Ask HN: Advice on Migrating from 1Password?
Controversy over 1Password’s financial support for DHH’s Omarchy Linux distro and his recent political writings has prompted some users to consider leaving the service. Commenters weigh how much a vendor’s ethics and donations should influence tool choice, with some advocating boycotts while others argue for separating politics from product decisions. Alternatives mentioned range from self‑hosted vaults like Vaultwarden and Passbolt to KeePass variants, Proton Pass, Apple’s built‑in passwords, and even paper or deterministic generators, each with trade-offs in usability, security, and maintenance.
Controversy over 1Password’s Omarchy Sponsorship
- 1Password’s financial support of the Omarchy Linux distro triggers calls for migration guides away from 1Password, similar to how some would treat other companies that fund Omarchy.
- Some argue this “second/third‑order boycott” logic (e.g., boycotting services that use Stripe/Cloudflare because of Omarchy) is unrealistic; others say they’d like such mapping to choose “clean” alternatives.
- A few see backlash as partly driven by Omarchy’s marketing success and perceived competition with other distros.
Debate on Omarchy Creator’s Politics and ‘Canceling’
- Multiple comments link to blog posts by Omarchy’s creator describing migrants and Roma people in dehumanizing terms (e.g., predator metaphors, calls for mass deportation).
- Several participants label these views racist, extreme, and reminiscent of 1930s European far‑right rhetoric; others claim this is exaggerated and reflects common conservative anti‑immigration views.
- There is disagreement over whether supporting Omarchy or defending its creator’s views is sufficient reason to drop 1Password.
- Some denounce “online witch hunts” and reputational punishment extending to everyone associated with controversial figures; others stress that funding such projects is a moral line for them.
Product vs Politics
- One camp: “Use the best tool for the job”; politics of individuals or sponsors shouldn’t dominate tool choice.
- Opposing camp: refuses to pay for a service if money may support projects or rhetoric they find abhorrent, even if data remains technically secure.
- A few note that free/open‑source tools at least avoid their money being redirected in ways they oppose.
Migration Targets and Technical Options
- Popular alternatives mentioned:
- Bitwarden / self‑hosted Vaultwarden (with Caddy, OIDC, etc.).
- KeePass / KeePassXC / Password Safe (open format, many clients; but sync/conflict handling is external).
- Pass / gopass (Git + GPG‑based; great for technical users, weaker GUI/integration).
- Passbolt, Proton Pass, Apple’s built‑in Passwords, deterministic password generators, even paper notebooks.
- Concerns:
- Self‑hosting: patching, uptime, supply‑chain risk.
- Sharing workflows (Bitwarden orgs vs Proton Pass vault sharing).
- Vendor lock‑in around passkeys, SSH keys, masked email, and proprietary integrations.
Standalone Managers vs Browser/OS Passwords
- Standalone tools praised for:
- Cross‑platform use, richer secret types, sharing, CLI integration, and often stronger/easier‑to‑audit security models.
- Browser/OS managers criticized for:
- Limited features, weaker sharing, restricted sync, and—depending on vendor—non‑E2E defaults or closed implementations.