All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
1Password built its reputation by asking customers to place their most sensitive information inside its vaults. Now, some of those customers are looking for the exit.
The password manager is facing backlash over a $300,000 pledge to the Omacom Foundation, which oversees a Linux distribution created by developer David Heinemeier Hansson.[1]
In a July blog post, Hansson compared Roma migrants in Copenhagen to wolves preying on sheep.[2]
“When wolves get out of control, you shoot them,” he wrote. “When gypsies take over public spaces, you deport them.”
Those remarks have made 1Password’s donation radioactive. Customers have announced cancellations, employees have reportedly objected internally, and alternative password managers are being suggested en masse.
Customers are canceling and recommending alternatives
Take your passwords somewhere you can trust
How to move from 1Password to Bitwarden safely
Should you leave 1Password?
Why did 1Password donate $300,000?
The donation made 1Password a “distinguished corporate patron” of Omacom, the nonprofit foundation behind Omarchy.
Omarchy is Hansson’s customized Linux distribution based on Arch Linux. It has a selection of preinstalled applications and settings chosen by Hansson, including prominent support for 1Password.
According to an internal message reported on by The Verge, 1Password CEO David Faugno told employees that Omarchy had become the second-most-used Linux distribution among the company’s customers.
Faugno wrote, “Our donation is not in any way an endorsement of his personal views or conduct," and clarified that the donation is "to the Omacom Foundation" rather than Hansson himself.
That distinction has failed to reassure many customers.
The controversy surrounding Hansson was already well documented. Duke University Libraries stopped using Basecamp in 2023, citing “harms” perpetuated by the leadership of its parent company, 37signals, which Hansson co-owns.
Customers are canceling and recommending alternatives
The backlash quickly spread across Reddit communities focused on technology, privacy, and 1Password itself.
In a r/technology discussion, one user said they had already acted, “I decided to also migrate to Bitwarden after reading the article and your post. Whole process took me ~30 minutes.”
Other commenters recommended Proton Pass, KeePassXC, and Apple Passwords. One former subscriber said they had canceled an $80-per-year plan and would use Apple’s built-in password manager instead.
The controversy also revived debate over 1Password’s closed-source software, as opposed to the preferred open-source alternative.
“Anyone serious about privacy should not be using a closed source offering for something as important as passwords,” one commenter argued in r/privacy.
It remains unclear how many paying customers have left.
Take your passwords somewhere you can trust
If 1Password has lost your confidence, Bitwarden offers a secure, transparent alternative.
Its open-source password manager uses end-to-end, zero-knowledge encryption, meaning Bitwarden cannot access your passwords or vault contents. Its security claims are reinforced by published third-party audits and penetration tests.
The free plan lets you store unlimited passwords across unlimited devices, generate strong credentials, manage passkeys, and autofill logins across major browsers and operating systems. Premium costs $1.65/mo and adds an integrated authenticator, emergency access, file attachments, and security reports.
Switching is straightforward, too. Bitwarden provides a dedicated 1Password importer, so you can transfer your vault without rebuilding it login by login.
How to move from 1Password to Bitwarden safely
Bitwarden provides an official migration guide for 1Password users. In general, you will need to:
- Create and secure your Bitwarden account.
- Export your data from the 1Password desktop app.
- Import the resulting 1PUX file into Bitwarden.
- Confirm that your logins, secure notes, one-time passwords, and other important items transferred correctly.
- Delete the export file immediately.
- Remove your information from 1Password and cancel only after verifying the new vault.
That fifth step is critical. The 1PUX format stands for “1Password Unencrypted Export.” Anyone who obtains the file may be able to read the passwords and other information inside it.
Do the migration on a trusted, malware-free device. Avoid placing the export in a cloud-synced folder, emailing it to yourself, or leaving it in your Downloads folder. Securely delete it as soon as the import is complete.
Attachments and certain item types may need to be transferred manually. Check several important accounts and make sure autofill, passkeys, and two-factor authentication codes work before deleting anything.
Should you leave 1Password?
You do not need to abandon 1Password because your vault suddenly became unsafe. Available evidence does not support that conclusion.
Leaving still makes sense if the donation destroyed your confidence in the company or crossed a personal ethical line. Password managers hold unusually sensitive positions in their customers’ lives, and trust involves more than an encryption algorithm.
Bitwarden provides a secure, open-source alternative with a free plan and a documented migration path. Take the transfer slowly, and protect the unencrypted export file along the way.
Whatever you decide, keep using a dedicated password manager. Returning to reused passwords, browser notes, or a spreadsheet would create a much more immediate security risk than either side of this controversy.
[1] 1Password wades into a right-wing mess after funding a Linux project
[2] Wolves, sheep, and gypsies