Earlier quoted context omitted.
There have not been any formal third-party audits done that we can document yet, however, the product is entirely open source (from the database, backend apis, to all client-side applications). https://github.com/bitwarden . Anyone is free to audit (and contribute) as much as they'd like. If you can get Travis (or any security researcher) interested in reviewing our products we would love to work with him.
Thanks. Are there any plans to have routine security audits done?
LastPass RCE vulnerability fixed
41–50 of 188 posts
Re: LastPass RCE vulnerability fixed
#42Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.
Re: LastPass RCE vulnerability fixed
#43Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.
Not sure about point 2, but 1Password seems to fit all the others. Really like it, personally.
Re: LastPass RCE vulnerability fixed
#44Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.
Not sure about point 2, but 1Password seems to fit all the others. Really like it, personally.
Re: LastPass RCE vulnerability fixed
#45Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.
It encrypts your passwords with your GPG key and stores them in a git repository. You can of course easily extend this to do a lot of different things.
I also wrote this tool for automating password rotation:
Re: LastPass RCE vulnerability fixed
#46Looks like this was discovered by the same guy that discovered CloudFail. That dude is amazing.
Look at all his bugs: https://bugs.chromium.org/p/project-zero/issues/list?can=1&q...
Re: LastPass RCE vulnerability fixed
#47Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.
Not sure about point 2, but 1Password seems to fit all the others. Really like it, personally.
Re: LastPass RCE vulnerability fixed
#48Earlier quoted context omitted.
The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.
same here. Trialling Dashlane, but not quite convinced yet..
Re: LastPass RCE vulnerability fixed
#49Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.
Not sure about point 2, but 1Password seems to fit all the others. Really like it, personally.