Oh boy. So much in this thread that it’s hard to know where to start so I will just take some of the posts that caught my eye:
More.
It looks like a single developer or small team and HE / THEY were able to ship a native app,
Meanwhile, 1password that has hundreds of employees has raised at least $300 million in venture capital said:
No native for you. You will eat electron and like it!
It’s easy to support native when you are a 1 man shop and perhaps not cross platform. But how reliable will that 1 man operation be in the future? They could get an accident and be in a coma or worse. They get get bored and just stop developing the product. I’ve seen that happen before. One man shops might be good for a game app, but not a product you and perhaps other family members need to rely on for many years to come.
Backups are important, yes, and multiple backups even more important; but all of those backups are worthless if you could not restore from them. This is where a local vault comes in because you wouldn't be stuck with being dependent on them for any disaster recovery. If their service goes down for any reason, anyone using them would be effectively locked out of their password vaults until that service come back up.
True. But if you have non-tech types in your family like I do, stuff needs to be SUPER simple for them. I always approach things from the point of “What if something happened to me and I was no longer around, could they figure it out?”. The answer to that question is almost always going to be no, so they need as much help from others as they can get. Backups in multiple redundant places? LOL, yeah right. That’s not going to happen. So for a person like me with non tech savvy people, cloud solutions, even with the risk they can introduce, are still the better option.
You wouldn't want someone else to have and hold your bank account number,
Ironically, just by having a bank account, you have trusted someone else to hold your actual money.
They can call your bank and give them all needed info for your vault like birthdate, addresses, spouse contact and do some serious social engineering
Uh...no. 1password doesn’t have visiabilty to all that. I suppose one could say they are lying, but they would then have to prove their case since they are the ones making the allegations.
AgileBits would have to shut off their service altogether, leaving you locked out of your vault. That doesn't eliminate the compromise of that vault, as the hacker would still have had the means to get a copy of that vault off of AgileBits' servers for their later perusal. Similar to HIPAA when your PHI data is compromised, or worse: similar to the TMobile breach
Not similar. T-Mobile didn’t shut down their service just because they had a breach. Although really the comparisons are even worse when you consider that T-mobile is a phone company, while AgileBits is a security based company. Their whole product is security. T-Mobile’s product is phone calls and mobile data access and selling you a phone. Completely different businesses. Security is more of a tacked on thing because they have to at T-mobile, and it shows. They rather be just selling you plans and phones. Whereas 1password is selling security. That’s the whole point of their product.
Now, one can make the case as many have here that using the cloud is by it’s nature insecure, and I get that. But It seems like AgileBits has taken great pains to keep things secure three different ways: encryption, your MasterPassword and the additional secret key. Someone could say that’s still not enough and it’s too tempting for hackers, but yet the company has never been hacked. That tells me they are putting a strong effort in security. But I get that for some people that will never be enough and they will always worry about “what if” scenarios. Yet these same people want to store things on icloud or dropbox or whatever. 🤷♂️
I think as this thread demonstrates, there is no perfect solution here. Small one man operations are unlikely to deliver the features people want, may not be cross platform, and may not be around long. Big companies may be around long, cross platform, and be able to roll out features quickly because of the size of their team, but that comes at a cost, quite literally, in the form of subscription models to sustain all that, and cloud services some people don’t want to trust.
It would be nice if Apple had a better developed product than keychain, but then it still wouldn’t be cross platform and you are still relying on a cloud of some sort to get things to multiple devices or users. And who knows....with Apple’s OWN reliance on software as services lately, I wouldn’t put it past them to put such improvements behind a subscription paywall themselves.