First impressions of 1Password

After several years using the same password-manager service–and then paying for its premium version–I’ve spent the last few weeks trying an alternative.

I can credit a sales pitch that included the italicized phrase “completely free” for this departure: 1Password’s offer of a free membership to journalists, in celebration of World Press Freedom Day this May 3. But I was also overdue to spend some time in a password manager besides LastPass.

So far, I’m impressed by the elegance of the interface but a little put off by how persnickety 1Password can be to set up. You don’t just create a username and password, you also have to type in a complex and random secret key to get going.

Having read this Toronto-based firm’s documentation of how this extra step helps ensure that a successful guess of your password still won’t compromise your account, I get where they’re coming from. But I’m not sure I’d recommend it to just anybody, especially not when LastPass’s free version suffices for many casual users.

Further time with 1Password’s Mac, Windows and Android apps has revealed other things I like:

This time has also surfaced one thing I don’t like: an incomplete approach to two-step verification that seems to require choosing between running an authenticator app on your smartphone or employing a weird Yubikey implementation that requires running a separate app instead of just plugging a standard USB security key. That’s no better than LastPass’s inflexible notion of two-step verification.

I’d like to see 1Password improve that and support the WebAuthn standard for security-key confirmation. But I’m prepared to give them some time, based on everything else I’ve seen so far.

Advertisements

Weekly output: LTE hotspots, Techdirt, SOTU, password managers, Washington Apple Pi, Tech Night Owl, old IE versions

I had a relaxing week after CES… no, that’s not right.

Wirecutter LTE hotspot guide1/11/2016: Best Wi-Fi Hotspot, The Wirecutter

My overdue update to this guide to LTE hotspots endorsed a Verizon model and gave a secondary endorsement to an AT&T hotspot with lesser battery life. We then revised the update after it posted to note that the Sprint reseller Karma had downgraded an initially-promising unlimited-data option.

1/12/2016: Techdirt Podcast Episode 56: The CES Post-Mortem, Techdirt

I ran into Techdirt’s Mike Masnick at CES, and on our respective ways out of town he suggested I appear on his podcast. I said that would be a great idea.

1/13/2016: State of the Union’s Technology? What Obama Didn’t Say, Yahoo Tech

The tech-policy story about this SOTU address is how little attention tech policy got. I’d still like to know what led Reuters to think that self-driving cars would get a mention in the speech.

1/14/2016: Tip: How to Make Sure Someone Can Access Your Passwords in an Emergency, Yahoo Tech

The 4.0 update LastPass rolled out right before CES added an emergency-access feature, so I used this tip to tell readers about that and Dashlane’s comparable emergency-contacts option.

1/14/2016: Afternoon Learners SIG, Washington Apple Pi

I stopped by a meeting of this Apple users’ group to share my thoughts about CES–and to hand out some PR swag and USB flash drives.

1/16/2016: January 16 2016 — John Martellaro and Rob Pegoraro, Tech Night Owl

I talked to Gene Steinberg about what I saw at CES, from UHD TVs to the Internet of Insecure Things.

1/17/2016: What to do after Microsoft ends support for older browsers, USA Today

The easy answer to Microsoft’s end of support for older Internet Explorer versions is “install IE 11.” But that browser isn’t the same app in Windows 7 as it is in Win 8 and 10, and updating your browser doesn’t end your Web-security chores.