Earlier quoted context omitted.
By default the browser plugin is configured in such a way that 2FA is completely bypassed for a second when logging in. This is officially documented, so we can likely assume that it will never be fixed. https://lastpass.com/support.php?cmd=showfaq&id=2775
Well. Not to defend LP, but for those who don't click through, offline mode can (and should be?) disabled. Perhaps this is a case where a feature that makes some sense in some cases was added, the problem is, outside that scope it's a really bad idea. But then someone said "We'll make it optional..." and the rest was history?
On Password Managers
291–300 of 347 posts
Re: On Password Managers
#292The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…
I changed from LastPass to 1Password for big part because it was "pay once, use forever" instead of LastPass' subscription service. It hasn't even been 3 years since I switched and I paid what felt like a lot of money, but I figured that it would still be less over all in comparison. Now I can't get my vault to sync on my Windows machine and last time I reinstalled my Mac it was a hunt for the right executable. I've…
You can switch again to a homerolled solution like you are suggesting, but you're not going to "no deal with this shit", you are now your own IT for this shit you homerolled.
Re: On Password Managers
#293Earlier quoted context omitted.
Have you used KeepassXC. I am panning to move to it from lastpass, and want to make sure I am making the right choice.
I've used KeePassXC, and I think it's the best KeePass variant. I don't like stock KeePass because it's horribly slow under Mono (Linux/OS X). And I like but am not as satisfied with KeePassX because it lacks some features I like. From what I recall, the maintainers of KeePassXC got frustrated with the feature set and development pace of KeePassX, so they made their own fork. And they added nice things like TOTP code…
The problem is that they can't deviate from the official KeePass database format, so adding something like aliases requires hacks like the above.
Re: On Password Managers
#294This is only tangentially related, but I believe it's time to have a unified login standard for the web. Not in the OAuth sense, as that's hard to do, but just a small, machine-readable file that tells your password manager "to log this user in, just submit credentials to /whatever/url/". That way, your password manager would show a "login" button on the browser's toolbar when you visited any page in a site, you'd cl…
The problem, I think, is that every site wants to own the web, and doesn't want to give up anything, let alone login. Facebook and Twitter and Google all want to be the auth providers to the net, but then you have to trust them in a much more elevated way than you should, and their motives are more around building a profile of you and where you go on the net than being a secure auth provider. If Facebook started supporting U2F (they may, I don't know), Yubikey sales would explode tomorrow and the web may be a safer place, who knows.
Re: On Password Managers
#295Re: On Password Managers
#296The only cloud based password manager I'm willing to use is Dashlane[1]. It's supposedly "zero knowledge", and although you can never be 100% there isn't some bug waiting around to be exploited, it's a compromise I'm willing to make (the lesser evil). They also have several complementing features like encrypted notes, auto saving receipts, credit cards, batch password changer with quite a few major sites. I'm not aff…
[0] Words mean things. They are dealing with encrypting passwords, after all, so I hope they're truthfully representing the technology behind their system:
https://en.wikipedia.org/wiki/Zero-knowledge_proof
Maybe even:
https://en.wikipedia.org/wiki/Zero-knowledge_password_proof
My money's on some corporate bullshit, however, for example:
Re: On Password Managers
#297Unfortunately, it seems that many companies these days are more interested in developing services rather than deftly solving specific user problems. Whether or not this is financially sound, it's an ongoing assault on my workflow. I can't live in fear of every utility on my system pivoting to a new business model! Fundamental software needs to be stable, and there's a good reason why most of our essentials (compression, video playback, web browsing, etc.) are free and open source.
Going forward, I hope we discover more ways to collectively fund open source software projects, large and small, because everything else is just an IOU for another future shakeup.
Re: On Password Managers
#298I'm glad to see this getting more attention because it has been brewing for months and 1Password is essentially doing what they promised they wouldn't - forcing users to the subscription/online model my phasing out support for local vaults. I'm not mad at the subscription. I'd pay them the few bucks a month happily for what is an excellent application cross-platform. I AM mad at the forced cloud sync. My current plan…
Anyways, there is a more stylish web UI for Keepass: https://keeweb.info/
Re: On Password Managers
#299I use Enpass on Linux, Windows, OS X, Android, and iOS. I also use the Chrome extension. It has a similar user experience to 1Password, but is actually serverless (you sync your encrypted blob to a cloud service of your choice, or not at all). I wish Enpass were open source, but I can understand their decision not to make it so -- its desktop application is free and its mobile apps include a small perpetual license f…
Re: On Password Managers
#300Is there simple open source non-commercial self-hosted password manager? I need something like 1Password, but with much more primitive interface, 1Password is just too user-friendly for me, so I'm reverted to text files which isn't very good from security point. I don't really need native apps, web interface would be sufficient, of course with crypto implemented in JavaScript.
Then there's LessPass[2] which is an open-source stateless password manager. This one has an odd list of supported platforms (Chrome, Firefox, Android, Cozy (?), CLI), but I believe it also has a web interface.
If you're wanting one more team-oriented, there's Passbolt[3] which I think I'm going to give a try this weekend to solve my workplace's info-sharing problem.
Otherwise, you can just use KeePass/KeePassX/KeePassXC and sync the database file in the cloud with the host of your choice.
[0] http://passit.io/ [1] https://news.ycombinator.com/item?id=14814595 [2] https://lesspass.com [3] https://www.passbolt.com/