9 points 0xbadcafebee 59 minutes ago 10 comments

I just found out that 1Password is donating $300,000 to a project founded by a very controversial person, and I'm looking to move to a different password manager.

Has anyone migrated from 1Password recently to another tool/platform? Have you had a good experience with any tools in particular? Any advice, tips? I'm also interested in the corporate-use context; if I can convince my company to switch to an alternative with business controls, I'll surely try.

rvz 51 minutes ago | parent

Here is the migration guide for 1Password. [0]

The CEO of Stripe also donated $1M to Omarchy.

Do we need another migration guide for Stripe since the CEO personally donated to Omarchy and then tell everyone to stop using Stripe and all of their services?

[0] https://www.patreon.com/violetblue/posts/how-to-migrate-1684...

ande-mnoc 15 minutes ago | parent

Yes, why not?

eddythompson80 7 minutes ago | parent

Huh, I guess TIL there is a controversy around Omarchy. I generally dismissed it as a serious distro after 5 second once realized it encourages using the AUR as your default package feed. The AUR is useful, but to me it’s something to be very aware of when you’re installing some software. Encouraging people to install everything through it is a crazy way to configure a distro. I just assumed it’s a distro for a very different target audience so kept my thoughts to myself

ggm 43 minutes ago | parent

I migrated from an older 1password to self hosted bitwarden (vaultwarden) using premade configurations which are available for Portman and Docker in the usual places. Mine uses caddy for the Web front, which automates letsencrypt certification. All the client app which talk to bitwarden talk to vaultwarden, but there's no guarantee into the future I guess. I just like self hosted.

The export is through CSV in clear. I wish they agreed to use some pkcs defined superencypherment and a json format so you could avoid the pass through plaintext.

Do this on a machine you trust, offnet I guess.

Bitwarden has corporate options. Password sharing under a reasonable model, group structure.

turtlehwan 33 minutes ago | parent

Oh, I was only storing and using it in AWS KMS because of the pricing issue, but thanks for the comment. I’ll look into it a bit more.

gspr 17 minutes ago | parent

Are people in your company moderately technical? If so, I highly recommend https://www.passwordstore.org/ coupled with a PGP key storage dongle (I personally use NitroKey). Then hosting is just a matter of hosting a minuscule git repo per user.

I imagine that a technical company can easily whip up a bespoke simplified interface for its non-technical staff too.

I've used it for about a decade at this point, and it's just perfect.

vintagedave 12 minutes ago | parent

There's a bit of a jump here from something appearing good to rapidly becoming very very bad. Here's what I read:

> 1Password has pledged $300,000 over three years in support of David Heinemeier Hansson's Linux distribution known as Omarchy, and is now a “distinguished corporate patron” of Omacom. What a nice brand partnership.

Supporting a Linux distribution sounds nice; I hadn't heard of that one.

But the very next paragraph:

> DHH has called for the ethnic cleansing of Europe; he is also an antivaxer, a Covid "truther," a proponent of the "lab leak" conspiracy theory, an 'anti woke' weirdo, and is virulently anti-DEI

> In an internal Slack message leaked to press today 1Password’s Roustem Karimov defended DHH as being attacked for his views...

Perhaps they could support a different Linux distribution.

It's also strongly concerning when someone defends someone with views like that, characterising them as being attacked. In general, toxic, racist, fascist views spread like viruses; when tolerated, through acceptance, they grow. A company needs to root them out. If we trust 1Password with our data, we are trusting a company with those views inside it with our data.

dokyun 7 minutes ago | parent

piece of paper