Skip to main content
August 13, 2021
Question

The real problem behind 1P8

  • August 13, 2021
  • 21 replies
  • 586 views

The biggest problem with the 1password 8 is that AgileBits are pulling a total and complete overhaul on everything. Sure a new code base is a clean break, but they are taking this as license to change anything and everything. So 1P8 is pissing off a lot of people for a lot of unrelated reasons. For example today I found out that if you use multiple accounts, you will now need to use multiple passwords to unlock your 1P client. Personally, I couldn't care less about the Electron thing and the search changes are annoying but not game breaking. However needing to use a bunch of passwords every 30 minutes to get access to the data I need is absolutely a change that would drive me away from 1password. After all it's called ONE Password, not 15Passwords.

Why are they doing this? Because someone thought it was more secure. Who cares what the customers think. Who cares what the customers need. Who cares about the actual use cases of the paying customers. Did anyone even ask the customers? Could it be a preference? Sure, totally. And some may want that. Heck, it something they could make as a business feature flag so that admins can require it. But should it be forced on everyone without any thought to what that actually means? Fark no. That's how you piss people off and drive them off your platform.

And this is one tiny change in a vast ocean of changes known as 1Password 8. So now I'm scared. What else is going to be changed that I (and others) haven't figured out, that is totally going to screw us? I don't know. No one knows. 1Password won't even be truthful about the changes it is making (see also electron and stand alone vault drama).

The only thing that a complete overhaul of an application (and service) accomplishes, is making everyone angry at you for changing the one or two things they cared about. Because you changed it all.

PS. And there is absolutely no way you can convince everyone that "this will be better in the long run". Unless you can address why each "game breaking" change is better, to an extent that makes all the customers happy.


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided

21 replies

1P_Rob
1Password Employee
1Password Employee
August 23, 2021

Hey, folks. I know this is a bit delayed, but I wanted to reiterate that everyone's feedback is valuable, and even when things feel a little heated it's good to know that it's only because people care about this product.

I also wanted to respond to a specific part of @ShakataGaNai's original post about the multiple passwords. We've actually been recommending folks use the same password for each of their 1Password accounts. This might sound ironic given that the typical advice w.r.t. passwords is to use a unique password for everything. The difference is that your 1Password account password is intended to be the one password you remember, and so in theory, if you can only dedicate so much brain space to passwords, if you use only one password for all of your 1Password accounts, you'll be able to make that password stronger than if you have to remember multiple account passwords. So part of the new behavior encourages folks that direction.

It's probably worth mentioning that this has been the behavior of 1Password in Chrome and Firefox for quite some time now, so it's not new in 1Password 8.

August 23, 2021

"We've actually been recommending folks use the same password for each of their 1Password accounts. "

Please. No. Please. No. You can't have it both ways.

1P_Rob
1Password Employee
1Password Employee
August 24, 2021

Hey @dougl. I'd love to hear more about why you think this advice is a problem. @jpgoldberg and @roustem commented in more detail about this in another thread, which may be helpful:

https://1password.community/discussion/comment/608291/#Comment_608291

August 24, 2021

Sure. So I get the nuances, I really do. The problem is that most 1P users aren't professional security people, so having inconsistent messaging complicates training and enablement. If the message is 'password reuse is bad', that's a full stop. As soon as we offer options/nuances, then where does that line end?

I have two 1P accounts, with two different passphrases. One for work, one personal. Since those don't change, remembering two isn't a big deal.

Now if you wanted to implement some type of SSO-esque system, that'd be fine. Because it's One Password (pun intended) that unlocks multiple things like Okta does. But telling people to manually set multiple passwords to be the same is dangerous.

And, there's another issue. In an eDiscovery situation, there's a possibility that the employee may be compelled to give up their work passphrase...but now their personal vault is exposed.

Happy to chat more about this.

1Password Employee
August 24, 2021

I do understand the concern about having to caveat advice, and I agree it is less than ideal to have to do so.

And, there's another issue. In an eDiscovery situation, there's a possibility that the employee may be compelled to give up their work passphrase...but now their personal vault is exposed.

How is this any different with the 1Password 8 model than with the 1Password 7 model? I would actually argue that with 1Password 8 people now explicitly have the option of not having the same password unlock both accounts, whereas that wasn't possible if you wanted to use both accounts with 1Password 7. With v7 one and only one password unlocked all accounts, regardless of what the passwords for those accounts were. With v8 if you don't want that to happen, and you want your personal data to unlock separately from your work data, you can.

Ben

August 24, 2021

You're right, not a 1P8 vs 7 topic - it's about guidance. 1P should be consistent - no reuse. Now if an individual company wants to add nuance, that's fine. But if 1P says reuse as a workaround, and the company has a no-reuse policy, it causes friction. If 1P says no, and the company says do, then that advice trumps. Make sense?

1Password Employee
August 24, 2021

I would still argue that the situation has improved, rather than gotten worse. The thing is it is totally optional now. It wasn't before. Before you were forced to have a single password that unlocked all added accounts. Period. Now there is a choice. If your company wants to put out a blanket "no password reuse" policy, you can do that, and then folks with multiple accounts can either unlock using entirely separate passwords, or use biometrics to unlock everything together, while obeying that policy.

Ben

roustem
1Password Employee
1Password Employee
August 24, 2021

There are many ideas and many painful lessons we learn over the years when helping our customers and using 1Password ourselves. Just wanted to say that we are definitely taking 1Password 8 release as an opportunity to rethink how things are done and make them better.

If we didn't then what would be the point of the release?

August 24, 2021

@roustem

I don't know. Were users telling you they wanted 1Password to be slower, have fewer features, have a UI that doesn't match their OS, and has a ton of bugs? You tell us what the point of the release is. You've not demonstrated any major advantages, just declared that someday there will be some.

The reality is this release makes it easier and more profitable for 1Password. But don't act like this is some huge step forward for users.

August 24, 2021

It is amazing how 1Pwd TeamMembers still try to convince us to like v8.
Almost everything what is more than a "common bug" gets blocked.
Still my wish, my hope is that Agile realises that v8 goes in the wrong - the WRONG - direction.
I wonder how/where they get their motivation to continue. Where is this positive feedback? Or is just the money (and pressure) their got some time ago?

Sorry, but I am back (decided to leave this EarlyAccess forum some days ago, but I could not stay away).