posted in Technology

1Password wades into a right-wing mess after funding a Linux project

1Password faced immediate backlash from customers this week over a $300,000 pledge in support of a Linux distro created by David Heinemeier Hansson, who has regularly published overtly racist blog posts that include comments calling for deportation of ethnic minorities in Europe. The popular password manager is now a “distinguished corporate patron” of Omacom, the nonprofit foundation that oversees a popular Linux distribution known as Omarchy.

Archive: archive.is/osNh3

www.theverge.com/tech/988536/1password-dhh-linux-controversy
enPage

Replying to @⁨ryper@lemmy.ca⁩

Nonetheless, it seems the company has sacrificed a moral position for a “mission-driven” position. In the same message to staff, Faugno says “the scale and growth of [Omarchy’s] use among our customers is significant - Omarchy has grown to be the second most used Linux distribution among 1Password users."

I didn’t know Omarchy existed until, like, yesterday, so this is surprising. Do 1Password users just tend not to use Linux, so second place isn’t many users?

Replying to @⁨jaygray91@piefed.zip⁩

that’s right, vaultwarden is the server. It’s not a bad idea to host it yourself, but this is kinda a critical service, and the clients are not too good in keeping the data accessible if the server goes down. so, choose wisely. there are also unofficial public bitwarden servers you can use. if that sounds better, choose one that hosts multiple services and has a community around it, those have a better chance of being kept alive.

Replying to an earlier post

My thought process is that I set up the server on my home computer as the main base, and have that occasionally sync to my other devices such as phone and laptop, and sync back to it if I do any changes in those. The remote devices should have local database because my main computer will not always be online.

How feasible is that and how easy is that to set up?

Or should I just set up keepass instead since IIRC that’s one of the ways it can be set up.

Replying to @⁨jaygray91@piefed.zip⁩

The remote devices should have local database because my main computer will not always be online.

yeah, about that. none of the official bitwarden clients allow editing if the server is not accessible. they didn’t want to have to deal with conflict resolution

Or should I just set up keepass instead since IIRC that’s one of the ways it can be set up.

sounds like a better idea. but synchronization wise, conflict resolution has to happen somewhere. like when you edit an entry on two devices, and later they try to sync both changes at once. Fortunately tye keepass format has a more comprehensive entry edit history than bitwarden, so clients can figure it out.
keepassxc on linux supports something called keeshare, check how is compatibility for that with your mobile keepass app. original keepass on windows supports some kind of automatic merging on saving and loading, maybe keepassxc does that too? if you end up using synthing, conflicts could occur at that layer, which is not hard but not so straightforward to handle, but keeshare is supposed to help with that I think.

Replying to @⁨jaygray91@piefed.zip⁩

if you have an always available central storage, and your keepass clients are never offline when you want to use them, I recommend to use that for storing the database file. but this is rare, and things can go wrong such that this central storage is not accessible, like network breaking down.

Otherwise, devices are online at different times, I would recommend using Syncthing, and then all devices can upload/download the database file when they see each other.

when using synthing, you’ll likely get into file conflicts, though. but it is predictable when will it happen, and you can avoid it if you are careful.
lets say, you edit the database on your phone, syncthing on it is sleeping for energy saving, you turn on your computer and you edit the database there too. then computer is kept running, and later the syncthing app on the phone wakes up. syncthing will see that the database file has changed on multiple devices, in a different way, and you will have to choose which one to keep.

if you can’t use keeshare of keepassxc, you’ll be holding your primary database on the syncthing folder. you will lose the changes made on one of your devices, depending on which one you discarded. but syncthing should save the discarded version with a special name, and I think, but you should check, the desktop version can handle this: if it has the database opened and unlocked, and you discard the local version in syncthing on your PC, resaving the database in keepass should merge the changes and no data is lost; if you have edited the same field of an entry on both devices, both values will be in the entry history. if this works this way, the conflict backup made by syncthing is nt needed.

if you can use keeshare, I believe discarding any of the versions in syncthing should fix it up eventually without data loss, because keeshare maintains a copy of the DB where your client can look for the “global state” of the DB, and always add anything to it that it deems to be new local changes not yet present in the global state. but the global state will only get eventually fixed up if all your devices will keep being able to sync to it; because if in the above scenario on your desktop you discarded the updated global state coming from your phone, to be able to accept the updated global state coming from your desktop, later your phone’s syncthing needs to be able to receive the global state you accepted elsewhere, potentially you will need to accept the remote changes here, then your keepass app needs to open the local database, process the global state database (updating it again with the local changes), and sync it to at least one other device (conflict free if there were no changes elsewhere in the meantime).
I don’t know how deletions are handled by keeshare. if it does not keep an index of deleted entries, then keepass on your local devices will keep readding the last version of this entry. that’s likely fine if it is only added back to the trash folder, and all devices know to delete it after a certain time being there.

Replying to @⁨ryper@lemmy.ca⁩

I feel like this has to be made up, downstream repack distros almost never show up on the top 10 usage stats. You will always see Ubuntu way ahead of Kubuntu.

Not to mention 1Password is a pretty popular enterprise app and I have yet to see some insane sysadmin actually roll with arch as their distro of choice. Most are probably on RHEL or some other enterprise derivative.

Replying to @⁨Zak@lemmy.world⁩

Terrible security record?

Of the items listed in your link, only the second one seems problematic, in that I wish they had discovered the (non-password but still privacy related) issues first. Even that section acknowledges all of the issues are fixed. The only section that makes it sound like there is still a problem is the last one, which states that version X still contains the vulnerabilities, but in reality that’s just how versions work. Patching a vulnerability creates a new version.

Is there ANY record of passwords being leaked from 1password because of their own lack of security??

Replying to @⁨Zak@lemmy.world⁩

lol what. 1Password literally has one of the best security records out there. They’re the ones actually inventing new more secure ways of doing things. The fact that those are all of the issues over the years and they’re one of the most popular pw managers on the planet is pretty indicative of how strong their security actually is. And they’ve never had a password breach, unlike lastpass.

Replying to @⁨ripcord@lemmy.world⁩

Per @GreenBeard@lemmy.ca’s comment

I think we all know why. Whether having money causes racism, or it just so happens that racists are the ones with the money and they’re good at keeping it “In The Family” so to speak is kind of tangential and academic. It’s the hateful bigots that have the cash to fund big things, so if you want funding, it pays to be trashy.

Replying to @⁨artyom@piefed.social⁩

I’m not OP but yeah, basically. People who are passionate about a specific topic will know what’s up in that area.

I can name half a dozen of the most popular Arch-based distros off the top of my head because… they’re actually well-known. Meaning they’ve been around for years, I’ve used several personally and can argue their pros and cons, and they feature prominently in objective lineups like the Steam Hardware Survey. Omarchy is none of these things.

Replying to @⁨Pxtl@lemmy.ca⁩

I’ve heard the name but have not spent the time to find out what it is. I thought it was some immutable distro. I think the same about bazzite and catchy (sp?) which are other distros I see mentioned from time to time and believe are immutable and flatpak-y and that’s all I know. I realise I’m just one data point but I never see a lot about these sorts of distros in my general browsing.

Replying to an earlier post

I don’t use password managers and I’ve never been exposed.

If your password is 16 characters with a letter, number, symbol, and is more than 1 word it will take millions of years to brute force. Just use multiple passwords and change the important ones every few months in case of data breach and you’re golden.

Forgot your password? If you have access to an email with multiple 2-factor you can recover any account in about a minute.

Replying to @⁨Axolotl_cpp@feddit.it⁩

It is currently more than that, and it even has its own repos/mirrors, but the fact that basically every rich person is throwing money at this project should be a huge warning sign to everyone to avoid this.

But at the end of the day, it’s nothing revolutionary. It’s customized Linux with a tiling window manager, all funded by billionaires and developed by a turbo racist.

Replying to @⁨jjlinux@lemmy.zip⁩

It’s popular to a lot of the non Foss tech job devs that want to try Linux after mostly using macOS for Dev work. It comes with keybinds they are familiar woth has a pretty UI by default and is arch base. They probably work for companies that are also right wing so it’s something they don’t care about as much as people in alignment with the Foss ideology.

Compared to today’s mask off fascism in the states the guy behind Omarchy is pretty tame and probably less mask off evil than the people they work for

Replying to @⁨titanicx@lemmy.zip⁩

You think if the developer bails out, the software will magically disappear from everywhere, leaving you with no way of recovery whatsoever?

Let’s say they decide to pull the plug. Everything you have that’s already running will keep running. Code can be forked (in fact with keepass, it already happened). Data can be exported after the fact. Other software can actually open keepass database file.

You really don’t see the difference between this and “the server stopped sending you your own data, oops”?

Replying to @⁨KullumDaue@lemmy.world⁩

I’ve had success on android with Syncthing. I had it installed on every device I needed the DB on and then a server that was always online to make sure each device had the latest version.

I have an iPhone now and Möbius Sync does not work as well (I think iOS limits background activity). My solution was to access access my DB via ssh (Strongbox has an option for this, Strongbox is KeepassXC but for Apple).

Replying to @⁨Jiral@lemmy.world⁩

distrowatch.com/dwres.php?resource=popularity

  • 12 mo: #21
  • 6 mo: #19
  • 3 mo: #16
  • 1 mo: #12

Obviously growing in popularity. That’s what aggressive marketing usually gets you.

If you don’t like that, perhaps consider stop talking about it, and him. Instead, every second day somebody writes an article about “DHH is fascist”. What the fuck do they think the effect of those articles is?

Are people actually so dumb that they think accusing him of fascism will make him disappear? That’s like high-octane clickbait fuel.

Same with Trump. It’s garmonbozia.

distrowatch.comDistroWatch.com: Put the fun back into computing. Use Linux, BSD.News and feature lists of Linux and BSD distributions.

Replying to @⁨abc@suppo.fi⁩

The DistroWatch Page Hit Ranking statistics are a light-hearted way of measuring interest in Linux distributions and other free operating systems among the visitors of this website. They correlate neither to usage nor to quality and should not be used to measure the market share of distributions. They simply show the number of times a distribution page on DistroWatch was accessed each day, nothing more.

Replying to @⁨thatsTheCatch@lemmy.nz⁩

I’ll just copy-paste the first paragraph in case you or anyone else can’t open it:

The English Wikipedia has decided to stop using archive.today and its related websites. This decision was agreed on after a request for comment with more than 200 participants concluded in February 2026, and is due to multiple concerns, including the site using editors’ and readers’ computers to run a denial-of-service attack and evidence that the website has tampered with some archived pages.

And the story on the DoS script itself:

gyrovague.com/…/archive-today-is-directing-a-ddos…

Replying to @⁨ryper@lemmy.ca⁩

I know about omarchy and seen that guy interviewed a couple of times. How the fuck am I just now aware he is a nazi? He seemed egotistical for sure, and his contribution to open source is … basically his personal dotfiles? I think that this shit was still completely devoid of extermination of minorities manifestos and hatespeech. But seriously how do you know if someone wants to kill refugees? why doesn’t he say so in the interviews or in the source code so we can know? This is fucked up. A faschist idea would be to keep a list. But omg, if you want to exterminate children that fled from war, please just say so in your dotfiles! Idk why this bothers me so… I really do care if my config was made by a hateful hand even if it doesn’t show

Replying to @⁨beernutz@lemmy.zip⁩

It’s like one of the founders of Mullvad VPN (very very rich OG Swedish hacker from way back when) came out as supporting a serious right wing nationalist party in Sweden a couple months back, he paid them like $500K to make sure they stayed in politics and won.

They are the best VPN, but I’m not coming back once my subscription expires.

What is even happening? Are we seeing something like a return to lead poisoning, but there some chemical in our environment that’s rotting people’s brains the same way but we don’t know about it just like we didn’t know about lead at first?

Replying to @⁨plsnerf7@lemmy.world⁩

All right windscribe.

Thing is with Mullvad is that I know for a fact that they don’t keep logs. The cops raided their place twice and they learned after that that there’s no point. They let them in and do whatever they wanted- they knew they wouldn’t find anything.

That type of trust is hard to come by.

Fuck nazis man, they infect the best of us. Such a copout. I suppose it’s something about… They get sentimental in their old years and remember a country that is no longer there- I feel that shit too, but I don’t get caught up in nationalist cosplay and LARP parties about it, shit changes, we need to fight for it without being fucking nazis. There’s a middle road here I feel.

Sorry, I just got rambling, didn’t mean to, but damn.

Replying to @⁨HostilePasta@lemmy.ml⁩

It’s FOSS and easy to set up. KeePass simply stores everything in a file and you use Syncthing to sync this file between devices. Syncing is optional, if you just need you password on desktop you don’t need it.

KeePass has pretty bad UX when compared with Bitwarden though. Bitwarden/Vaulwarden is the best solution IMHO but it’s really difficult to set up.

Replying to @⁨Takeshidude@lemmy.world⁩

KeePass honestly sucks for the most part. I love local vault and hope something better comes along, but KeePass UI constantly gives me issues. I’ve tried KeePassXC and that is what I use still, but being limited to opening a single entry at a time. Additional properties are a pain. It’s author not even understanding the need for using the desktop session for the CLI (requires passing password via the terminal to or having separate key file). KeeShare not working on Android. So many things that Bitwarden/Vaultwarden solves much better and quicker. Sad that Bitwarden/Vaultwarden didn’t make a local SQLite client that doesn’t rely on a server.

Replying to @⁨deft@lemmy.wtf⁩

So that every service I use can have a randomly generated, unique password. Therefore if one of them gets hacked and my password leaked, brute-forced, or decrypted, it won’t affect any other service.

Plus it stores passkeys and handles 2fa code generation, keeping them synced on all my devices, and ensures I never have to remember specific passwords because they’re all safely stored in heavily encrypted vaults guarded by the only single password I do have to remember. Also it notifies me if any of my information is in any breaches, or if I could do better to secure my account.

Trust me when I say, it’s safer, simpler, and smoother way to manage things.