Live data from Hacker News

LogMeIn acquires Lastpass

blog.lastpass.com

231–240 of 443 posts

Re: LogMeIn acquires Lastpass

#231

Huh. Gotta admit, I'm rather distressed by this, but I'm trying to think through it logically. * They still don't have access to my raw passwords. Everything's already encrypted before it gets to them, and they don't have the key. They just store the encrypted data. * They however do control access to the account. This means there's a point where they get all sorts of data on me, and while I personally don't mind, I…

This isn't quite a reason to jump ship for me yet, but I'll certainly be duplicating work to other services(which so far, I've found to be quite inferior). Did you try 1Password (which works with Dropbox, Wifi sync, etc.)? Not affiliated with them, just a happy customer.

Give okeylabs a look. Not out yet but for the future.

Re: LogMeIn acquires Lastpass

#232

Huh. Gotta admit, I'm rather distressed by this, but I'm trying to think through it logically. * They still don't have access to my raw passwords. Everything's already encrypted before it gets to them, and they don't have the key. They just store the encrypted data. * They however do control access to the account. This means there's a point where they get all sorts of data on me, and while I personally don't mind, I…

LastPass has a web interface, is also available as a browser plugin and when I tried it the only password they asked for was my account password.

So how come they don't have your raw passwords? Because of their web centric approach, I doubt that they are encrypting it locally. And regardless, LastPass is a proprietary thing, so you can consider your passwords to be compromised anyway.

Re: LogMeIn acquires Lastpass

#233

Earlier quoted context omitted.

This isn't quite a reason to jump ship for me yet, but I'll certainly be duplicating work to other services(which so far, I've found to be quite inferior). Did you try 1Password (which works with Dropbox, Wifi sync, etc.)? Not affiliated with them, just a happy customer.

Give okeylabs a look. Not out yet but for the future.

Looks like great future proofing. how do they deal with people who dont have an apple watch though?

Re: LogMeIn acquires Lastpass

#234

This really rubs me the wrong way. Do not like the idea of my password manager bouncing around owners. Or infrastructure changes that new owners often push on the acquired company. If there's one business I REALLY do not want to be moving about, and I want as little churn as possible for, it's a password manager. The thing I liked about LastPass was that it seemed like the highly geeky, less startupy approach to pass…

Dashlane looks really promising. Does anyone here have experience with it? Does it work as smoothly everywhere as LastPass did?

I'm not affiliated with Dashlane in any manner but I thought I'd chime in with my experience as a user. I used to use LastPass but lost a bit of confidence in them when they asked users to reset their master password [1] when an anomaly was found present in network traffic from one of their DBs. Prior to this I was looking at open source alternatives but the syncing and add-ons for each browser (which made logging in and generating passwords easier offered by Dashlane) really caught my attention. These features aren't unique to Dashlane, I'm sure. New sign-ups reap the benefits of premium features for a month or so, then you could send an invite to a friend and accrue 6 free months of premium service when they sign up (which is what I did) for free. They also offer a public password generator [2] page. They support the major browsers (Safari, Chrome, Firefox). Dashlane also has a "security dashboard" which keeps track of password expiration, reuse, and weak password usage, with a base analysis score that gets presented to you when action on a site is required. If you want something for offline use and that is hardware based, I'd recommend checking out the Mooltipass [3]. I hope this helps.

[1] - https://www.duosecurity.com/blog/breaking-down-the-probable-... [2] - https://www.dashlane.com/password-generator [3] - http://www.themooltipass.com/

Re: LogMeIn acquires Lastpass

#236
When I started my job I got a laptop with the extension for LastPass installed to Safari. One of the first things I encountered was an error dialog, modal for the entire Safari app, telling me of some nonsense problem with Lastpass, which at that point I hadn't even used yet! So I never started using it after that.

I occasionally use 1Password for the iPhone, but still mostly rely on the built-in OS X Keychain app. 1Password is too expensive for the Mac and all the other managers don't seem to place much emphasis on UX.

This class of application is quite poor to use overall. Even as nice as 1Password is, its syncing story is not very good.

Re: LogMeIn acquires Lastpass

#237

Earlier quoted context omitted.

This isn't quite a reason to jump ship for me yet, but I'll certainly be duplicating work to other services(which so far, I've found to be quite inferior). Did you try 1Password (which works with Dropbox, Wifi sync, etc.)? Not affiliated with them, just a happy customer.

Give okeylabs a look. Not out yet but for the future.

Can't watch their demo video -- blocked because of copyright infringement. Whoops.

Re: LogMeIn acquires Lastpass

#238

My first reaction to reading the title was "why?" After reading the article (and then reading it again) I'm not left feeling confident that this is in any way positive for me as a LastPass Premium and Xmarks customer. In particular the vague line about, "As we become part of the LogMeIn family over the next several months, we’ll be releasing updates to LastPass, introducing new features..." To me, LastPass is feature…

LogMeIn purchased, and absolutely ruined, Hamachi back in 2006. That program was the perfect lightweight virtual LAN client in existence with all the necessary features. Within months of acquisition, Hamachi had several "updates" and became bloated beyond recognition, slow, buggy, and downright unreliable. I have the worst taste in my mouth from what LogMeIn did to a perfectly working product and won't use anything t…

I forgot about Hamachi! I used to love that back in college, and you are right, they destroyed it. Salted the earth.

Re: LogMeIn acquires Lastpass

#239
And this is precisely why I'm not using other people's (proprietary) password managers.

And if you really have to pick a proprietary thing, then 1Password has always been better because it doesn't have an online component, syncs with Dropbox only if you want it to and whatever happens with the app, the Dropbox sync includes an HTML/JS interface that can read the dumped passwords, plus the format is documented.

Re: LogMeIn acquires Lastpass

#240

Huh. Gotta admit, I'm rather distressed by this, but I'm trying to think through it logically. * They still don't have access to my raw passwords. Everything's already encrypted before it gets to them, and they don't have the key. They just store the encrypted data. * They however do control access to the account. This means there's a point where they get all sorts of data on me, and while I personally don't mind, I…

LastPass has a web interface, is also available as a browser plugin and when I tried it the only password they asked for was my account password. So how come they don't have your raw passwords? Because of their web centric approach, I doubt that they are encrypting it locally. And regardless, LastPass is a proprietary thing, so you can consider your passwords to be compromised anyway.

They are encrypting it locally. It isn't anything to doubt- it's been shown time and time again.

Nowhere in the payload that gets sent to them is your key. The only way you could consider your passwords compromised is if you think there's already a rainbow table out there to decrypt everything, which is ludicrous.

Post reply on HN