Ask HN: Advice on Migrating from 1Password?
I just found out that 1Password is donating $300,000 to a project founded by a very controversial person, and I'm looking to move to a different password manager.
Has anyone migrated from 1Password recently to another tool/platform? Have you had a good experience with any tools in particular? Any advice, tips? I'm also interested in the corporate-use context; if I can convince my company to switch to an alternative, I'll surely try.
111 comments
[ 0.29 ms ] story [ 10.3 ms ] threadThe CEO of Stripe also donated $1M to Omarchy.
Do we need another migration guide for Stripe since the CEO personally donated to Omarchy and then tell everyone to stop using Stripe and all of their services?
[0] https://www.patreon.com/violetblue/posts/how-to-migrate-1684...
They must be completely independent services that is an alternative to any of the companies that funded Omarchy.
https://world.hey.com/dhh/as-i-remember-london-e7d38e64
That this controversy goes three levels deep (DHH -> Omarchy -> Supporters of Omarchy (1Password)) is kinda funny to me. At what point does it stop?
> When wolves get out of control, you shoot them.
There isn’t more extreme than that. If you think that’s a normal way of talking about humans, I’m sorry but you’re very far down a radicalization rabbit hole
Most of the people back home wouldn't bat an eye at someone saying "They need to be deported", which is what DHH is saying.
> This has predictably led to these foreign vagrants setting up camp ...
> Copenhagen is the Danish capital. It's repeatedly been named the safest city in the world in recent years. Partly because it didn't tolerate vagrants ...
It would be easier to ask how this is a normal way of speaking? Gypsies is already a derogatory word, and he's making an issue of them not being local vagrants (what?). The decisions he's incredulous about came about democratically and the debates involved were carried out by public representatives and are publicly actually. The incredulity is just rhetoric and the implication that they're dangerous because they're foreign or live transiently surely has no place in a modern society.
> When wolves get out of control, you shoot them.
How is this in any way a non-extreme metaphor to use?
Vagrants and transients are often dangerous and mentally ill.
It is reasonable to use state violence to suppress crimes.
It is. The Romani aren't vagrants and they're doing nothing illegal. Calling them vagrants is charged and misleading.
> Vagrants and transients are often dangerous and mentally ill.
That can be true. Again the Romani aren't vagrants and using the word to describe then implies a level of danger and/or mental health issues that isn't evidenced.
> It is reasonable to use state violence to suppress crimes.
No-one has asserted otherwise.
> the control of dangerous animals being similar to the control of dangerous people is not extreme.
It's generally accepted the dehumanising a people or culture is extreme, I'm not sure how you can argue otherwise. There are any number of alternative metaphors that could have been used (not to mention that the argument could have been built on its own weight) that wouldn't have involved comparing an entire people to a pest that needs to be controlled with lethal force.
It never stops which is the problem. While DHH cannot be "cancelled", anyone who associates with him gets the backlash instead.
The real reason is that Omarchy has better marketing and is serious competition against the others distros, hence the reactions.
Expecting people should stop using "Ruby on Rails", Stripe, Dell, and so on and so forth is unrealistic.
Given the rapid attention to Omarchy and DHH, its quite an urgent matter...
The export is through CSV in clear. I wish they agreed to use some pkcs defined superencypherment and a json format so you could avoid the pass through plaintext.
Do this on a machine you trust, offnet I guess.
I imagine that a technical company can easily whip up a bespoke simplified interface for its non-technical staff too.
I've used it for about a decade at this point, and it's just perfect.
> 1Password has pledged $300,000 over three years in support of David Heinemeier Hansson's Linux distribution known as Omarchy, and is now a “distinguished corporate patron” of Omacom. What a nice brand partnership.
Supporting a Linux distribution sounds nice; I hadn't heard of that one.
But the very next paragraph:
> DHH has called for the ethnic cleansing of Europe; he is also an antivaxer, a Covid "truther," a proponent of the "lab leak" conspiracy theory, an 'anti woke' weirdo, and is virulently anti-DEI
> In an internal Slack message leaked to press today 1Password’s Roustem Karimov defended DHH as being attacked for his views...
Perhaps they could support a different Linux distribution.
It's also strongly concerning when someone defends someone with views like that, characterising them as being attacked. In general, toxic, racist, fascist views spread like viruses; when tolerated, through acceptance, they grow. A company needs to root them out. If we trust 1Password with our data, we are trusting a company with those views inside it with our data.
Leaving aside all the rest of this, I thought "lab leak" was considered a reasonable hypothesis, although not especially likely, these days, rather than some kind of fringe theory.
... so I think your framing there is too strong.
https://www.who.int/news/item/27-06-2025-who-scientific-advi...
Political right is the other way around.
It is not conclusively proven one way or the other, but most people just made their conclusion: left that it's the market, right that it's the lab (or bioweapon for especially out there).
I don't think it's just the fringes, at least it wasn't the case in 2022, now it's just not something many people talk about anymore
A lot of more reasonable people would have put 1% or 5% confidence on covid coming from a lab leak, saying roughly "It's unlikely, but hard to rule out because China isn't being transparent". And then ask for more investigation, which is exactly what happened.
So at no point was it rationally worth a 99% probability estimate, but it was worth investigation.
Calling something a conspiracy theory means rejecting its validity for investigation out of hand. Maybe you don't use it like that but that's how most people apparently use it.
> There was a point at which lot of people would have put 100% or 99% confidence that covid came from a lab leak
Why was? Now it is a point at which a lot of people put 100% confidence that covid came from a lab leak. And a lot of other people put 100% confidence that it was Wuhan market bat. And that's the problem I tried to express.
it doesn't mean it's true (we may never know), but framing as "conspiracy" was a product of conflict of interest where certain scientist were protecting grant money. Since then even some of the scientists who participated in it walked it back and openly said that both natural and lab leak theories were credible: https://www.science.org/doi/10.1126/science.abj0016
One of his criticisms was the virulent attacks on anyone that questioned policy during covid. He for example prefered the Danish approach and they still ended up doing better than the UK or US.
I also can't help but see the folks clamoring for mass migration for the past 2 decades in europe against popular will as anything other than blind oikophobes. If you'd look at my capital and other places you'd question who is actually calling for ethnic cleansing.
It does not read as twisting of his views: he has it right in writing on his blog. https://world.hey.com/dhh/wolves-sheep-and-gypsies-ba44af6a
Remember one of the tactics is to sound reasonable, while stretching what is acceptable speech. This lets those who approach with bad faith defend the statements while approving of what they imply or lead to.
I was called similar for much milder views and past caution. I stood by in discussion further in the past when people got attacked in that way lest id be perceived badly and out of line with my ohter progressive views. No caution was had. Now it's too late. You can't reasonably undo most of it. I honestly see my culture as a dead one down the line. All so we could supress wages, pretend to hold up a pyramid scheme whilst doing some social signaling.
That doesn't mean i should forget, forgive myself and others and go along. I've developed a strong dislike for the social cooling that got us there despite the opinions of the public. I no longer want to be overly nuanced and I am more than able to remember and throw back every past claim and defense regarding all this i read countless times a decade or 2 ago.
> vs talking about shooting wolves and calling for deportations using a word regarded as a slur
It's a stupid analogy. That said deportations within the law of foreign nationals that have no permission to be there is a historic normality the world over. The slur i can see tho i also don't give it much weight because I think it's one squarely on the euphemism threadmil. I used to argue your very point roughly a decade ago alongside an american against a polish friend who was very much opposed to them. Putting his grandma in the hospital over a bike, killing a mates dog along the whole cultural chasm with forced marriages and attitudes towards education and authority really didn't sit well which i could see. But i thought words have power and will worsen the situation. But in the end the word gypsies will be forced out of the vocab, zigeuner/cigany will go as well and then roma will be used with those conotations.
>Remember one of the tactics is to sound reasonable, while stretching what is acceptable speech. This lets those who approach with bad faith defend the statements while approving of what they imply or lead to.
And the opposite has happened as well and has had far far more impact. Curtailing what is acceptable speech to defend in bad faith and hide what it's all leading to.
Is this really true? Your data is presumably encrypted at rest on their servers; you're not "trusting" them with it any more than you're trusting S3 when you send encrypted blobs to it. The political alignment of Jeff Bezos doesn't really come into it.
You're certainly supporting them with your money - that seems like the real objection here.
Travelling is a little worse. I'd need to carry my little pocket book an risk losing it and now I can't lock my accounts, because I don't have the password for them (I could have a backup).
You know, I'm kinda talking myself into just doing passwords in a pocket book.
I don't like Bitwarden's UI as much as 1Password's, but at least it feels faster.
Before this I used Vaultwarden, but I was always a bit afraid of the self-hosting (of something this critical), and I really didn't like how you share credentials in BitWarden (through organizations), Proton Pass is much more intuitive with just straight up sharing of credentials or sharing whole Vaults.
What I don't like is the tight coupling to Proton's services, Pass should have had it's own credentials. But if you're not a Proton user that doesn't matter (or perhaps it doesn't matter t you in any case.)
But maybe that has changed in the meantime.
It has it's own credentials, it's optional: https://proton.me/support/pass-extra-password
https://world.hey.com/dhh/wolves-sheep-and-gypsies-ba44af6a
https://world.hey.com/dhh/as-i-remember-london-e7d38e64
Commenting isn’t worth it.
Probably the worst quote:
> When wolves get out of control, you shoot them. When gypsies take over public spaces, you deport them. This isn't hard, it isn't cruel. It's the basic logic of self-preservation. [0]
The comparison between shooting wolves here seems definitively bad tase and missing nuance.
[0] https://world.hey.com/dhh/wolves-sheep-and-gypsies-ba44af6a
[1] https://world.hey.com/dhh/as-i-remember-london-e7d38e64
If you were so inclined you read equivalent stuff in the Telegraph every week, so why go after DHH and his projects so enthusiastically? It just feels like there is something else going on.
Apple Passwords will store a user/pass combo for a site. That's it, feature list over.
1Password will let you configure how those things autofill, it provides an `op` CLI that you can use with service account tokens, you can store stuff like photos of your passports and licences, it understands 'Sign in with GitHub', it has per-user access per vault for shared accounts, you can add any number of extra fields to each entry, it integrates directly with Claude, it monitors your passwords against Haveibeenpwned, it'll tell you where you could be using 2FA and aren't … and the list goes on.
They are personal, meaning no user management or sharing of secrets.
They do not sync across devices -- or when they do, with restrictions like same browser/same OS only.
They cannot be used for e.g. commit signing or SSH login.
Just felt the need to post that.
Did I get myself into vendor lock-in, or are these items covered by those password manager exports?
The KeePassXC-Browser extension for Firefox and Chromium-based browsers is useful too: https://github.com/keepassxreboot/keepassxc-browser
KeePass does not offer sync and conflict resolution. This must be handled by your filesystem/OS/other tools. While this is typically not a problem for single users or very small groups, this can be catastrophic in company/group settings. So please think hard about whether you want sync/conflict resolution (server/client based solutions like Bitwarden/Vaultwarden) to be part of your Password manager – or not.
So hijacking the thread to ask if anyone has used Aliasvault [0] (no affiliation)?
[0] https://github.com/aliasvault/aliasvault
The entire thing has a smell to it, like theres some weird tax avoidance happening or something.
Just a guy's meh level config.
I feel like releasing a distro based around Niri and calling it Omarcomin
I thought about self-hosting Bitwarden, but I honestly don’t trust myself to maintain something security-critical (stay on top of patches and also be aware of supply chain attacks to revert patches and all that fun).
They have a way to use from Windows, have never tried it:
https://support.apple.com/guide/icloud-windows/set-up-icloud...