Live data from Hacker News

LogMeIn acquires Lastpass

blog.lastpass.com

291–300 of 443 posts

Re: LogMeIn acquires Lastpass

#291
post #82

Earlier quoted context omitted.

No, it doesn't and it seems that it doesn't have 2 factor authentication or yubikey supper

1Password stores its encrypted data 'offline', so 2FA does not make sense for their product. Even with LastPass offering 2FA, its just that, authentication, its not used as part of the encryption/decryption process (I did read somewhere it helps with your local cached copy, but it doesn't effect the copy stored on their servers) If you wanted to use your YubiKey with 1Password, you could set a static password and 'sp…

> 1Password stores its encrypted data 'offline', so 2FA does not make sense for their product.

Why doesn't makes sense in a mobile device?

> Even with LastPass offering 2FA, its just that, authentication,

Like Touchid

Re: LogMeIn acquires Lastpass

#292
post #191

A lot of folks only have experience with Logmein from the horrible way they handled transitioning users from the free to paid service. My company has used Logmein Central for remote access to hundreds of PCs for years. The core software is great, reliable, and has been ever since we started using it. The problem is that Logmein the company knows they're on top of the heap when it comes to remote management. They have…

I also remember when LogMeIn changed the number of users allowed in the free tier of Hamachi (a P2P VPN) -- it went from 10 to 5 with no notice, just randomly disconnecting half of the peers.

Re: LogMeIn acquires Lastpass

#293
post #212

Earlier quoted context omitted.

I actually did an evaluation of password storage services recently and chose LastPass over 1Password for a couple reasons: 1. 1Password is SUPER expensive for what it is. You really pay for the fact that it looks nice and integrates well with mac. 2. It has no enterprise level features (This is for my organization) such as user management, access logging and fine grained roles and sharing. 1Password might be good for…

If it's for an organization you should probably use KeePass, as all the data is kept locally by the organization. Allowing any third party access to sensitive passwords sounds like a bad idea.

My name is Eva Schweber and I work for AgileBits, the company that makes 1Password.

I would just like to clarify that AgileBits never gets access to your data or your Master Password. It is either stored locally on the user's machine or network or in his/her own Dropbox or iCloud account.

Re: LogMeIn acquires Lastpass

#294

Earlier quoted context omitted.

This isn't quite a reason to jump ship for me yet, but I'll certainly be duplicating work to other services(which so far, I've found to be quite inferior). Did you try 1Password (which works with Dropbox, Wifi sync, etc.)? Not affiliated with them, just a happy customer.

Give okeylabs a look. Not out yet but for the future.

Does it work with Linux, Windows or Android?

Re: LogMeIn acquires Lastpass

#295

Earlier quoted context omitted.

70€ is quite expensive

For the secure storage of hundreds of passwords that sit in front of insane amounts of personal information, with support for auto-filling on desktop and mobile, easy syncing, archive sharing, and more... It's really not that expensive for what you're trusting it with. Edit: not affiliated, but it has to be my #1 favorite application on any platform.

Hi themartorana,

My name is Eva Schweber and I work for AgileBits, the makers of 1Password. I just wanted to thank you for sharing your love of 1Password! We love our customers and with folks like you, is it any wonder why?

Re: LogMeIn acquires Lastpass

#296

Huh. Gotta admit, I'm rather distressed by this, but I'm trying to think through it logically. * They still don't have access to my raw passwords. Everything's already encrypted before it gets to them, and they don't have the key. They just store the encrypted data. * They however do control access to the account. This means there's a point where they get all sorts of data on me, and while I personally don't mind, I…

> They still don't have access to my raw passwords. > They however do control access to the account.

From point 2, point 1 is trivial to change. All they would need to do is update the extension or add some javascript (for the web login) to grab your master password in the clear.

Sure, a local password manager like Keepass could provide a new version that posted my p/w, key file, and DB up to a server somewhere, but I would have to manually install it, and it would have to get around a local program executable-firewall. No such challenges with auto-updating extensions and/or JS served from their server (or MITM.)

I don't know if the acquisition makes them more secure or less, but having worked at large companies, I tend to agree with:

> I must admit I felt a bit safer when I thought it was a smaller, purpose-built company managing things.

Re: LogMeIn acquires Lastpass

#297

Huh. Gotta admit, I'm rather distressed by this, but I'm trying to think through it logically. * They still don't have access to my raw passwords. Everything's already encrypted before it gets to them, and they don't have the key. They just store the encrypted data. * They however do control access to the account. This means there's a point where they get all sorts of data on me, and while I personally don't mind, I…

This isn't quite a reason to jump ship for me yet, but I'll certainly be duplicating work to other services(which so far, I've found to be quite inferior). Did you try 1Password (which works with Dropbox, Wifi sync, etc.)? Not affiliated with them, just a happy customer.

1Password is the only password manager that has been polished, feature complete, and low-impact enough to get me to actually use it. I gladly paid for it. If only all mobile browsers has easy ways for 1Password to integrate...

Re: LogMeIn acquires Lastpass

#298

Earlier quoted context omitted.

$12 a year vs. a one-time purchase. Just for clarification purposes.

One time purchase until the next major upgrade, then you need to pay more to stay up-to-date.

Hi Goronmon,

My name is Eva Schweber and I work for AgileBits, the folks who make 1Password.

While it is true that we think it is important for our potential customers to know that we may charge for a future version of 1Password, we have only done this once in the 9 years that 1Password has been available. And that was after a significant upgrade from 1Password 3 to 1Password 4 when we rewrote the entire app from scratch.

Customers who purchased 1Password 4 for iOS have received free upgrades (including Pro Features) to 1Password 5 and 1Password 6. The same is true for our 1Password 4 for Mac customers, who received 1Password 5 (our current version) for free.

Re: LogMeIn acquires Lastpass

#299
post #212

Earlier quoted context omitted.

This isn't quite a reason to jump ship for me yet, but I'll certainly be duplicating work to other services(which so far, I've found to be quite inferior). Did you try 1Password (which works with Dropbox, Wifi sync, etc.)? Not affiliated with them, just a happy customer.

I actually did an evaluation of password storage services recently and chose LastPass over 1Password for a couple reasons: 1. 1Password is SUPER expensive for what it is. You really pay for the fact that it looks nice and integrates well with mac. 2. It has no enterprise level features (This is for my organization) such as user management, access logging and fine grained roles and sharing. 1Password might be good for…

I haven't used it, but doesn't 1password support multiple vaults?

IE: your company makes a vault in a dropbox directory shared with employees, and multiple people just add that as a secondary vault?

conflicting changes are probably an issue though...

Re: LogMeIn acquires Lastpass

#300

My homegrown alternative to password managers like LastPass and 1Password: An encrypted zip file. The zip contains * encrypt.sh * payload, a folder containing subfolders, password text files and other personal information. To "unlock", extract the zip. To "lock", run encrypt.sh. Make sure that the extracted data won't get backed-up at any time. I just came up with this a few days ago. Let me know if you have any conc…

I would avoid using .zip file format encryption, who knows how safe that is. PGP as encryptor would probably be a better choice.
Post reply on HN