Nicholas Tong1Password

03 / 46

1Password and the second secret

4 min read 956 words

Screenshot of the 1Password desktop app's login screen

I got 1Password wrong for about two years. I had it filed in my head as the expensive closed-source one, a subscription tax for people who liked rounded corners, and I said as much in more than one code review comment thread. Then a work project put me in a shop that ran it, I read their security design whitepaper the way I read everything, badly, at 1am, and I had to walk back my own take. The mechanism I had been ignoring is the whole product.

Individual runs $3.99 a month billed yearly, Families is $5.99 for five people. There's no free tier, 14 days of trial and then you pay or leave. Bitwarden costs $19.80 a year for the same broad feature set, so before anything else you deserve the argument for the difference.

the part everyone gets wrong

The comparison everyone makes is price, and it's the wrong axis. The difference is that 1Password encrypts your vault with two independent secrets.

The first is your master password, like every manager. The second is the Secret Key, a 128-bit random value generated on your device at account creation, shown to you once, and never transmitted anywhere. Your account password plus your Secret Key together produce the keys that decrypt your vault. Take the Secret Key out of the equation and a phished or guessed master password alone cannot open your data from a stolen sync blob, because there is no blob on any server that decrypts with the password by itself. Bitwarden derives everything from the password, hardens it with PBKDF2 or Argon2, and leans on 2FA at login instead. That's a legitimate design. It is not the same design.

The catch is symmetrical: lose both the Secret Key and every signed-in device, and 1Password cannot help you. Nobody can. There's no reset, by design, and the Emergency Kit, a printable PDF containing the Secret Key, is the product's real recovery story. Whether that trade suits you depends on whether you can be trusted with a piece of paper for a decade.

the mechanics

Locally, vault items are encrypted with AES-256-GCM, the password is stretched with PBKDF2-HMAC-SHA256 at 650,000 iterations, and authentication between client and server uses SRP so the password never crosses the wire in any usable form. Those details are in their published whitepaper, and external audits and a HackerOne bug bounty sit on top. What you don't get is source code. The clients are closed, and unlike Bitwarden I cannot read what I'm running, which is the actual cost of the polish, not the subscription.

The part that converted me is boring and developer-shaped: the SSH agent. 1Password 8 on macOS, Windows, and Linux can serve your SSH keys from the vault, per-key with its own authorization prompt, so a git push pops a dialog naming the exact key and host. My older habit, agent forwarding from a jump box because my keys lived on a machine I could not secure properly, was worse in every direction, and I knew it and did it anyway for about three years.

Watchtower, the breach and weakness checker, phones home by design. It compares your saved domains against breach data through 1Password's backend rather than shipping your vault anywhere, and they publish a privacy model for it that you can read. Updates, obviously, also phone home. I'm comfortable with both, and you should read their page and decide for yourself, since I could be wrong about the current specifics and if I am someone will tell me.

where it breaks

Everything above assumes you are a subscriber, forever. Version 8 ended the old standalone licenses, and the price hikes of 2023 landed on people who had structured their whole setup around buying once. I hear that grievance and mostly dismiss it, because paying roughly $48 a year for Families is a fair price for what the thing does, but the lock-in feeling is real and the export format is your only exit.

Other breakage, from a year of daily use:

  • The Emergency Kit is the failure mode. Mine lived in a photo on my phone for eleven months, which is the same as not having one, since the phone is the device I'd lose first. It's printed now and lives in a fire safe next to my dad's machinist calipers, tools he used for thirty years by the ship channel and that I will never have a reason to use.
  • The Linux app arrived years after the Mac one and still feels like the third port it is. Functional, occasionally clumsy.
  • Autofill is better than Bitwarden's extension, which is a low bar, and still fills wrong on the occasional stubborn iframe.
  • Analytics got added to the apps in 2023 with an opt-out, and people noticed. Opted out here.

what to do

  1. If you're already on Bitwarden with 2FA on the account, switching is optional. The Secret Key is better design, not magic, and $16 of annual difference doesn't buy security so much as it buys a different failure surface.
  2. If you switch: print the Emergency Kit the day you sign up, and store it somewhere physical.
  3. Turn on 2FA for the account regardless. The Secret Key covers decryption, 2FA covers login, and they are different doors.
  4. Developers: try the SSH agent before writing it off as a gimmick.
  5. Export a 1PUX file after your vault is migrated, and check it opens.

The lock screen screenshot on their marketing site shows a vault guarded by a face in a circle, and mine has guarded, at last count, 412 logins, one passport scan, and the wifi password for a taco trailer that no longer exists.

Print the Emergency Kit first, not after the vault is full.