PSA: 1Password uses “1Password.co” for email links — instead of their usual “1Password.com” domain. Craig isn’t an idiot; it 100% feels like phishing. If you ask me, tracking link clicks and opens in emails is simply not worth the potential freak-out when you think you’ve been phished, please tell the marketing team to pound sand (respectfully)

From: @chockenberry
https://mastodon.social/@chockenberry/112049988291729734

@cabel Unluckily 1Password went 100% the enshitifcation way. Loved it and happily paid for it. But now there is no trust left.
@masek @cabel Care to elaborate? What did they do to lose your trust?

@rmasoni @cabel Because they now force me to store my passwords with them.

I always separated storage and software manufacturer in order to avoid problem should one become corrupted.

With version 8 they stopped supporting that: no more local vaults, no vault on DropBox.

They did that in order to receive recurring revenue. I have no problems with them getting money from me on a regular basis. But the way they enforced that is detrimental to the security.

If 1Password falls, I lose too much. This is a cluster risk.

@masek @cabel Oh, I see. Thanks for sharing. Did you migrate to another service? I was tempted by Minimalist.
@rmasoni @cabel Bitwarden with locally hosted Vaultwarden (as Container on QNAP NAS).

@masek @rmasoni @cabel please make sure you have working backups. And a working restore.

If your nas dies...

@jan @rmasoni @cabel

  • I sync from my primary NAS to my secondary NAS daily
  • Once per quarter I make a backup on a disk which I store in a bank safe