Earlier quoted context omitted.
I do. What else does auto form fills based on urls, client side encryption, and runs in chrome, IE and Safari?
1Password, and it's been awesome. If you use the non-hosted version you control the whole thing. LAN only sync, or Dropbox, Rsync, however you want to sync it if it matters. Otherwise they've got a hosted version which can also give you web access in a pinch and handle all the syncing for you. I have been with them for long enough that my only option was a non-hosted version and I keep in sync with Dropbox and it wor…
LastPass RCE vulnerability fixed
171–180 of 188 posts
Re: LastPass RCE vulnerability fixed
#172Earlier quoted context omitted.
Which mobile app do you use with KeePass? I use MiniKeePass and am pretty happy with it.
It's a good app but as far as I remember the integration with Dropbox wasn't working properly. I think that's the main issue with KeePass right now - getting your passwords synchronized with your phone.
Re: LastPass RCE vulnerability fixed
#173Earlier quoted context omitted.
That is honestly embarrassing. I'm glad I don't use LastPass.
I do. What else does auto form fills based on urls, client side encryption, and runs in chrome, IE and Safari?
PasswordSafe's safe is an open source file structure and thus there are many different ways to access it with different features for each. I have PasswordSafe on both my Windows PC and android phone and I'm using PasswordSafe professionally for my organization's passwords and found that there are reliable Mac options so those with Macs can access the safe.
Re: LastPass RCE vulnerability fixed
#174Brilliant find by taviso. So simple yet thousands of others passed over it. It takes a relentless mind to comb through all this code and actually find such an issue.
> So simple yet thousands of others passed over it. is that true? how do you know?
Re: LastPass RCE vulnerability fixed
#175>>Its a pretty bad trait we should do something about that and just continue striving for peer reviewable code and implementations. COMMENT OF THE DECADE. If you think that lastpass should be embarrassed based on what Tavis has written, maybe consider taking a lit criticism class. There is a concept called an "unreliable narrator." Tavis has a documented track record of poor interpersonal behavior. It's time that peo…
Unfortunately, your comment history has plenty of uncivil and unsubstantive comments. It also has some really good ones, so we aren't banning you, but if you keep doing this, we'll have to, so please fix it.
We detached this subthread from https://news.ycombinator.com/item?id=13927087 and marked it off-topic.
Re: LastPass RCE vulnerability fixed
#176Earlier quoted context omitted.
I'm really surprised, and disappointed, that Travis announced this publicly like this. From my understanding the Google team has a policy of giving people time to patch the bug before announcing it. I know that the technical details weren't released by by confirming there is a zero day exploit he's making it more likely to be discovered and exploited. The responsible thing would have been to notify the vendor and app…
He announced it exists, though not what it is. Who knows, it might even spur some people to move away from LP.
Re: LastPass RCE vulnerability fixed
#177Earlier quoted context omitted.
Has anyone used hardware-based password manager like Trezor Password Manager? [1] [2] Initially Trezor was created as a bitcoin wallet but is much more these days. The issue with 1Password is that it's not accessible in Linux and no U2F (yubikey etc) support AFAIK... [1] https://trezor.io/passwords/ [2] https://blog.trezor.io/satoshilabs-launches-trezor-password-...
I've wanted to use such a thing, but the requirement to use a specific browser is always a massive bother same with things like yubikey It seems like it would be better to just fake a keyboard output instead? then you could have something that could work on all platforms in all situations
Re: LastPass RCE vulnerability fixed
#178Re: LastPass RCE vulnerability fixed
#179Earlier quoted context omitted.
1Password, and it's been awesome. If you use the non-hosted version you control the whole thing. LAN only sync, or Dropbox, Rsync, however you want to sync it if it matters. Otherwise they've got a hosted version which can also give you web access in a pinch and handle all the syncing for you. I have been with them for long enough that my only option was a non-hosted version and I keep in sync with Dropbox and it wor…
But no linux support.
It would be very nice if they did support Linux and people have been asking for it, but there is a passable workaround- and frankly one I'm willing to work with because it works so great everywhere else.
Re: LastPass RCE vulnerability fixed
#180Earlier quoted context omitted.
But no linux support.
No direct Linux support but you can absolutely run the windows version 4 in Wine. It's not without a few crashy glitches but for just using stored passwords it works fine. It would be very nice if they did support Linux and people have been asking for it, but there is a passable workaround- and frankly one I'm willing to work with because it works so great everywhere else.
When I tried it out I wanted 1password family so I could share some accounts with my partner. 1password 4 doesn't support their cloud datastore; the version that does will not run on Wine.
However, I could use the webapp on linux. It was a bit annoying but I could have dealt with it. The other complaint I had was the UX for Android. Having to switch my keyboard every time I wanted to enter a password was very annoying. Hopefully that gets better with the recently announced Autofill API for Android O.