RE: https://hachyderm.io/@miketheman/116008792409955286

When I say TOTP is phishable and webauthn (“passkeys”) isn’t, this is a real-world example of what I am talking about

@glyph I wish regular password managers weren’t so flaky because they’ve trained me that they can’t be trusted to input the password and I’ll have to copy-paste into place at least occasionally
@porglezomp 1password is pretty good about this, but you have to know how to use it *really* well, and you have to regard "copy/paste into a field on a website" as an omega-level threat, rather than "basic, normal functionality of your computer" which is not in the muscle-memory of most people. https://mastodon.social/@glyph/115942437226812155
@glyph yeah I was very happy with 1Password but I didn’t want to jump into cloud subscription software and the legacy extension is rotting which is part of why I can’t rely on it. Also it never got good tools for merging different accounts that are actually the same. And Passwords.app has a different set of problems like occasionally disconnecting from my browser and being even worse at merging accounts.
@porglezomp I understand the trepidation about subscription software, but personally I am happy to subscribe. I want 1password to update to every new OS security feature, to always be available on lots of new devices, to be up to date and constantly responsive to evolving threats, and that involves a constantly-maintained service not just a drop-it-and-forget-it app purchase.
@glyph I was more opposed to the switch to only supporting online vaults than the subscription but I guess that’s always true with apple’s Passwords so I might as well switch back.
@porglezomp @glyph Just chiming in to a conversation that I wasn’t part of to agree that the “online vault only” bit was the objectionable part for me as well. I’m fine with 1password being a subscription since it’s pretty clear that they need to continually spend on maintaining it in a way that couldn’t be sustained by plain paid upgrades.
@griotspeak @porglezomp as I said, I get the trepidation. I actually use a few features that you can really only get from the "online vault" stuff (and, to be clear, there *is* an offline cache so you don't need to be literally connected to the Internet to access your data) but I can understand wanting a higher level of control over where your data is stored.
@glyph @porglezomp Ah yes I should have included that I do still use 1Password.