Earlier quoted context omitted.
same here. Trialling Dashlane, but not quite convinced yet..
If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).
LastPass RCE vulnerability fixed
111–120 of 188 posts
Re: LastPass RCE vulnerability fixed
#112Earlier quoted context omitted.
That is honestly embarrassing. I'm glad I don't use LastPass.
I do. What else does auto form fills based on urls, client side encryption, and runs in chrome, IE and Safari?
Re: LastPass RCE vulnerability fixed
#113Earlier quoted context omitted.
same here. Trialling Dashlane, but not quite convinced yet..
what is your hesitation with dashlane?
Re: LastPass RCE vulnerability fixed
#114Re: LastPass RCE vulnerability fixed
#115Earlier quoted context omitted.
Isn't sharing passwords a bad thing to do in general? Each user should have a separate account/identity and manage his own secrets.
There are endless online services which only allow one user per logical account. In fact I would say the majority of them do it.
Re: LastPass RCE vulnerability fixed
#116Earlier quoted context omitted.
I do. What else does auto form fills based on urls, client side encryption, and runs in chrome, IE and Safari?
I would suggest not using the auto fill feature of password managers. I use 1Password and the mini UI that sits in the tray is super easy to copy a password from and paste in the browser.
Re: LastPass RCE vulnerability fixed
#117Earlier quoted context omitted.
bitwarden is currently sponsored by the Microsoft BizSpark program which covers many of our operation costs and allows us to offer services for free to our users. We are working to introduce enterprise features for businesses in the future (scheduled for release next month) which will allow us to monetize. In the meantime, everything is free for users.
Which of the current free-for-everyone features, if any, are you considering making available to paid accounts only? (i.e., what will your current free users lose unless they move to a paid account once you monetize?)
Re: LastPass RCE vulnerability fixed
#118Earlier quoted context omitted.
Woo! I just got app-fill working. To be clear though, app-fill and auto-fill were referring to different things. What I meant by lack of "auto-fill" was that when I visit a website on desktop, my details aren't instantly filled when the page loads. I have to manually click the extension icon in my browser and select the account I want.
This is not always a bad thing. Sometimes you don't want software to automatically plunk your login credentials into appropriately named fields on a JavaScript driven web page
Re: LastPass RCE vulnerability fixed
#119Update: another vulnerability found, not patched yet. https://mobile.twitter.com/taviso/status/844312124541186048
Re: LastPass RCE vulnerability fixed
#120Earlier quoted context omitted.
That is honestly embarrassing. I'm glad I don't use LastPass.
I do. What else does auto form fills based on urls, client side encryption, and runs in chrome, IE and Safari?