1Password wades into a right-wing mess after funding a Linux project

66 points by DefiantEmbassy a day ago on tildes | 51 comments

[OP] DefiantEmbassy | a day ago

(Apologies if this is better in ~tech, the political side of things made me err on putting it here)

Very disappointed in 1Password, and seemingly the rot is not just a single VP, but the entire leadership team. Time to move to Bitwarden.

regularmother | 20 hours ago

Bitwarden got bought by private equity and is becoming enshittified - https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden I cannot recommend them going forward.

[OP] DefiantEmbassy | 20 hours ago

The market for hosted consumer password managers isn’t fun…

  • LastPass is obviously so bad it would be irresponsible to use the them.
  • Proton Pass, well, Proton also has questionable leadership.
  • Dashlane, I don’t know much about tbh.
  • Nord Pass, just, no.

I’d prefer a hosted solution that could work with my parents. Vaultwarden, however nice, I don’t want to host an instance public to the internet.

Any good choices out there I’m not aware of?

Sheep | 19 hours ago

Keepass and its derivatives. It's been around for ages and has always been fully offline. Just need to sync a single database file between your devices, which you can do with whatever solution you prefer.

[OP] DefiantEmbassy | 19 hours ago

Sadly, not hosted. I used KeePass for over a decade, but I don’t want to deal with syncing issues any more.

And the idea of getting my parents to use KeePass is laughable. 1Password is barely functional enough for them, and even then they struggle to use it.

Protected | 17 hours ago

What syncing issues did you typically experience? I used KeePass on Windows for about as long, which was a bit of a mess locally (with Kee(Fox) for browser integration), and moved to KeePassXC on Linux, which kept the same database but works better. On Windows the database was moved over SFTP (directly within KeePass) and it never, ever got corrupted. On Linux it's on a sshfs mount, which is much faster and so far so good.

[OP] DefiantEmbassy | 15 hours ago

Typically just loss of data. My set up at the time would’ve been either Google Drive or Dropbox. Effectively, I write an entry on my phone. Go back to my desktop, which already has KP loaded, but obviously is in an old state. If I don’t remember to re-open the app, I will lose the data I added on my phone whenever I make a change on the desktop.

I did work around it for a while using a KeePass plugin to add a “native” sync using the cloud services, but really don’t want to go back to a janky plugin setup with Windows KeePass.

I wonder why no password managers have adopted some sort of eventually consistent database like CouchDB.

It would almost completely solve all synchronization issues between multiple clients sharing a password store.

guissmo | 19 hours ago

Yes, thank you very much! It does answer my original question. And I could probably set it up easily when I get the time.

However, is there something that my less tech-inclined friends and family can use? Are they stuck with Bitwarden and other cloud-based password managers for their ease of use?

papasquat | 10 hours ago

You can drop a keepass file in OneDrive or GDrive and use it pretty easily.

The user experience frankly sucks compared to online password managers, and I think most people who advocate for it and deny that are being disingenuous, but it's not that bad, and pretty easy to set up, it's not like you need a docker environment or anything.

ButteredToast | 6 hours ago

Last I looked at Keypass, it had an issue with something of a perpetual game of musical chairs going on with its clients, with the current "preferred" option that is maintained and secure periodically rotating, with some platforms being worse than others. Has that settled down yet?

Banazir | 12 hours ago

Proton Pass, well, Proton also has questionable leadership.

Care to define the "questionable leadership"? Because the only thing anybody ever points to is a single tweet from Andy Yen, while there is a lot more evidence for him leaning left.

[OP] DefiantEmbassy | 9 hours ago

It is definitely thin. For example, there was the recent controversy around a poor sponsorship, and seeming community silencing, but truthfully, I've only heard and read about it today. If I can be convinced Proton is more reasonable, I'm certainly willing to reconsider.

Carrow | 9 hours ago

That article is from 01/2025, they had also recently sponsored a far right French YouTuber, which admittedly seems minor compared to the evidence in your link.

https://tildes.net/~society/1ule/proton_sponsors_far_right_french_youtuber_claims_lack_of_awareness_in_response_to_backlash

SurfShark VPN seems cool, they don't offer port forwarding, but IIRC what proton calls port forwarding is P2P support rather than actual port forwarding.

NaraVara | 14 hours ago

Proton Pass, well, Proton also has questionable leadership.

Sadly this seems to be the deal across the infosec/privacy world. It’s the main reason I left that industry, I just can’t stand the prevalence of CHUD culture there.

My guess is that the single largest demographic for online privacy software is the government conspiracy types, so once you've courted the tech crowd, expanding rightward is the next logical step.

Kinda tragic really.

DefinitelyNotAFae | 10 hours ago

I saw someone talking about how the rich people lost their shit during COVID because they've never been inconvenienced like that before, and it's like they've never recovered.

I don't believe that is the cause of it, however the tenor of the country and the world has changed since, and not just because of the pandemic by any means. And the social acceptability of bigotry and cruelty in general has drastically changed.

I find it really telling that when I press people on why they think illegal immigration is a problem, they are unable to do anything other than regurgitate the easily disproven talking points:

  • They're sending us their criminals
  • They're taking our jobs
  • They're stealing our benefits
  • They're fraudulently voting

And the defendents get really angry when you ask how exactly they'd be able to find the illegal immigrants at a random Walmart without resorting to "Papers, Please."

DefinitelyNotAFae | 10 hours ago

Well the answer is skin color and accent, and they don't like you making them admit that.

Obviously, and that's why it's important to make them do it as often as possible.

"If you're ashamed to admit that, then maybe you should reconsider your stance."

Of course, then they'll call me the Nazi for judging their beliefs.

GOTO10 | 15 hours ago

Proton Pass, well, Proton also has questionable leadership.

ugh I wanted to switch to their VPN when my Mullvad one is finished, but... :(

Banazir | 12 hours ago

The "questionable leadership" is a single tweet the CEO made, but donations and activity show a more leftward lean. Basically Proton got hit with yet another smear campaign and this one is sticking. They're not 100% perfect, but they are (at the moment) the best general option that I'm aware of.

GOTO10 | 9 hours ago

Thanks, good to hear some more context.

macleod | 12 hours ago

Vaultwarden, however nice, I don’t want to host an instance public to the internet.

You can host VW on a private network, and then rely on tailscale (or headscale, the OSS reverse engineered version) or Netbird (OSS) to create your own virtual private network that can't be accessed from the public internet.

[OP] DefiantEmbassy | 9 hours ago

If it was just for myself, totally an option (granted, I'd also hate having to manage backups). With my parents, unlikely to work - ensuring that the connection to the Tailnet stays up will add a lot of complexity, not to mention that I don't really want them on the Tailnet I currently have.

The article doesn't mention it being enshittified in any way. They changed their website, but there have been no negative product changes so far.

chargrilled_broccoli | 19 hours ago

https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden

That smells like AI. The em-dashes and phrases like "the brake on the worst case: " and "the real safety net", reek of AI.

frailtomato | 17 hours ago

Also

That matters.

and

but that’s a speed bump, not a wall

yeha I concur - doesn't mean it's wrong though sadly, I'm worried personally been an avid bitwaden fanboy since the LastPass shit show.

chargrilled_broccoli | 15 hours ago

Sure the personnel changes look worrying indeed. I have my rents on Bitwarden but I’m migrating their credential stores to Keepass2.

Keepass clients and browser extensions have reached the required ease of use for my use cases now.

Okay good to know, simple enough for family also? how do you handle sync?

chargrilled_broccoli | 9 hours ago

There is no sync in my configuration. All the clients I use now directly save to , and load from, the same webdav connector. So there is no local data, and no syncing.

stu2b50 | 8 hours ago

This feels extremely alarmist. If you read the blog, the "alarming behavior" is

  1. increasing their dirt cheap premium plan from $10/year to $20/year. I mean, yes, that's doubling, but it's also not even $2/month. The premium plan which isn't required to begin with.

  2. removing the words "always free" from one of their sales pages (which they added back anyway)

If you nitpick all options to this extent then, then yes, there are no good password managers, because nothing is perfect in this world.

Bitwarden already has a perfect release valve in the form of it being both open-source and open-spec. You can always migrate to vaultwarden if you don't like hosted bitwarden without changing anything on the clients.

Ah balls. Valutwarden changed my life. Guess the time has come to make independent clients too.

CptBluebear | 19 hours ago

ZZZZZZZZZZZZZZZZZZZZZ

Why does this happen every time. They know it sucks because it's kept quiet as much as possible. This is the first I hear of it.

guissmo | 19 hours ago

What password manager have you been using?

chargrilled_broccoli | 19 hours ago

I use keepass2 database files with various compatible clients, with the master file on a private cloud vps and mostly accessed over webdav if the clients support it.

Barney | 18 hours ago

I've been using KeePassXC for as long as I can remember. Might be worth checking it out if you're looking for a password manager.

I store my ssh keys in there too and inject them into my desktop ssh agent on demand. It's really cool stuff.

post_below | 21 hours ago

Also, all their desktop apps use Electron. Which is a huge download/install size and memory usage hit for an (otherwise) lightweight app like a password manager.

Weldawadyathink | 13 hours ago

This sucks, and unfortunately I will have to keep giving them money. As others have said, the market for password managers is pretty grim right now. And I’ve spent years training my family to use 1password. And the user experience in 1password is legitimately quite good. Moving to a worse product and having to retrain my family is a non starter.

bitshift | 12 hours ago

I'm in a similar boat. In terms of usability and security, 1Password is unfortunately the best existing solution for me.

In an ideal world, there would be an open standard for syncing credentials and legal requirements to ensure companies play nicely in that ecosystem. We shouldn't be in a position where we're forced to choose from a very small handful of providers, of which only one or two are actually secure. But there are reasons why that's hard and why we don't live in that ideal world.

So we're forced into an optimization problem. You can't have too many hard lines, because at a certain point you basically couldn't use technology at all. The best you can do is use the limited wiggle room you have to minimize how much you have to hold your nose. (And also, not judge anyone, yourself or others, for giving these companies money.)

stu2b50 | 8 hours ago

In an ideal world, there would be an open standard for syncing credentials and legal requirements to ensure companies play nicely in that ecosystem.

Is it not the case? To switch from 1password to bitwarden, all it takes is exporting one file, then importing that one file: https://bitwarden.com/help/import-from-1password/

Pretty much all password managers can export all of your data either in a fairly fungible json format, a CSV, or both, making it easy to swap between them.

bitshift | 6 hours ago

True, fair enough!

When I wrote that, one of the things on my mind was stuff like passkeys being locked down to devices/accounts—which seems like the sort of thing that Apple/Google/etc would be excited about, and not for altruistic reasons. I presume 1Password can export passkeys though. It just requires diligence in knowing where your keys are stored.

stu2b50 | 6 hours ago

which seems like the sort of thing that Apple/Google/etc would be excited about, and not for altruistic reasons.

Why? The passkey spec is public, and the benefit of hardware keys has nothing to do with platform lock in.

There's two types of passkeys: normal passkeys, which are just a secret and public key used for asymmetric identity verification, and hardware bound passkeys.

The former is what is going to end up on Bitwarden and the like, and are intended to replace normal passwords. These are fully portable. Bitwarden or 1password can absolutely export or move around them. The spec is open and managed by FIDO.

The latter is not really a replacement for your ordinary passwords - it's more of a replacement for a password + hardware 2-factor authentication. In the context it's used, it shouldn't be the only way to access your account (usually, either you also have a password, normal passkey, or something like email access - OR, it's a corporate device, where IT has ultimate control and can give you access again).

I don't see how it's any more nefarious than yubikeys are normally, which is not at all.

kfwyre | 8 hours ago

Same boat here too. I basically dragged my family on to 1Password by giving them the extremely good deal of “I will pay for it if you will use it.” As such, I’ve been shelling out for a family account for years now that includes my parents, siblings, and their partners.

It took a lot of time and effort to get them on and used to it, especially because a few of them had never even used a password manager before.

Changing over simply isn’t going to happen for us, so I’m stuck with 1Password no matter what they decide to do. Instead, all I can do is cheer on the employees who are pushing back on this from the inside.

chroma | 12 hours ago

Why the fuck can't I just use my useful tech in peace without being blindsided by a moral dilemma lol

I recently de-Googled, de-Appled, de-everything'd to the extent practical - switching to Graphene, self-hosting most cloud solutions (except 1Password... if my homelab goes down I don't want to be SOL). I don't want to support any of this, and so now I know I will be spending my weekend migrating mine and my partner's personal 1P archive to like KeePass or something.

Despite my hobbyist enjoyment of doing stuff like this I am becoming exhausted from having to Make a Choice all the time god damn it.

I run Vaultwarden locally, and have a dedicated nightly decrypted then re-encrypted export onto cloud storage.

If homelab goes poof,I'm back up and running on almost any provider instantly.

chroma | 12 hours ago

Thanks, I will do this with KeePass or something.

(I realized I might as well do encrypted cloud backups for most of my lower volume homelab stuff too. I don't have a backup strategy right now because my setup is relatively new and I don't want to shell out an asinine amount for drives in 2026. It for some reason never occurred to me to just rent cloud storage.)

Rclone with crypt remounts are your best friend. I also manually encrypt the password store itself before uplaoding there too.

I paid for a 2TB lifetime PCloud plan years ago now, and have officially hit 'breakeven'. Wait for one of their Black Friday sales.

carsonc | 16 hours ago

I just want to mention how much I have enjoyed using Enpass over the years. The prospect of keeping my online backup in the location that I feel secure and the knowledge that it is not sitting in a single repository alongside countless other vaults have been reassuring to me. If anyone is looking for a new password handler, you might want to check it out.

ButteredToast | 6 hours ago

They also just announced that they're killing sync support for 1Password 7, which is the last version that resembled AgileBits' handcrafted indie Mac app roots. With v8 they went all in on a new bloated, buggy Electron client with an enterprise slop look and feel that fits in better with the likes of Salesforce and JIRA.

So disappointing. I've switched to Bitwarden for now, but am aware of concerns with it too, and its UI isn't as nice as that of 1Password 7.