Live data from Hacker News

LastPass RCE vulnerability fixed

bugs.chromium.org

41–50 of 188 posts

Re: LastPass RCE vulnerability fixed

#41

Earlier quoted context omitted.

There have not been any formal third-party audits done that we can document yet, however, the product is entirely open source (from the database, backend apis, to all client-side applications). https://github.com/bitwarden . Anyone is free to audit (and contribute) as much as they'd like. If you can get Travis (or any security researcher) interested in reviewing our products we would love to work with him.

Thanks. Are there any plans to have routine security audits done?

As we bring some of our revenue generating features online we hope to have the cash flow to fund regular third-party audits.

Re: LastPass RCE vulnerability fixed

#42

Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.

Not sure about point 2, but 1Password seems to fit all the others. Really like it, personally.

Re: LastPass RCE vulnerability fixed

#43

Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.

Not sure about point 2, but 1Password seems to fit all the others. Really like it, personally.

1Password didn't support Linux last time I checked. There are 3rd party libraries, but most of them don't support the newer keychain format. I still use it and just look up the password on my phone when I'm on a Linux system.

Re: LastPass RCE vulnerability fixed

#44

Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.

Not sure about point 2, but 1Password seems to fit all the others. Really like it, personally.

I believe 1Password only supports Windows and OS X on the desktop.

Re: LastPass RCE vulnerability fixed

#45

Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.

I can't help you with #4, but I've been a pass user for a long time: https://www.passwordstore.org/

It encrypts your passwords with your GPG key and stores them in a git repository. You can of course easily extend this to do a lot of different things.

I also wrote this tool for automating password rotation:

https://github.com/SirCMpwn/pass-rotate

Re: LastPass RCE vulnerability fixed

#46
post #3

Looks like this was discovered by the same guy that discovered CloudFail. That dude is amazing.

Look at all his bugs: https://bugs.chromium.org/p/project-zero/issues/list?can=1&q...

This is golden:

https://bugs.chromium.org/p/project-zero/issues/detail?id=69...

Re: LastPass RCE vulnerability fixed

#47

Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.

Not sure about point 2, but 1Password seems to fit all the others. Really like it, personally.

I imagine 2. works if you buy the enterprise options?

Re: LastPass RCE vulnerability fixed

#48
post #9

Earlier quoted context omitted.

The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.

same here. Trialling Dashlane, but not quite convinced yet..

It uses soo much memory and there is obvious UX mistakes everywhere like you can add new sites in client but not generate passwords. Dashlane really worried me sadly.

Re: LastPass RCE vulnerability fixed

#49

Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/Linux support 2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc. 3. Reasonably secure 4. Not too terrible to use for Engineers/non-techies alike.

Not sure about point 2, but 1Password seems to fit all the others. Really like it, personally.

1password along with seemingly every other mobile password manager slips up from time to time. Turn around time once something is disclosed is my main concern.

https://team-sik.org/trent_portfolio/password-manager-apps/

Post reply on HN