Ask HN: Advice on Migrating from 1Password?

2 points by 0xbadcafebee ↗ HN
I just found out that 1Password is donating $300,000 to a project founded by a very controversial person, and I'm looking to move to a different password manager.

Has anyone migrated from 1Password recently to another tool/platform? Have you had a good experience with any tools in particular? Any advice, tips? I'm also interested in the corporate-use context; if I can convince my company to switch to an alternative, I'll surely try.

111 comments

[ 0.29 ms ] story [ 10.3 ms ] thread
Here is the migration guide for 1Password. [0]

The CEO of Stripe also donated $1M to Omarchy.

Do we need another migration guide for Stripe since the CEO personally donated to Omarchy and then tell everyone to stop using Stripe and all of their services?

[0] https://www.patreon.com/violetblue/posts/how-to-migrate-1684...

Yes, why not?
A migration guide for all the services that funded Omarchy would be nice which the alternative must not do business with another service. (E.g, Alternative A to Cloudflare must not use Stripe, or Alternative B to Shopify must not use Cloudflare or Dell)

They must be completely independent services that is an alternative to any of the companies that funded Omarchy.

Thankfully, second order effect is a spectrum and not a black-and-white thing.
Huh, I guess TIL there is a controversy around Omarchy. I generally dismissed it as a serious distro after 5 second once realized it encourages using the AUR as your default package feed. The AUR is useful, but to me it’s something to be very aware of when you’re installing some software. Encouraging people to install everything through it is a crazy way to configure a distro. I just assumed it’s a distro for a very different target audience so kept my thoughts to myself
It's not really around Omarchy, but around DHH due to his political beliefs. I'm not deep into this, but I think the majority of the controversy stems from this article:

https://world.hey.com/dhh/as-i-remember-london-e7d38e64

That this controversy goes three levels deep (DHH -> Omarchy -> Supporters of Omarchy (1Password)) is kinda funny to me. At what point does it stop?

Wow. I just read this one now, and DHH really makes it hard to defend him. It's definitely possible to make this argument without likening groups of people to wolves and sheep...
(comment deleted)
Might be cause I'm from the Balkans, but I see nothing extreme here
You see nothing extreme with dehumanizing a group of people and comparing them to wolfs being killed?

> When wolves get out of control, you shoot them.

There isn’t more extreme than that. If you think that’s a normal way of talking about humans, I’m sorry but you’re very far down a radicalization rabbit hole

I've lived a large section of my life near a gypsy shantytown, and I would take a pack of wolves over gypsies literally any day of the week. I have had my house broken into around a dozen times (and I even recognize some of the ones that did it since they're repeat offenders and caught on tape numerous times), I've been held at knifepoint several times, I've witnessed them harassing the elderly endless times (always in large groups so that no one can do anything about it without getting stabbed), when the city decides to clean up the mountains of junk they throw in their surroundings, they simply do it again until the neighbourhood looks like it's next to a tornado-prone landfill, they steal anything and everything that isn't bolted down into the foundation (and even if it is), they actively reject any and all forms of help from well-meaning hippies and the gov't, they purposefully take their young children out of school so that they can be used as begging props instead and breed the never-ending cycle of destructive anti-social behavior, and I could keep going on for a long time.

Most of the people back home wouldn't bat an eye at someone saying "They need to be deported", which is what DHH is saying.

“Act in such a way that you treat humanity, whether in your own person or in the person of any other, never merely as a means to an end, but always at the same time as an end.”
Why is this extreme?
> Cue the gypsies in Copenhagen, and their increasingly brazen behavior, after the city legalized overnight sleeping in parks and other green areas last year. Because "it shouldn't be illegal to be homeless" ...

> This has predictably led to these foreign vagrants setting up camp ...

> Copenhagen is the Danish capital. It's repeatedly been named the safest city in the world in recent years. Partly because it didn't tolerate vagrants ...

It would be easier to ask how this is a normal way of speaking? Gypsies is already a derogatory word, and he's making an issue of them not being local vagrants (what?). The decisions he's incredulous about came about democratically and the debates involved were carried out by public representatives and are publicly actually. The incredulity is just rhetoric and the implication that they're dangerous because they're foreign or live transiently surely has no place in a modern society.

> When wolves get out of control, you shoot them.

How is this in any way a non-extreme metaphor to use?

Vagrancy is a crime in many places.

Vagrants and transients are often dangerous and mentally ill.

It is reasonable to use state violence to suppress crimes.

> Vagrancy is a crime in many places.

It is. The Romani aren't vagrants and they're doing nothing illegal. Calling them vagrants is charged and misleading.

> Vagrants and transients are often dangerous and mentally ill.

That can be true. Again the Romani aren't vagrants and using the word to describe then implies a level of danger and/or mental health issues that isn't evidenced.

> It is reasonable to use state violence to suppress crimes.

No-one has asserted otherwise.

> the control of dangerous animals being similar to the control of dangerous people is not extreme.

It's generally accepted the dehumanising a people or culture is extreme, I'm not sure how you can argue otherwise. There are any number of alternative metaphors that could have been used (not to mention that the argument could have been built on its own weight) that wouldn't have involved comparing an entire people to a pest that needs to be controlled with lethal force.

> At what point does it stop?

It never stops which is the problem. While DHH cannot be "cancelled", anyone who associates with him gets the backlash instead.

The real reason is that Omarchy has better marketing and is serious competition against the others distros, hence the reactions.

Expecting people should stop using "Ruby on Rails", Stripe, Dell, and so on and so forth is unrealistic.

Yes
Maybe you should tell Anthropic to not use Cloudflare or Stripe in their services, since they are in-directly funding Omarchy and move to some alternatives.

Given the rapid attention to Omarchy and DHH, its quite an urgent matter...

I don’t work for anthropic…
I migrated from an older 1password to self hosted bitwarden using premade configurations which are available for Portman and Docker in the usual places. Mine uses caddy for the Web front, which automates letsencrypt certification.

The export is through CSV in clear. I wish they agreed to use some pkcs defined superencypherment and a json format so you could avoid the pass through plaintext.

Do this on a machine you trust, offnet I guess.

Just encrypt your CSV after export with the tool of your choice.
Oh, I was only storing and using it in AWS KMS because of the pricing issue, but thanks for the comment. I’ll look into it a bit more.
Are people in your company moderately technical? If so, I highly recommend https://www.passwordstore.org/ coupled with a PGP key storage dongle (I personally use NitroKey). Then hosting is just a matter of hosting a minuscule git repo per user.

I imagine that a technical company can easily whip up a bespoke simplified interface for its non-technical staff too.

I've used it for about a decade at this point, and it's just perfect.

There's a bit of a jump here from something appearing good to rapidly becoming very very bad. Here's what I read:

> 1Password has pledged $300,000 over three years in support of David Heinemeier Hansson's Linux distribution known as Omarchy, and is now a “distinguished corporate patron” of Omacom. What a nice brand partnership.

Supporting a Linux distribution sounds nice; I hadn't heard of that one.

But the very next paragraph:

> DHH has called for the ethnic cleansing of Europe; he is also an antivaxer, a Covid "truther," a proponent of the "lab leak" conspiracy theory, an 'anti woke' weirdo, and is virulently anti-DEI

> In an internal Slack message leaked to press today 1Password’s Roustem Karimov defended DHH as being attacked for his views...

Perhaps they could support a different Linux distribution.

It's also strongly concerning when someone defends someone with views like that, characterising them as being attacked. In general, toxic, racist, fascist views spread like viruses; when tolerated, through acceptance, they grow. A company needs to root them out. If we trust 1Password with our data, we are trusting a company with those views inside it with our data.

> DHH has called for the ethnic cleansing of Europe; he is also an antivaxer, a Covid "truther," a proponent of the "lab leak" conspiracy theory, an 'anti woke' weirdo, and is virulently anti-DEI

Leaving aside all the rest of this, I thought "lab leak" was considered a reasonable hypothesis, although not especially likely, these days, rather than some kind of fringe theory.

I believe it was disproved, but regardless, there is a lot between accepting an hypothesis and possibly valid and building a conspiracy around it. I don't about this case, but this conspiracy typically degenerate in anti-science behaviours, perosonal attacks (on researchers or just chiense people) and similar nice things.
The lab leak isn’t considered reasonable outside of pundits as far as I’m aware. Unfortunately the pundits are the ones with the microphone
> “I thank each of the 27 members of SAGO for dedicating their time and expertise to this very important scientific undertaking over more than three years,” said Dr Tedros Adhanom Ghebreyesus, WHO Director-General. “As things stand, all hypotheses must remain on the table, including zoonotic spillover and lab leak.” [but] “the weight of available evidence…suggests zoonotic spillover”

... so I think your framing there is too strong.

https://www.who.int/news/item/27-06-2025-who-scientific-advi...

Thanks that was an interesting read
It's a result of political division in US. If you are on the left then you have to see lab leak as a racist rightie conspiracy theory or you will have issues fitting in. Also lab leak is rejected as a side effect from being confused with intentional leak/bioweapon theory, which is entirely radioactive.

Political right is the other way around.

It is not conclusively proven one way or the other, but most people just made their conclusion: left that it's the market, right that it's the lab (or bioweapon for especially out there).

It is both a racist rightie conspiracy theory and a plausible possibility worthy of serious consideration. Any reasonable person needs to recognize it as both simultaneously and will have no trouble fitting in among anyone outside the fringe at either end of the political spectrum.
It can't be two mutually exclusive things simultaneously.

I don't think it's just the fringes, at least it wasn't the case in 2022, now it's just not something many people talk about anymore

What is mutually exclusive about those two things?
"conspiracy theory" specifically means choosing the crazy explanation while more reasonable explanations exist. If you say the explanation is NOT crazy because it deserves investigation then it's automatically not a conspiracy theory.
"choosing" is the keyword here. You have to reason probabilistically. There was a point at which lot of people would have put 100% or 99% confidence that covid came from a lab leak. That's the conspiracy theory side.

A lot of more reasonable people would have put 1% or 5% confidence on covid coming from a lab leak, saying roughly "It's unlikely, but hard to rule out because China isn't being transparent". And then ask for more investigation, which is exactly what happened.

So at no point was it rationally worth a 99% probability estimate, but it was worth investigation.

What validity do you put on earth being flat? So that's the validity some people put on covid lab leak theory. You may be surprised.

Calling something a conspiracy theory means rejecting its validity for investigation out of hand. Maybe you don't use it like that but that's how most people apparently use it.

> There was a point at which lot of people would have put 100% or 99% confidence that covid came from a lab leak

Why was? Now it is a point at which a lot of people put 100% confidence that covid came from a lab leak. And a lot of other people put 100% confidence that it was Wuhan market bat. And that's the problem I tried to express.

COVID lab leak is not a conspiracy theory.

it doesn't mean it's true (we may never know), but framing as "conspiracy" was a product of conflict of interest where certain scientist were protecting grant money. Since then even some of the scientists who participated in it walked it back and openly said that both natural and lab leak theories were credible: https://www.science.org/doi/10.1126/science.abj0016

It's mostly extreme hyperbole and twisting of his views if anything.

One of his criticisms was the virulent attacks on anyone that questioned policy during covid. He for example prefered the Danish approach and they still ended up doing better than the UK or US.

I also can't help but see the folks clamoring for mass migration for the past 2 decades in europe against popular will as anything other than blind oikophobes. If you'd look at my capital and other places you'd question who is actually calling for ethnic cleansing.

I think caution re cultural integration, vs talking about shooting wolves and calling for deportations using a word regarded as a slur, are two different things. (Both these are within the same paragraph, adjacent sentences.)

It does not read as twisting of his views: he has it right in writing on his blog. https://world.hey.com/dhh/wolves-sheep-and-gypsies-ba44af6a

Remember one of the tactics is to sound reasonable, while stretching what is acceptable speech. This lets those who approach with bad faith defend the statements while approving of what they imply or lead to.

>I think caution re cultural integration.... are two different things.

I was called similar for much milder views and past caution. I stood by in discussion further in the past when people got attacked in that way lest id be perceived badly and out of line with my ohter progressive views. No caution was had. Now it's too late. You can't reasonably undo most of it. I honestly see my culture as a dead one down the line. All so we could supress wages, pretend to hold up a pyramid scheme whilst doing some social signaling.

That doesn't mean i should forget, forgive myself and others and go along. I've developed a strong dislike for the social cooling that got us there despite the opinions of the public. I no longer want to be overly nuanced and I am more than able to remember and throw back every past claim and defense regarding all this i read countless times a decade or 2 ago.

> vs talking about shooting wolves and calling for deportations using a word regarded as a slur

It's a stupid analogy. That said deportations within the law of foreign nationals that have no permission to be there is a historic normality the world over. The slur i can see tho i also don't give it much weight because I think it's one squarely on the euphemism threadmil. I used to argue your very point roughly a decade ago alongside an american against a polish friend who was very much opposed to them. Putting his grandma in the hospital over a bike, killing a mates dog along the whole cultural chasm with forced marriages and attitudes towards education and authority really didn't sit well which i could see. But i thought words have power and will worsen the situation. But in the end the word gypsies will be forced out of the vocab, zigeuner/cigany will go as well and then roma will be used with those conotations.

>Remember one of the tactics is to sound reasonable, while stretching what is acceptable speech. This lets those who approach with bad faith defend the statements while approving of what they imply or lead to.

And the opposite has happened as well and has had far far more impact. Curtailing what is acceptable speech to defend in bad faith and hide what it's all leading to.

> If we trust 1Password with our data, we are trusting a company with those views inside it with our data.

Is this really true? Your data is presumably encrypted at rest on their servers; you're not "trusting" them with it any more than you're trusting S3 when you send encrypted blobs to it. The political alignment of Jeff Bezos doesn't really come into it.

You're certainly supporting them with your money - that seems like the real objection here.

piece of paper
Dont know why you are getting downvoted, this is a valid method widely recomended in this day and age. The hacker cant hack your password book locked in your desk drawer!
It's not dumb, it's just a little inconvenient. My passwords are normally 50+ characters and pretty hard to type out, but I could fix that with "Correct Horse Battery Staple" passwords.

Travelling is a little worse. I'd need to carry my little pocket book an risk losing it and now I can't lock my accounts, because I don't have the password for them (I could have a backup).

You know, I'm kinda talking myself into just doing passwords in a pocket book.

I moved to self hosted Vaultwarden (Bitwarden server reimplementation that's client-compatible). You can also directly run Bitwarden, but Vaultwarden is easier to self-host, especially OIDCwarden is nice if SSO is your cup of tea.

I don't like Bitwarden's UI as much as 1Password's, but at least it feels faster.

OIDCwarden still requires two passwords :(
unix passstore is perfect
I really enjoy Proton Pass (but I have a paid subscription so I have passmail aliasses as well). I've been going full passkeys recently, no issues yet.

Before this I used Vaultwarden, but I was always a bit afraid of the self-hosting (of something this critical), and I really didn't like how you share credentials in BitWarden (through organizations), Proton Pass is much more intuitive with just straight up sharing of credentials or sharing whole Vaults.

What I don't like is the tight coupling to Proton's services, Pass should have had it's own credentials. But if you're not a Proton user that doesn't matter (or perhaps it doesn't matter t you in any case.)

Im a happy Proton customer since a decade for their email and recently file storage service, but I’m concerned about having my passwords and my files and my emails in the same system. It’s risky to have so much in one company, if I lose my proton access for some reasons I’m out of everything
[delayed]
I've been off vaultwarden for 2 years now I guess, but I remember that having to share cedentials with my wife I had to make an organization in the admin interface. Then add us both to that org. There was no sharing of just 1 credential, or a group or something like that. It feels like a more formal system, perhaps better at home in an enterprise.

But maybe that has changed in the meantime.

IMO choosing products over politics is a pointless game. Use the best tool for the job.
Can I assume that you’re not someone affected by DHH’s abhorrent views?
I do not know who DHH is so I assume you are correct!
100%, but this is unimaginable on HN :)
This goes both ways; I'm forced to use Basecamp, and I find it an unpleasant, poorly designed tool.
This anti-DHH movement is so weird to me. People seem to read summaries of his views, often based on interpretations that get exaggerated from one article to another until they become something else entirely. At least read the articles yourself, including his other work, so you don’t just cherry-pick the ideas that conform to your existing beliefs. Then form your own opinions.
HN rivals Reddit wrt extreme left and woke views. Shadow of its former self.

Commenting isn’t worth it.

Does DHH actually deserve to be cancelled, or Omarchy "defunded"? I just read the OOOL on Reddit, and I have to say that I am not entirely convinced. https://www.reddit.com/r/linux/comments/1oa74wh/im_out_of_th...
He did post at least two blog posts with very questionable political standpoints, while also not displaying a high level of critical thinking, one could say. Not sure where the point of „should be cancelled“ is reached, but doesn’t paint the best picture of him to say the least.

Probably the worst quote:

> When wolves get out of control, you shoot them. When gypsies take over public spaces, you deport them. This isn't hard, it isn't cruel. It's the basic logic of self-preservation. [0]

The comparison between shooting wolves here seems definitively bad tase and missing nuance.

[0] https://world.hey.com/dhh/wolves-sheep-and-gypsies-ba44af6a

[1] https://world.hey.com/dhh/as-i-remember-london-e7d38e64

(comment deleted)
Not sure what'll convince you then, if DHH's own rant against immigrants and roma doesn't.
It's amazing that even after the Holocaust, prejudice against Roma is so prevalent in allegedly polite society.
I don't know. Something just feels... "off" about it?

If you were so inclined you read equivalent stuff in the Telegraph every week, so why go after DHH and his projects so enthusiastically? It just feels like there is something else going on.

Oh fuck, 1Password is also part of the DHH crowd?!
(comment deleted)
Been using DropBox + Keepass for over a decade now.
n00b question I guess but what is the value of a standalone password manager? Seems like most browsers and operating systems offer this capability nowadays.
1Password offers a lot more functionality than, say, Apple Passwords.

Apple Passwords will store a user/pass combo for a site. That's it, feature list over.

1Password will let you configure how those things autofill, it provides an `op` CLI that you can use with service account tokens, you can store stuff like photos of your passports and licences, it understands 'Sign in with GitHub', it has per-user access per vault for shared accounts, you can add any number of extra fields to each entry, it integrates directly with Claude, it monitors your passwords against Haveibeenpwned, it'll tell you where you could be using 2FA and aren't … and the list goes on.

To not be tied to a single machine or OS
Google Password Manager, the one built into Chrome, doesn't even do end-to-end encryption by default. You have to go into the settings and opt in to encrypt your password data before it gets sent to Google. And since it's closed source, you also just have to take Google's word for it.
Browser password apps are not suited to just store secrets not related to logins.

They are personal, meaning no user management or sharing of secrets.

They do not sync across devices -- or when they do, with restrictions like same browser/same OS only.

They cannot be used for e.g. commit signing or SSH login.

Well, I'm staying exactly where I am. I'll be keeping my company on 1password, and my family too, because I think it's a good product. I don't personally use Omarchy, but I welcome anything that can bring more people to linux on the desktop, so I support that too. I don't agree with everything DHH says, but I absolutely despise online witch hunts so I guess I support him too just on principle.

Just felt the need to post that.

Make sure you look closely into politics of anybody connected to the password manager you are switching too, it could be even worse!
Very true. Linux is overrun by leftist who will ban you from their forums / software for your politics. Definitely don't want to be supporting people who hate you.
Passkeys, SSH keys, Fastmail's masked email integration.

Did I get myself into vendor lock-in, or are these items covered by those password manager exports?

KeePassXC or Bruce Schneier's Password Safe. The nice things about Keepass* is that the format is an open standard with multiple implementations and if any one turns out to be a problem, you can switch easily.
Whenever I see KeePass mentioned as an alternative I think we should add this disclaimer:

KeePass does not offer sync and conflict resolution. This must be handled by your filesystem/OS/other tools. While this is typically not a problem for single users or very small groups, this can be catastrophic in company/group settings. So please think hard about whether you want sync/conflict resolution (server/client based solutions like Bitwarden/Vaultwarden) to be part of your Password manager – or not.

KeePassXC has a merge feature for this scenario. Apps like Strongbox (macOS/iOS) merge automatically while saving. And I believe there are more apps doing this.
I've been using Bitwarden for close to a decade now, and it still works, but given silent documentation changes and increasingly opaque communication following the CEO change, I started considering self-hosting. While vaultwarden exists, and would be the obvious choice, I started shopping around as well.

So hijacking the thread to ask if anyone has used Aliasvault [0] (no affiliation)?

[0] https://github.com/aliasvault/aliasvault

Apart from everything about DHH, I personally feel like the choice to invest so much money in Omarchy, of all things, shows a lack of good technical sense from the folks at 1pw. If you’re doing charitable giving, why not give to an established product that will be around in 10 years time, or one that provides core technology the other linux distros depend on? I don’t want the money I spend on 1pw going to some poorly chosen bet on a vibecoded distro, just because it’s in the SV hype limelight at the moment.
Exactly, Omarchy is little more than a wrapper around Arch, why not just donate to Arch directly?

The entire thing has a smell to it, like theres some weird tax avoidance happening or something.

Not even a technically well executed wrapper around Arch.

Just a guy's meh level config.

I feel like releasing a distro based around Niri and calling it Omarcomin

Let's see your work that has brought in thousands of new people to Linux?
Because Arch itself is run by a cesspool of leftist idealogs that will ban anyone that disagree with them politically. - They banned the XLibre project from the Arch wiki and repos - They rejected DHH's offer to work together to improve the Arch AUR and to work on aarch64 support for mainline.
I set up a Passbolt server. Took less than an hour to set up and then migrate all my passwords from 1Password. Free since it is open source.
Yeah, I've been pretty impressed with Passbolt in testing. Currently running Vaultwarden but quite tempted by Passbolt.
Apple’s built in passwords app. It’s basic, but it’s fine. I trust Apple’s security team way more than I trust pretty much any other company on this.

I thought about self-hosting Bitwarden, but I honestly don’t trust myself to maintain something security-critical (stay on top of patches and also be aware of supply chain attacks to revert patches and all that fun).