Live data from Hacker News

LogMeIn acquires Lastpass

blog.lastpass.com

241–250 of 443 posts

Re: LogMeIn acquires Lastpass

#242
post #237

Earlier quoted context omitted.

Give okeylabs a look. Not out yet but for the future.

Can't watch their demo video -- blocked because of copyright infringement. Whoops.

Really? I can, what country are you in? At least there's animated sections under the main heading.

Re: LogMeIn acquires Lastpass

#243
post #154

Huh. Gotta admit, I'm rather distressed by this, but I'm trying to think through it logically. * They still don't have access to my raw passwords. Everything's already encrypted before it gets to them, and they don't have the key. They just store the encrypted data. * They however do control access to the account. This means there's a point where they get all sorts of data on me, and while I personally don't mind, I…

> "They however do control access to the account. This means there's a point where they get all sorts of data on me, and while I personally don't mind, I must admit I felt a bit safer when I thought it was a smaller, purpose-built company managing things." I've never really understood the appeal of account-based password managers. It was a startup and it needed a business model, sure, so from the company's perspectiv…

> The payoff is convenience

It's true for any level of password management. KeePass is less secure but more convenient than simply memorizing each of your long, secure passwords. Choosing less secure passwords or repeating passwords is more convenient than memorizing long, unique passwords.

Finding the right balance of convenience & security is critical for securing the myriad accounts of the "masses." We know that the average person isn't going to bother memorizing long unique passwords - even the most security conscious person won't do that (except for maybe a handful of super-critical passwords).

Re: LogMeIn acquires Lastpass

#244

I've been using an excel workbook that is stored in an encrypted image as my ways to manage passwords. How are these services that people mention in the comments, better at doing the same? Is there a better way someone has come up with to manage passwords where you don't have to rely on these services?

- they automatically fill login forms in browser. Nicer than copy/pasting things around and more secure: there's malware stealing clipboard contents, and you can also accidentally CTRL+V your password in chat window ;-)

- Excel has larger attack surface than purpose-built password managers. Have you checked Excel doesn't leave behind recovery copies of your passwords file in c:\windows\temp ?

Re: LogMeIn acquires Lastpass

#245

Earlier quoted context omitted.

Agreed. Logically, something like KeepassX ( https://www.keepassx.org/ ) is the most logical, secure choice. I think a lot of people pick Lastpass and such for the convenience of browser integration, but I don't think that's necessarily impossible with keepassx - just so happens that nobody is really working on it (which is a shame).

An important thing is that LastPass works on mobile.

Back when I first signed up for LastPass, the killer feature for me was that it worked on my BlackBerry Curve. The fact that they made versions of LP for damn near every platform is what sold it for me.

I don't have a BlackBerry anymore, though. Now might be the time to jump ship.

Re: LogMeIn acquires Lastpass

#246

I'd really love for some objective person to weigh in about why all the negative reaction to this. Is LogMeIn a terrible company? I have not used either LogMeIn or LastPass.

I don't really know but I'm surprised people liked using the thing to begin with. Always struck me as junky.

Re: LogMeIn acquires Lastpass

#247
There's something really odd happening with i18n on that blog. It recognizes my primary browser language as German and hence displays menue items and the right side bar in German. So far so good. However, it also partially translates the actual text into German, i.e. for some sentences the first word is translated while the rest remains English:

- Zunächst, we (LogMeIn/LastPass) have no plans ... - Zweitens, this acquisition provides us ... - Seitdem, LastPass has grown by leaps ...

Re: LogMeIn acquires Lastpass

#248
My homegrown alternative to password managers like LastPass and 1Password: An encrypted zip file.

The zip contains

* encrypt.sh

* payload, a folder containing subfolders, password text files and other personal information.

To "unlock", extract the zip.

To "lock", run encrypt.sh.

Make sure that the extracted data won't get backed-up at any time. I just came up with this a few days ago. Let me know if you have any concerns about this.

Here's the encrypt.sh: http://pastebin.com/DudVinms

Re: LogMeIn acquires Lastpass

#249
post #237

Earlier quoted context omitted.

Can't watch their demo video -- blocked because of copyright infringement. Whoops.

Really? I can, what country are you in? At least there's animated sections under the main heading.

Ah, im on mobile. Let me try chrome

Re: LogMeIn acquires Lastpass

#250

This is pretty terrible news. It would have been need to see LastPass get acquired by a company like AWS but LogMeIn doesn't really have the reputation required to ask people to trust them with all their passwords. Also, the valuation also seems low to me. Maybe LastPass was having trouble generating recurring revenue. It seems like going public would be a better route for security companies but maybe the revenue was…

LogMeIn has many years of experience securing their remote management software, something that has incredible potential for malicious activity. They seem like a good candidate for keeping LastPass secure, based on their reputation from a technical standpoint.
Post reply on HN