Before this I used Vaultwarden, but I was always a bit afraid of the self-hosting (of something this critical), and I really didn't like how you share credentials in BitWarden (through organizations), Proton Pass is much more intuitive with just straight up sharing of credentials or sharing whole Vaults. You can also share through public 1-time visit, limited time valid-urls. I use that a lot when I set up people's accounts.
What I don't like is the tight coupling to Proton's services, Pass should have had it's own credentials. But if you're not a Proton user that doesn't matter (or perhaps it doesn't matter t you in any case.)
I for one also have my 2fa with them... I get the feeling.
The export is through CSV in clear. I wish they agreed to use some pkcs defined superencypherment and a json format so you could avoid the pass through plaintext.
Do this on a machine you trust, offnet I guess.
Bitwarden has corporate options. Password sharing under a reasonable model, group structure.
I don't like Bitwarden's UI as much as 1Password's, but at least it feels faster.
Apple Passwords will store a user/pass combo for a site. That's it, feature list over.
1Password will let you configure how those things autofill, it provides an `op` CLI that you can use with service account tokens, you can store stuff like photos of your passports and licences, it understands 'Sign in with GitHub', it has per-user access per vault for shared accounts, you can add any number of extra fields to each entry, it integrates directly with Claude, it monitors your passwords against Haveibeenpwned, it'll tell you where you could be using 2FA and aren't … and the list goes on.
Probably the worst quote:
> When wolves get out of control, you shoot them. When gypsies take over public spaces, you deport them. This isn't hard, it isn't cruel. It's the basic logic of self-preservation. [0]
The comparison between shooting wolves here seems definitively bad tase and missing nuance.
[0] https://world.hey.com/dhh/wolves-sheep-and-gypsies-ba44af6a
Just felt the need to post that.
Travelling is a little worse. I'd need to carry my little pocket book an risk losing it and now I can't lock my accounts, because I don't have the password for them (I could have a backup).
You know, I'm kinda talking myself into just doing passwords in a pocket book.
I imagine that a technical company can easily whip up a bespoke simplified interface for its non-technical staff too.
I've used it for about a decade at this point, and it's just perfect.
The CEO of Stripe also donated $1M to Omarchy.
Do we need another migration guide for Stripe since the CEO personally donated to Omarchy and then tell everyone to stop using Stripe and all of their services?
[0] https://www.patreon.com/violetblue/posts/how-to-migrate-1684...
https://world.hey.com/dhh/as-i-remember-london-e7d38e64
That this controversy goes three levels deep (DHH -> Omarchy -> Supporters of Omarchy (1Password)) is kinda funny to me. At what point does it stop?
> 1Password has pledged $300,000 over three years in support of David Heinemeier Hansson's Linux distribution known as Omarchy, and is now a “distinguished corporate patron” of Omacom. What a nice brand partnership.
Supporting a Linux distribution sounds nice; I hadn't heard of that one.
But the very next paragraph:
> DHH has called for the ethnic cleansing of Europe; he is also an antivaxer, a Covid "truther," a proponent of the "lab leak" conspiracy theory, an 'anti woke' weirdo, and is virulently anti-DEI
> In an internal Slack message leaked to press today 1Password’s Roustem Karimov defended DHH as being attacked for his views...
Perhaps they could support a different Linux distribution.
It's also strongly concerning when someone defends someone with views like that, characterising them as being attacked. In general, toxic, racist, fascist views spread like viruses; when tolerated, through acceptance, they grow. A company needs to root them out. If we trust 1Password with our data, we are trusting a company with those views inside it with our data.
it doesn't mean it's true (we may never know), but framing as "conspiracy" was a product of conflict of interest where certain scientist were protecting grant money. Since then even some of the scientists who participated in it walked it back and openly said that both natural and lab leak theories were credible: https://www.science.org/doi/10.1126/science.abj0016
They won't. SV/YC loves the guy, that's the only reason they're donating to Linux/OSS (but really just omarchy).
Leaving aside all the rest of this, I thought "lab leak" was considered a reasonable hypothesis, although not especially likely, these days, rather than some kind of fringe theory.