I'm really disappointed to see #bitwarden falling into the slop hole. Can anyone recommend a #passwordmanager , ideally #selfhosted , that doesn't use LLM slop in its core product, OR in its contributing commits?
#askfedi

@violet @astraluma

1Password has been awesome, my polycule’s resident techspert has had it running locally for ages (well, locally in the cloud, but eh. Not through another server)

@Beckydog @violet @astraluma isn't it proprietary software? i would argue against using proprietary software for anything, especially anything security-sensitive

also, if you go to
1password.com

@lumi @Beckydog @astraluma you are working better than I can this morning. Even researching adjacent to the slop is melting my brain 😭😭😭

Thanks Lumi

@violet @Beckydog @astraluma ofc ​​

@lumi @violet @astraluma

I can only speak from a user point of things, but there’s no Ai in it afaik!

@Beckydog @violet @astraluma sadly, it's not like you can check, as it is proprietary software. and from their website, it seems like they do embrace it, so i think there is a high likelihood there is genai-generated code in it

@lumi @Beckydog @violet i wouldn't equate "shipping features or solutions for AI" to "going all-in on genAI"

in the context of this bubble and having investors, having some kind of AI thing is pretty much a requirement for a tech company.

But 1pass has always been big on developer, automation, servers, etc, so them re-spinning those existing features for AI would have low impact on their product.

@astraluma @Beckydog @violet if we assume that 1password cares about ethics, this is a good argument

but they're proprietary software, so i don't buy it

@lumi @Beckydog @violet you don't need ethics to be against AI?

You can be against on the basis of "new hype technologies have a history of being immature and risky" or "genAI code tends to lack nuance and be kinda crap, and we're a security product" or "we use a B-list tech stack, and the AI just isn't very good at it"

@astraluma @Beckydog @violet i guess i'm less optimistic about it

@lumi @Beckydog @violet that's valid

but no situation has been improved by overestimating the risks

and yes, ultimately, it is all proprietary code and we can only speculate.

but so far, all I'm seeing is that 1password is only shipping AI integrations. Which is basically the same as Just's MCP server https://just.systems/man/en/model-context-protocol.html

Model Context Protocol - Just Programmer's Manual

@lumi @Beckydog @violet if your goal is nothing that even acknowledges AI, yeah, 1pass does that.

but like i said elsethread, it's going to be real hard to do non-trivial computing with that standard in this moment

@astraluma @Beckydog @violet that is definitely fair. it being proprietary is a much bigger no-no to me