Earlier quoted context omitted.
To start, the LastPass browser extension auto logout feature has critical bugs. I've come back to my computer after several days and found it still logged in with full access to the vault (no master password re-entry required) even with auto logout set to 15 minutes of inactivity. After that happened several times, I lost trust in the product.
There is also a serious bug regarding 2FA. There is a race condition where if you know a users master password you can bypass 2FA for 1 single login. Apparently someone commented below that is a documented "feature". Wow.
On Password Managers
341–347 of 347 posts
Re: On Password Managers
#342Re: On Password Managers
#343Earlier quoted context omitted.
Your phone... I'm sure your data is hopping over many machines.
Can you explain? I use my home wifi to sync to my phone. I'm sure my data is not hopping over many machines, or any machines I do not control.
Re: On Password Managers
#344Earlier quoted context omitted.
As another opinion, I use 1Password 4 for Windows, and am quite happy with it.
Did they add OTP support to version 4 of the windows client? Last I saw it was not supported, so it was not super useful to me.
Re: On Password Managers
#345Earlier quoted context omitted.
As another opinion, I use 1Password 4 for Windows, and am quite happy with it.
I'm happy with it with Google Chrome, which is what I use on my Windows gaming desktop. However, on my Surface Pro 4 I use Edge, because it supposedly uses less power than Chrome. If I've understood the 1Password forums correctly, the Edge integration that they are working on will only be in the subscription version. Those of us staying on 4 will be stuck with manually looking up passwords in 1Password.
Re: On Password Managers
#346Earlier quoted context omitted.
I have it and it's terrible IMO.
As another opinion, I use 1Password 4 for Windows, and am quite happy with it.
Enpass doesn't seem to support multiple vaults at all though...
Re: On Password Managers
#347Earlier quoted context omitted.
Playing devil's advocate: if you can trust that 1Password is doing everything they can to protect you, the user (using HTTPS, resource integrity) while using the browser app, then are you worried that 1Password may act maliciously? I see this argument all the time but I don't buy it because why on Earth would 1Password do such a thing, if their entire model is based on the customer trusting them handling their data?
They can be compelled by an outside force to do so. Or their business model may change
Threat models aren't the same person-to-person - this probably won't happen to you (the grandparent), but embedded journalists / people trying to overthrow a corrupt regime depend on this stuff to literally keep them alive.
Another fairly common possibility, and one that affects damn near everybody: they can get hacked and have their source code modified. This happens with some regularity, and it can affect apps too: https://www.macrumors.com/2017/05/07/handbrake-app-security-... but in a browser this happens silently and unpreventably. Apps don't (usually) update invisibly just because you launched them.