66 votes

1Password wades into a right-wing mess after funding a Linux project

51 comments

  1. [39]
    DefiantEmbassy
    Link
    (Apologies if this is better in ~tech, the political side of things made me err on putting it here) Very disappointed in 1Password, and seemingly the rot is not just a single VP, but the entire...

    (Apologies if this is better in ~tech, the political side of things made me err on putting it here)

    Very disappointed in 1Password, and seemingly the rot is not just a single VP, but the entire leadership team. Time to move to Bitwarden.

    17 votes
    1. [36]
      regularmother
      Link Parent
      Bitwarden got bought by private equity and is becoming enshittified - https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden I cannot recommend them going forward.

      Bitwarden got bought by private equity and is becoming enshittified - https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden I cannot recommend them going forward.

      22 votes
      1. [23]
        DefiantEmbassy
        Link Parent
        The market for hosted consumer password managers isn’t fun… LastPass is obviously so bad it would be irresponsible to use the them. Proton Pass, well, Proton also has questionable leadership....

        The market for hosted consumer password managers isn’t fun…

        • LastPass is obviously so bad it would be irresponsible to use the them.
        • Proton Pass, well, Proton also has questionable leadership.
        • Dashlane, I don’t know much about tbh.
        • Nord Pass, just, no.

        I’d prefer a hosted solution that could work with my parents. Vaultwarden, however nice, I don’t want to host an instance public to the internet.

        Any good choices out there I’m not aware of?

        10 votes
        1. [8]
          Sheep
          Link Parent
          Keepass and its derivatives. It's been around for ages and has always been fully offline. Just need to sync a single database file between your devices, which you can do with whatever solution you...

          Keepass and its derivatives. It's been around for ages and has always been fully offline. Just need to sync a single database file between your devices, which you can do with whatever solution you prefer.

          17 votes
          1. [4]
            DefiantEmbassy
            Link Parent
            Sadly, not hosted. I used KeePass for over a decade, but I don’t want to deal with syncing issues any more. And the idea of getting my parents to use KeePass is laughable. 1Password is barely...

            Sadly, not hosted. I used KeePass for over a decade, but I don’t want to deal with syncing issues any more.

            And the idea of getting my parents to use KeePass is laughable. 1Password is barely functional enough for them, and even then they struggle to use it.

            6 votes
            1. [3]
              Protected
              Link Parent
              What syncing issues did you typically experience? I used KeePass on Windows for about as long, which was a bit of a mess locally (with Kee(Fox) for browser integration), and moved to KeePassXC on...

              What syncing issues did you typically experience? I used KeePass on Windows for about as long, which was a bit of a mess locally (with Kee(Fox) for browser integration), and moved to KeePassXC on Linux, which kept the same database but works better. On Windows the database was moved over SFTP (directly within KeePass) and it never, ever got corrupted. On Linux it's on a sshfs mount, which is much faster and so far so good.

              1 vote
              1. [2]
                DefiantEmbassy
                Link Parent
                Typically just loss of data. My set up at the time would’ve been either Google Drive or Dropbox. Effectively, I write an entry on my phone. Go back to my desktop, which already has KP loaded, but...

                Typically just loss of data. My set up at the time would’ve been either Google Drive or Dropbox. Effectively, I write an entry on my phone. Go back to my desktop, which already has KP loaded, but obviously is in an old state. If I don’t remember to re-open the app, I will lose the data I added on my phone whenever I make a change on the desktop.

                I did work around it for a while using a KeePass plugin to add a “native” sync using the cloud services, but really don’t want to go back to a janky plugin setup with Windows KeePass.

                1. vord
                  Link Parent
                  I wonder why no password managers have adopted some sort of eventually consistent database like CouchDB. It would almost completely solve all synchronization issues between multiple clients...

                  I wonder why no password managers have adopted some sort of eventually consistent database like CouchDB.

                  It would almost completely solve all synchronization issues between multiple clients sharing a password store.

                  2 votes
          2. [2]
            guissmo
            Link Parent
            Yes, thank you very much! It does answer my original question. And I could probably set it up easily when I get the time. However, is there something that my less tech-inclined friends and family...

            Yes, thank you very much! It does answer my original question. And I could probably set it up easily when I get the time.

            However, is there something that my less tech-inclined friends and family can use? Are they stuck with Bitwarden and other cloud-based password managers for their ease of use?

            3 votes
            1. papasquat
              Link Parent
              You can drop a keepass file in OneDrive or GDrive and use it pretty easily. The user experience frankly sucks compared to online password managers, and I think most people who advocate for it and...

              You can drop a keepass file in OneDrive or GDrive and use it pretty easily.

              The user experience frankly sucks compared to online password managers, and I think most people who advocate for it and deny that are being disingenuous, but it's not that bad, and pretty easy to set up, it's not like you need a docker environment or anything.

              5 votes
          3. ButteredToast
            (edited )
            Link Parent
            Last I looked at Keypass, it had an issue with something of a perpetual game of musical chairs going on with its clients, with the current "preferred" option that is maintained and secure...

            Last I looked at Keypass, it had an issue with something of a perpetual game of musical chairs going on with its clients, with the current "preferred" option that is maintained and secure periodically rotating, with some platforms being worse than others. Has that settled down yet?

        2. [3]
          Banazir
          Link Parent
          Care to define the "questionable leadership"? Because the only thing anybody ever points to is a single tweet from Andy Yen, while there is a lot more evidence for him leaning left.

          Proton Pass, well, Proton also has questionable leadership.

          Care to define the "questionable leadership"? Because the only thing anybody ever points to is a single tweet from Andy Yen, while there is a lot more evidence for him leaning left.

          5 votes
          1. DefiantEmbassy
            Link Parent
            It is definitely thin. For example, there was the recent controversy around a poor sponsorship, and seeming community silencing, but truthfully, I've only heard and read about it today. If I can...

            It is definitely thin. For example, there was the recent controversy around a poor sponsorship, and seeming community silencing, but truthfully, I've only heard and read about it today. If I can be convinced Proton is more reasonable, I'm certainly willing to reconsider.

            1 vote
          2. Carrow
            Link Parent
            That article is from 01/2025, they had also recently sponsored a far right French YouTuber, which admittedly seems minor compared to the evidence in your link....

            That article is from 01/2025, they had also recently sponsored a far right French YouTuber, which admittedly seems minor compared to the evidence in your link.

            https://tildes.net/~society/1ule/proton_sponsors_far_right_french_youtuber_claims_lack_of_awareness_in_response_to_backlash

            SurfShark VPN seems cool, they don't offer port forwarding, but IIRC what proton calls port forwarding is P2P support rather than actual port forwarding.

            1 vote
        3. [6]
          NaraVara
          Link Parent
          Sadly this seems to be the deal across the infosec/privacy world. It’s the main reason I left that industry, I just can’t stand the prevalence of CHUD culture there.

          Proton Pass, well, Proton also has questionable leadership.

          Sadly this seems to be the deal across the infosec/privacy world. It’s the main reason I left that industry, I just can’t stand the prevalence of CHUD culture there.

          4 votes
          1. vord
            Link Parent
            My guess is that the single largest demographic for online privacy software is the government conspiracy types, so once you've courted the tech crowd, expanding rightward is the next logical step....

            My guess is that the single largest demographic for online privacy software is the government conspiracy types, so once you've courted the tech crowd, expanding rightward is the next logical step.

            Kinda tragic really.

            7 votes
          2. [4]
            DefinitelyNotAFae
            Link Parent
            I saw someone talking about how the rich people lost their shit during COVID because they've never been inconvenienced like that before, and it's like they've never recovered. I don't believe that...

            I saw someone talking about how the rich people lost their shit during COVID because they've never been inconvenienced like that before, and it's like they've never recovered.

            I don't believe that is the cause of it, however the tenor of the country and the world has changed since, and not just because of the pandemic by any means. And the social acceptability of bigotry and cruelty in general has drastically changed.

            7 votes
            1. [3]
              vord
              Link Parent
              I find it really telling that when I press people on why they think illegal immigration is a problem, they are unable to do anything other than regurgitate the easily disproven talking points:...

              I find it really telling that when I press people on why they think illegal immigration is a problem, they are unable to do anything other than regurgitate the easily disproven talking points:

              • They're sending us their criminals
              • They're taking our jobs
              • They're stealing our benefits
              • They're fraudulently voting

              And the defendents get really angry when you ask how exactly they'd be able to find the illegal immigrants at a random Walmart without resorting to "Papers, Please."

              9 votes
              1. [2]
                DefinitelyNotAFae
                Link Parent
                Well the answer is skin color and accent, and they don't like you making them admit that.

                Well the answer is skin color and accent, and they don't like you making them admit that.

                8 votes
                1. vord
                  Link Parent
                  Obviously, and that's why it's important to make them do it as often as possible. "If you're ashamed to admit that, then maybe you should reconsider your stance." Of course, then they'll call me...

                  Obviously, and that's why it's important to make them do it as often as possible.

                  "If you're ashamed to admit that, then maybe you should reconsider your stance."

                  Of course, then they'll call me the Nazi for judging their beliefs.

                  9 votes
        4. [3]
          GOTO10
          Link Parent
          ugh I wanted to switch to their VPN when my Mullvad one is finished, but... :(

          Proton Pass, well, Proton also has questionable leadership.

          ugh I wanted to switch to their VPN when my Mullvad one is finished, but... :(

          1. [2]
            Banazir
            Link Parent
            The "questionable leadership" is a single tweet the CEO made, but donations and activity show a more leftward lean. Basically Proton got hit with yet another smear campaign and this one is...

            The "questionable leadership" is a single tweet the CEO made, but donations and activity show a more leftward lean. Basically Proton got hit with yet another smear campaign and this one is sticking. They're not 100% perfect, but they are (at the moment) the best general option that I'm aware of.

            8 votes
            1. GOTO10
              Link Parent
              Thanks, good to hear some more context.

              Thanks, good to hear some more context.

        5. [2]
          macleod
          Link Parent
          You can host VW on a private network, and then rely on tailscale (or headscale, the OSS reverse engineered version) or Netbird (OSS) to create your own virtual private network that can't be...

          Vaultwarden, however nice, I don’t want to host an instance public to the internet.

          You can host VW on a private network, and then rely on tailscale (or headscale, the OSS reverse engineered version) or Netbird (OSS) to create your own virtual private network that can't be accessed from the public internet.

          1. DefiantEmbassy
            Link Parent
            If it was just for myself, totally an option (granted, I'd also hate having to manage backups). With my parents, unlikely to work - ensuring that the connection to the Tailnet stays up will add a...

            If it was just for myself, totally an option (granted, I'd also hate having to manage backups). With my parents, unlikely to work - ensuring that the connection to the Tailnet stays up will add a lot of complexity, not to mention that I don't really want them on the Tailnet I currently have.

            1 vote
      2. fxgn
        Link Parent
        The article doesn't mention it being enshittified in any way. They changed their website, but there have been no negative product changes so far.

        The article doesn't mention it being enshittified in any way. They changed their website, but there have been no negative product changes so far.

        9 votes
      3. [6]
        chargrilled_broccoli
        Link Parent
        That smells like AI. The em-dashes and phrases like "the brake on the worst case: " and "the real safety net", reek of AI.

        https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden

        That smells like AI. The em-dashes and phrases like "the brake on the worst case: " and "the real safety net", reek of AI.

        8 votes
        1. frailtomato
          Link Parent
          Also and

          Also

          That matters.

          and

          but that’s a speed bump, not a wall

          7 votes
        2. [4]
          sum4
          Link Parent
          yeha I concur - doesn't mean it's wrong though sadly, I'm worried personally been an avid bitwaden fanboy since the LastPass shit show.

          yeha I concur - doesn't mean it's wrong though sadly, I'm worried personally been an avid bitwaden fanboy since the LastPass shit show.

          1 vote
          1. [3]
            chargrilled_broccoli
            Link Parent
            Sure the personnel changes look worrying indeed. I have my rents on Bitwarden but I’m migrating their credential stores to Keepass2. Keepass clients and browser extensions have reached the...

            Sure the personnel changes look worrying indeed. I have my rents on Bitwarden but I’m migrating their credential stores to Keepass2.

            Keepass clients and browser extensions have reached the required ease of use for my use cases now.

            1. [2]
              sum4
              Link Parent
              Okay good to know, simple enough for family also? how do you handle sync?

              Okay good to know, simple enough for family also? how do you handle sync?

              1. chargrilled_broccoli
                Link Parent
                There is no sync in my configuration. All the clients I use now directly save to , and load from, the same webdav connector. So there is no local data, and no syncing.

                There is no sync in my configuration. All the clients I use now directly save to , and load from, the same webdav connector. So there is no local data, and no syncing.

      4. stu2b50
        Link Parent
        This feels extremely alarmist. If you read the blog, the "alarming behavior" is increasing their dirt cheap premium plan from $10/year to $20/year. I mean, yes, that's doubling, but it's also not...

        This feels extremely alarmist. If you read the blog, the "alarming behavior" is

        1. increasing their dirt cheap premium plan from $10/year to $20/year. I mean, yes, that's doubling, but it's also not even $2/month. The premium plan which isn't required to begin with.

        2. removing the words "always free" from one of their sales pages (which they added back anyway)

        If you nitpick all options to this extent then, then yes, there are no good password managers, because nothing is perfect in this world.

        Bitwarden already has a perfect release valve in the form of it being both open-source and open-spec. You can always migrate to vaultwarden if you don't like hosted bitwarden without changing anything on the clients.

        7 votes
      5. vord
        Link Parent
        Ah balls. Valutwarden changed my life. Guess the time has come to make independent clients too.

        Ah balls. Valutwarden changed my life. Guess the time has come to make independent clients too.

        3 votes
      6. CptBluebear
        Link Parent
        ZZZZZZZZZZZZZZZZZZZZZ Why does this happen every time. They know it sucks because it's kept quiet as much as possible. This is the first I hear of it.

        ZZZZZZZZZZZZZZZZZZZZZ

        Why does this happen every time. They know it sucks because it's kept quiet as much as possible. This is the first I hear of it.

        2 votes
      7. [2]
        guissmo
        Link Parent
        What password manager have you been using?

        What password manager have you been using?

        1. chargrilled_broccoli
          Link Parent
          I use keepass2 database files with various compatible clients, with the master file on a private cloud vps and mostly accessed over webdav if the clients support it.

          I use keepass2 database files with various compatible clients, with the master file on a private cloud vps and mostly accessed over webdav if the clients support it.

          2 votes
    2. Barney
      Link Parent
      I've been using KeePassXC for as long as I can remember. Might be worth checking it out if you're looking for a password manager. I store my ssh keys in there too and inject them into my desktop...

      I've been using KeePassXC for as long as I can remember. Might be worth checking it out if you're looking for a password manager.

      I store my ssh keys in there too and inject them into my desktop ssh agent on demand. It's really cool stuff.

      4 votes
    3. post_below
      Link Parent
      Also, all their desktop apps use Electron. Which is a huge download/install size and memory usage hit for an (otherwise) lightweight app like a password manager.

      Also, all their desktop apps use Electron. Which is a huge download/install size and memory usage hit for an (otherwise) lightweight app like a password manager.

      3 votes
  2. [6]
    Weldawadyathink
    Link
    This sucks, and unfortunately I will have to keep giving them money. As others have said, the market for password managers is pretty grim right now. And I’ve spent years training my family to use...

    This sucks, and unfortunately I will have to keep giving them money. As others have said, the market for password managers is pretty grim right now. And I’ve spent years training my family to use 1password. And the user experience in 1password is legitimately quite good. Moving to a worse product and having to retrain my family is a non starter.

    9 votes
    1. [4]
      bitshift
      Link Parent
      I'm in a similar boat. In terms of usability and security, 1Password is unfortunately the best existing solution for me. In an ideal world, there would be an open standard for syncing credentials...

      I'm in a similar boat. In terms of usability and security, 1Password is unfortunately the best existing solution for me.

      In an ideal world, there would be an open standard for syncing credentials and legal requirements to ensure companies play nicely in that ecosystem. We shouldn't be in a position where we're forced to choose from a very small handful of providers, of which only one or two are actually secure. But there are reasons why that's hard and why we don't live in that ideal world.

      So we're forced into an optimization problem. You can't have too many hard lines, because at a certain point you basically couldn't use technology at all. The best you can do is use the limited wiggle room you have to minimize how much you have to hold your nose. (And also, not judge anyone, yourself or others, for giving these companies money.)

      7 votes
      1. [3]
        stu2b50
        Link Parent
        Is it not the case? To switch from 1password to bitwarden, all it takes is exporting one file, then importing that one file: https://bitwarden.com/help/import-from-1password/ Pretty much all...

        In an ideal world, there would be an open standard for syncing credentials and legal requirements to ensure companies play nicely in that ecosystem.

        Is it not the case? To switch from 1password to bitwarden, all it takes is exporting one file, then importing that one file: https://bitwarden.com/help/import-from-1password/

        Pretty much all password managers can export all of your data either in a fairly fungible json format, a CSV, or both, making it easy to swap between them.

        1. [2]
          bitshift
          Link Parent
          True, fair enough! When I wrote that, one of the things on my mind was stuff like passkeys being locked down to devices/accounts—which seems like the sort of thing that Apple/Google/etc would be...

          True, fair enough!

          When I wrote that, one of the things on my mind was stuff like passkeys being locked down to devices/accounts—which seems like the sort of thing that Apple/Google/etc would be excited about, and not for altruistic reasons. I presume 1Password can export passkeys though. It just requires diligence in knowing where your keys are stored.

          1. stu2b50
            Link Parent
            Why? The passkey spec is public, and the benefit of hardware keys has nothing to do with platform lock in. There's two types of passkeys: normal passkeys, which are just a secret and public key...

            which seems like the sort of thing that Apple/Google/etc would be excited about, and not for altruistic reasons.

            Why? The passkey spec is public, and the benefit of hardware keys has nothing to do with platform lock in.

            There's two types of passkeys: normal passkeys, which are just a secret and public key used for asymmetric identity verification, and hardware bound passkeys.

            The former is what is going to end up on Bitwarden and the like, and are intended to replace normal passwords. These are fully portable. Bitwarden or 1password can absolutely export or move around them. The spec is open and managed by FIDO.

            The latter is not really a replacement for your ordinary passwords - it's more of a replacement for a password + hardware 2-factor authentication. In the context it's used, it shouldn't be the only way to access your account (usually, either you also have a password, normal passkey, or something like email access - OR, it's a corporate device, where IT has ultimate control and can give you access again).

            I don't see how it's any more nefarious than yubikeys are normally, which is not at all.

            1 vote
    2. kfwyre
      (edited )
      Link Parent
      Same boat here too. I basically dragged my family on to 1Password by giving them the extremely good deal of “I will pay for it if you will use it.” As such, I’ve been shelling out for a family...

      Same boat here too. I basically dragged my family on to 1Password by giving them the extremely good deal of “I will pay for it if you will use it.” As such, I’ve been shelling out for a family account for years now that includes my parents, siblings, and their partners.

      It took a lot of time and effort to get them on and used to it, especially because a few of them had never even used a password manager before.

      Changing over simply isn’t going to happen for us, so I’m stuck with 1Password no matter what they decide to do. Instead, all I can do is cheer on the employees who are pushing back on this from the inside.

      7 votes
  3. [4]
    chroma
    Link
    Why the fuck can't I just use my useful tech in peace without being blindsided by a moral dilemma lol I recently de-Googled, de-Appled, de-everything'd to the extent practical - switching to...

    Why the fuck can't I just use my useful tech in peace without being blindsided by a moral dilemma lol

    I recently de-Googled, de-Appled, de-everything'd to the extent practical - switching to Graphene, self-hosting most cloud solutions (except 1Password... if my homelab goes down I don't want to be SOL). I don't want to support any of this, and so now I know I will be spending my weekend migrating mine and my partner's personal 1P archive to like KeePass or something.

    Despite my hobbyist enjoyment of doing stuff like this I am becoming exhausted from having to Make a Choice all the time god damn it.

    9 votes
    1. [3]
      vord
      Link Parent
      I run Vaultwarden locally, and have a dedicated nightly decrypted then re-encrypted export onto cloud storage. If homelab goes poof,I'm back up and running on almost any provider instantly.

      I run Vaultwarden locally, and have a dedicated nightly decrypted then re-encrypted export onto cloud storage.

      If homelab goes poof,I'm back up and running on almost any provider instantly.

      1 vote
      1. [2]
        chroma
        Link Parent
        Thanks, I will do this with KeePass or something. (I realized I might as well do encrypted cloud backups for most of my lower volume homelab stuff too. I don't have a backup strategy right now...

        Thanks, I will do this with KeePass or something.

        (I realized I might as well do encrypted cloud backups for most of my lower volume homelab stuff too. I don't have a backup strategy right now because my setup is relatively new and I don't want to shell out an asinine amount for drives in 2026. It for some reason never occurred to me to just rent cloud storage.)

        2 votes
        1. vord
          Link Parent
          Rclone with crypt remounts are your best friend. I also manually encrypt the password store itself before uplaoding there too. I paid for a 2TB lifetime PCloud plan years ago now, and have...

          Rclone with crypt remounts are your best friend. I also manually encrypt the password store itself before uplaoding there too.

          I paid for a 2TB lifetime PCloud plan years ago now, and have officially hit 'breakeven'. Wait for one of their Black Friday sales.

          2 votes
  4. carsonc
    Link
    I just want to mention how much I have enjoyed using Enpass over the years. The prospect of keeping my online backup in the location that I feel secure and the knowledge that it is not sitting in...

    I just want to mention how much I have enjoyed using Enpass over the years. The prospect of keeping my online backup in the location that I feel secure and the knowledge that it is not sitting in a single repository alongside countless other vaults have been reassuring to me. If anyone is looking for a new password handler, you might want to check it out.

    2 votes
  5. ButteredToast
    Link
    They also just announced that they're killing sync support for 1Password 7, which is the last version that resembled AgileBits' handcrafted indie Mac app roots. With v8 they went all in on a new...

    They also just announced that they're killing sync support for 1Password 7, which is the last version that resembled AgileBits' handcrafted indie Mac app roots. With v8 they went all in on a new bloated, buggy Electron client with an enterprise slop look and feel that fits in better with the likes of Salesforce and JIRA.

    So disappointing. I've switched to Bitwarden for now, but am aware of concerns with it too, and its UI isn't as nice as that of 1Password 7.

    2 votes