“People always just post when they're unhappy about something, so I just wanted to take the time to post that I think 1Password did a good thing with the new "universal sign-in".”
“I have no clue what 1Password’s interest in it is. (When I retired three years ago, Debian was the preferred distro at 1Password, at least among developers.) But 1Password does contribute upstream to open source projects.”
“no, 1Password isn’t vacuuming up the user’s Chrome passwords or browsing history, but the real risk is that a shared Google login makes activity and account recovery messy because everyone is”
“yeah, that sounds like an autofill limitation rather than a vault setup issue, but has 1Password said whether ChatGPT Work is getting a proper integration or is this entirely on OpenAI’s side?”
“I'm not sure when this started, but lately whenever I log into a site that uses SMS-based OTP codes for MFA, 1Password tries to autofill its own stored OTP instead of letting me use the code that arrives in Messages.”
“@thsottiaux A feature where you can approve it from your phone when Codex on desktop requests secret access from 1Password. I should probably tell 1Password...”
“I tested ChatGPT Work’s new secure website sign-in on Android with 1Password set as my default autofill provider. Everything is configured correctly, but the process was extremely manual.”
“Hi, my nintendo account is set up with passkey login via 1password. When I try to authenticate (on win 10) a window pops up for half a second and immediately closes.”
“can someone help, more than 50% of the time i get a "error" when saving a passkey via chrome. this is relatively new issue call it over last month. is it something i'm doing or are there 1password errors”
“As someone who’s migrated off Dashlane I would say that 1password and bitwarden definitely have better security. Dashlane was recently hacked and while I know that the data was encrypted and hackers only stole some encrypted info that alone is concerning.”
“A synced (exportable, backup-eligible) passkey is literally designed to be exported and potentially shared, so copying it does not "completely defeat the point."”
“That's just one of the many reasons I set short timeouts for both my Mac/iPhone lock screen and 1Password itself. I want to minimize the chance that someone can get into things if they happen to acquire physical access to my devices.”
“Turned on the new macos universal autofill update and now I get this browser popup asking that I enter my computer password to allow the 1Password browser extension to use the passkey for a website even though 1Password on the computer and in the browser is unlocked??? So frustrating.”
“Bitwarden is $20/year vs. $36 for 1Password Individual. For how I use it, I have a hard time justifying paying almost twice as much for 1Password. And the best part about Bitwarden is the robust free tier.”
“Both are solid options. If you already have 1Password, try out the free version of Bitwarden with an export from 1password and see what you like better.”
“I use both and unless you just hate 1Password, I'd stick with it. I find it to generally just be more polished but it sounds like I may use more of the features than you.”
“On the Secret Key: there's no exact equivalent in Bitwarden, and it's worth being upfront about that instead of glossing over it. In 1Password, your vault is encrypted with master password + Secret Key (34 chars, high entropy, never leaves your devices).”
“And it’s somehow 1Password’s fault that in that situation your data is at risk? Whatever nonsense you’re using to drag passkeys into the discussion is irrelevant; if your unlocked vault ends up in the hands of an adversary, all bets are off, period.”
“While figuring out how to set up credential management for AI, I discovered 1Password CLI, and it terrifies me how it requires giving full account access for 10 minutes to the entire terminal!”
“If someone gets a hold of your unlocked 1Password vault, all bets are off even if it's a passkey. Passkeys can't yet be exported to a file, because 1Password are being very specific about not wanting them left on disk unprotected.”
“You have to both install and explicitly enable the 1Password CLI, both steps no “normal” user is going to take unless socially engineered to.https://www.1password.dev/cli/get-startedAnd getting secrets using it requires explicit authentication with password/fingerprint/etc (I forget if it’s per item or per process, but still).”
“Why is there no biometric prompt before generating a link, or at least a setting to strip the passkey when sharing? Letting anyone copy a private key out like this completely defeats the point.”
“That tiny shell script is the -minimum- security any password manager must have.I get that most major password managers like 1password and lastpass also get this wrong. I submit with a straight face that they have never let any capable security engineers near their products. They have a negligent design end to end and must not be replicated.”
“I just got an app update for 1Password and everything is back to normal. Seems like restarting the app might have fixed it previously. Thanks for trying to assist.”
“Starting around 2 weeks ago on both 1Password Stable and Dev, Proxmox has started to fail to login with 1Password. It will just ask for the 2fa again and again till you try for the 2nd or third try, then it works, but it leaves the window up that asked you to input the 2FA, which can just be closed.”
“For personal needs I use 1password, but in my previous jobs I had to use bitwarden and nordpass. All three are good options, I don't think there's particularly a big difference between them all, so choose the one that you like the best.”