are useful. You can archive old passwords you think you'll never use but can't delete, for example.
  9. Browser integration for login works really, really well. Out of ~75 websites I tried, it had trouble with 1.

Cons:
  1. Browser integration will not work for password updates - it generates a password, I apply it, but nothing is saved. Maybe a bug tbh? pebkac? Idk
  2. File attachments loving sucks. Documents are their own entry type and you can only attach one file per document.
  3. I would love more types of categories - ssh, ftp, etc. This is also why I want to attach files to entries!
  4. Turning off watchtower for certain entries only works with tags and only for http and 2fa. If you have a weak password you don't control (like my library pin) you can set it to ignore; instead you have to put the "password" in a non-primary password field and name it something like PIN so watchtower will ignore it.
  5. Import only really imports logins and maybe secure notes. No mass importing of files, api credentials, software licenses, etc.
  6. Searching sucks - it's pretty basic, it lets you search titles, tags, usernames, passwords, but if you want to see which entries have otp setup (for example) good luck. Want to search by date? Lol. No.
  7. The windows app (v7) is kinda janky. It refreshes a lot in weird ways and when I save an entry it is no longer selected. Right clicking and applying tags and such is janky too. I expected more polish than this.
  8. No multi-line "password" fields - useful for structured data you want to not just show when an entry is displayed, like a list of recovery keys.
  9. Small con but Watchtower doesn't let me specify a minimum password strength to evaluate my passwords.
  10. Closed source
  11. Many of these cons people have been asking the developers to fix/improve for YEARS with no promise or roadmap or anything

AnimeIsTrash
Jun 30, 2018

I like using keepass.

Sagebrush
Feb 26, 2012

keep rear end.

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
i had 1password maximized and i right clicked an entry and selected edit and it un-maximized the window

i tried this multiple times and it keeps doing it

lol

Agile Vector
May 21, 2007

scrum bored



Cold on a Cob posted:

  1. Browser integration will not work for password updates - it generates a password, I apply it, but nothing is saved. Maybe a bug tbh? pebkac? Idk

might be a sync delay if the plug-in is 1password x, which is the full standalone browser plug-in version, not the full install extension version. the names are confusing, and i believe x has better in-field visual integration that is inexplicably not let of the other extension, though i swear it was before x was an option

SO DEMANDING
Dec 27, 2003

Cold on a Cob posted:

ok i did a thorough evaluation of 1password and here are my thoughts

Pros:
  1. Good looking app.
  2. Categories are good and it's nice having templates for different types of entries
  3. Favourites and tags are also useful. I'd love folders too but most PWMs use one or the other vOv.
  4. Multiple TOTP and passwords and websites per entry is very useful. I can basically map my domain creds at work to one entry, add all my totps, etc. (Yes I give no fucks about my work creds lol)
  5. Watchtower works really well - it's nice to know if my passwords suck or were pwned or if 2fa is available, etc.
  6. Sharing passwords with family is extremely useful - we do have shared accounts for things like food delivery so it's nice.
  7. Works well with iOS password integration (I really wish windows would implement something like this so i wouldn't have to gently caress around with browser extensions).
  8. Separate Archive and Delete features are useful. You can archive old passwords you think you'll never use but can't delete, for example.
  9. Browser integration for login works really, really well. Out of ~75 websites I tried, it had trouble with 1.

Cons:
  1. Browser integration will not work for password updates - it generates a password, I apply it, but nothing is saved. Maybe a bug tbh? pebkac? Idk
  2. File attachments loving sucks. Documents are their own entry type and you can only attach one file per document.
  3. I would love more types of categories - ssh, ftp, etc. This is also why I want to attach files to entries!
  4. Turning off watchtower for certain entries only works with tags and only for http and 2fa. If you have a weak password you don't control (like my library pin) you can set it to ignore; instead you have to put the "password" in a non-primary password field and name it something like PIN so watchtower will ignore it.
  5. Import only really imports logins and maybe secure notes. No mass importing of files, api credentials, software licenses, etc.
  6. Searching sucks - it's pretty basic, it lets you search titles, tags, usernames, passwords, but if you want to see which entries have otp setup (for example) good luck. Want to search by date? Lol. No.
  7. The windows app (v7) is kinda janky. It refreshes a lot in weird ways and when I save an entry it is no longer selected. Right clicking and applying tags and such is janky too. I expected more polish than this.
  8. No multi-line "password" fields - useful for structured data you want to not just show when an entry is displayed, like a list of recovery keys.
  9. Small con but Watchtower doesn't let me specify a minimum password strength to evaluate my passwords.
  10. Closed source
  11. Many of these cons people have been asking the developers to fix/improve for YEARS with no promise or roadmap or anything

youre holding it wrong

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

Agile Vector posted:

might be a sync delay if the plug-in is 1password x, which is the full standalone browser plug-in version, not the full install extension version. the names are confusing, and i believe x has better in-field visual integration that is inexplicably not let of the other extension, though i swear it was before x was an option

i installed from the crhome store. anyhow i gave up, the other cons are too much to overcome for me. i've also figured out better ways to get around some of my annoyances in keep rear end so i'm gonna stick w/ it.

Agile Vector
May 21, 2007

scrum bored



SO DEMANDING posted:

youre holding it wrong

the windows client is indeed wonky. things like entering a year works as a search string on ios but doesn't in windows. it was always the less updated client but lol

wait, maybe they merged the two extensions? i just looked and yeah, the default direction they pointed me for chromium browsers looks like x minus the name. x was a full client for chrome for use on any os that didn't have a full installable app

the date search also works there. they should just burn the windows client down and stick the extension in a stand alone app for management and use

RoastBeef
Jul 11, 2008


I'm still using PasswordSafe :shrug: it's needs suiting and the android app/keyboard thing works pretty well.

Cybernetic Vermin
Apr 18, 2005

i am very thankful for microsoft authenticator, which i was already using, launching into the password managing business. finally forced me to stop putting off using one. though i suspect it is pretty far from the best option i am pretty sure it is way better than my natural state of just using a lot of bad passwords.

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Agile Vector posted:

might be a sync delay if the plug-in is 1password x, which is the full standalone browser plug-in version, not the full install extension version. the names are confusing, and i believe x has better in-field visual integration that is inexplicably not let of the other extension, though i swear it was before x was an option

x is gone, its just “1Password” now and the old plugin is called “1Password Classic”.

there’s also an option for the plugin to also connect to the app directly

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

Cybernetic Vermin posted:

i am very thankful for microsoft authenticator, which i was already using, launching into the password managing business. finally forced me to stop putting off using one. though i suspect it is pretty far from the best option i am pretty sure it is way better than my natural state of just using a lot of bad passwords.

yeah that's like bottom of the "good pwm practices hierarchy" that i did years ago too

i'm finally, ityool 2021, done cleaning up my mess of old passwords that all followed the pattern {MixedCasePassphraseAndFavouriteNumber}{NameOfService}{ExclamationIfSymbolRequired}

{MixedCasePassphraseAndFavouriteNumber} is very much in the haveibeenpwned db even though it was a random thing i just reused everywhere because of numerous breaches over the years

Agile Vector
May 21, 2007

scrum bored



CRIP EATIN BREAD posted:

x is gone, its just “1Password” now and the old plugin is called “1Password Classic”.

there’s also an option for the plugin to also connect to the app directly

that makes so much more sense and is way less confusing, it's such a better choice to combo them

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

Cold on a Cob posted:

yeah that's like bottom of the "good pwm practices hierarchy" that i did years ago too

i'm finally, ityool 2021, done cleaning up my mess of old passwords that all followed the pattern {MixedCasePassphraseAndFavouriteNumber}{NameOfService}{ExclamationIfSymbolRequired}

{MixedCasePassphraseAndFavouriteNumber} is very much in the haveibeenpwned db even though it was a random thing i just reused everywhere because of numerous breaches over the years

i'm adding this pattern to my auto exploiter scripts

AnimeIsTrash
Jun 30, 2018

Sagebrush posted:

keep rear end.

I keep my asses close, that's why I post in the same threads as you.

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Agile Vector posted:

that makes so much more sense and is way less confusing, it's such a better choice to combo them

yeah i think they merged them relatively recently once they considered the all-in-one to be "stable".

you had to download the plugin manually from the 1password site for ages.

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
well it didn’t work for me

logging into things was fine, updating passwords was not. i was pretty careful after the first time it hosed up to account for pebcak too

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
what browser?

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
chrome

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
i had the desktop client open at the same time (but notably i was NOT changing data in the desktop client) so maybe sync shenanigans from it auto-saving? idk. i was annoyed enough i didn't check the history on the entry in question.

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
in any case, i'm going ot assume the weirdness i ran into is just something to do with me. maybe reinstalling everything would have fixed, idk. i have friends who use 1pass who are very happy but they also get to live entirely using macs and/or linux, unfortunately i have to use windows too so keepassxc for me vOv

i might give bitwarden one more try b/c shared credentials are still something keepassxc is real bad at, but going to give it a few weeks i think.

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
a goon friend has informed me that 1password 8 is a shitload better than 7.7

https://blog.1password.com/1password-8-for-windows-is-now-in-early-access/

i'm gonna give it a spin and report back

Agile Vector
May 21, 2007

scrum bored



i'm eagerly looking forward to that report and want to try it too. that looks like the best of the macOS and iOS clients with further UI/UX improvements on those designs, and the rust codebase sounds like maybe they tossed all the old cruft from 7, which itself was a big step from the old 4 codebase

PIZZA.BAT
Nov 12, 2016


:cheers:


yeah i'm still on 1pass 4. once i saw they were going the route of forcing subscriptions on people i disabled auto-updates and i've been coasting for years on this without too many issues

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
good:
- jank is gone. editing screen is a lot less busy but still has everything you need. it looks really good too.
- i can attach multiple files to any entry
- it has a quick way to generate fake security question/answers, which i didn't really play with much but it's there.
- dark mode added
- low memory footprint, very responsive
- watchtower is nicer. the new password strength graph is sweet and all results are condensed into one page now.
- i like the integration of categories at the top of the list, makes the sidebar less busy

still missing or newly broken (keeping in mind it's early access!! so some of this may be unfinished/coming back/etc - hard to say b/c no road map or public plans):
- no change to searching and it still sucks. in fact i think they made it worse, i can no longer type in "tag:" to find all untagged items.
- can no longer add/remove tags with a right-click - hopefully they'll bring this back
- still no multi-line/note style obfuscated fields
- watchtower still lacks ability to customize it a bit or turn it off for certain items short of using special tags for some things.
- still closed source but vOv
- forgot to mention before but i want auto-type capability as well, but i understand it's not high priority for them and honestly i'd use it for maybe three apps, only one of which i use daily
- no new categories and still can't create "custom" categories
- still no roadmap? idk maybe idk where to look but it would be nice :shobon:
- created a new vault but it didn't appear until i closed and re-opened the application vOv weird random bug

i didn't re-test browser integration
i also didn't re-test importing data

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

PIZZA.BAT posted:

yeah i'm still on 1pass 4. once i saw they were going the route of forcing subscriptions on people i disabled auto-updates and i've been coasting for years on this without too many issues

i'm still running you need a budget 4 for this exact reason

Last Chance
Dec 31, 2004

is it a good idea to use an old version of a password manager? doesnt seem like a good idea to me

Weaponized Autism
Mar 26, 2006

All aboard the Gravy train!
Hair Elf
personal: firefox, keepassxc

at work: https://www.usefulsoft.com/network-password-manager/ , boss hadn't upgraded it in over 10 years so got to get done as a mini-project

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
oh i didnt even realize they released a stand-alone 1password app for linux

cool

Agile Vector
May 21, 2007

scrum bored



PIZZA.BAT posted:

yeah i'm still on 1pass 4. once i saw they were going the route of forcing subscriptions on people i disabled auto-updates and i've been coasting for years on this without too many issues

I was doing that until the client on other platforms got too out of sync and I got tired of trying to work around 4. if you can swing it, that's a good setup, tbh

Cold on a Cob posted:

good:
- jank is gone. editing screen is a lot less busy but still has everything you need. it looks really good too.
- i can attach multiple files to any entry
- it has a quick way to generate fake security question/answers, which i didn't really play with much but it's there.
- dark mode added
- low memory footprint, very responsive
- watchtower is nicer. the new password strength graph is sweet and all results are condensed into one page now.
- i like the integration of categories at the top of the list, makes the sidebar less busy

still missing or newly broken (keeping in mind it's early access!! so some of this may be unfinished/coming back/etc - hard to say b/c no road map or public plans):
- no change to searching and it still sucks. in fact i think they made it worse, i can no longer type in "tag:" to find all untagged items.
- can no longer add/remove tags with a right-click - hopefully they'll bring this back
- still no multi-line/note style obfuscated fields
- watchtower still lacks ability to customize it a bit or turn it off for certain items short of using special tags for some things.
- still closed source but vOv
- forgot to mention before but i want auto-type capability as well, but i understand it's not high priority for them and honestly i'd use it for maybe three apps, only one of which i use daily
- no new categories and still can't create "custom" categories
- still no roadmap? idk maybe idk where to look but it would be nice :shobon:
- created a new vault but it didn't appear until i closed and re-opened the application vOv weird random bug

i didn't re-test browser integration
i also didn't re-test importing data

I grabbed it too and the search not getting date of creation or change is still annoying me. it such a tiny inconsistency when so much of the experience took a step forward everywhere else

the browser integration seems better, but maybe it's because I was using classic and not the new standard (x) version. I like the new watchtower view as well, but there's always some entries, like "unsecured urls" that point to my local printer's settings for example that will never be https, that i want some way of telling it to ignore them

Silver Alicorn
Mar 30, 2008

𝓪 𝓻𝓮𝓭 𝓹𝓪𝓷𝓭𝓪 𝓲𝓼 𝓪 𝓬𝓾𝓻𝓲𝓸𝓾𝓼 𝓼𝓸𝓻𝓽 𝓸𝓯 𝓬𝓻𝓮𝓪𝓽𝓾𝓻𝓮
turns out my org provides a lastpass account. thanks org

Agile Vector
May 21, 2007

scrum bored



okay, so my homebridge had a lazy password and i used the rc 1p v8 extension to change it, it spotted the new password fields fine with a nice update view and that synced to the app instantly which removed the entry from watchtower and (a bit annoyingly) reset me to the main view because it wasn't flagged anymore

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

Agile Vector posted:

the browser integration seems better, but maybe it's because I was using classic and not the new standard (x) version. I like the new watchtower view as well, but there's always some entries, like "unsecured urls" that point to my local printer's settings for example that will never be https, that i want some way of telling it to ignore them

give it an 'http' tag and it should exclude it

you can also give '2fa' tags to things you don't give a poo poo about adding 2fa to or just plain can't, like most wikipedia users

Agile Vector posted:

that synced to the app instantly which removed the entry from watchtower and (a bit annoyingly) reset me to the main view because it wasn't flagged anymore

yeah this was driving me nuts too

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
fwiw i'm also loving around trying to get keepassxc syncing nicely between work pc, home pc, and ios and results are.... meh. i've already had one sync conflict. i think it's b/c keepassium doesn't work like keepassxc with constant saving and reloading, which is probably good for battery life and bad for keeping poo poo in sync vOv

edit: i'm using dropbox to do the sync b/c i don't use it at all for anything else except syncing a few config files between work and home.

Adbot
ADBOT LOVES YOU

FCKGW
May 21, 2006

1Password took a few mill of VC cash a couple years ago and I was kinda worried but seems like they’ve at least put it to good use and gone into overdrive with development. good poo poo.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply