Live data from Hacker News

LastPass bug leaks credentials from previous site

zdnet.com

1–10 of 196 posts

Re: LastPass bug leaks credentials from previous site

#4
I am seriously considering alternatives to LastPass.

Since they moved to a dedicated app instead of just a plugin on Mac, it is borderline unusable for me.

Almost never actually fills in my passwords (often have to click copy password), often thinks I am on a different website than I am, or just gives me an empty white box when I click the LastPass button.

Re: LastPass bug leaks credentials from previous site

#7
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

+1 for bitwarden, moved to them a few months ago and its been rock solid.

Re: LastPass bug leaks credentials from previous site

#8
post #4

I am seriously considering alternatives to LastPass. Since they moved to a dedicated app instead of just a plugin on Mac, it is borderline unusable for me. Almost never actually fills in my passwords (often have to click copy password), often thinks I am on a different website than I am, or just gives me an empty white box when I click the LastPass button.

While it's definitely more work to setup, I've been using KeePassXC + NextCloud for syncing. I've got it working on my phone with keepass2android (think that's the name) and also use a yubikey challenge-response key to help ensure that even with a bad password i've got decent protection of my passwords. There's browser extensions for basically every browser out there, and it even supports auto-typing into non-browser based applications (though I can't say I use that feature myself).

Re: LastPass bug leaks credentials from previous site

#9

This is why I use pass and browserpass. I can't vouch for browserpass extension, but pass is just a wrapper for GnuPG. The encrypted files can be synced using almost any sync solution or even Git. There are apps for mobile too.

That makes no sense as the point of attack here is exactly the extension. So wrt this type of bug you gain nothing.

Re: LastPass bug leaks credentials from previous site

#10

Was prepared to change all my darn credentials when clicking on that. For those clicking the comments first, the byline is: "LastPass has released a fix last week. Vulnerability details are now public. Users advised to update."

For something that has such a long trail of vulnerabilities, I don't recommend LastPass to family friends and business associates. Use 1Password instead, or pass.

Just one example (this one from 2017) of many: https://bugs.chromium.org/p/project-zero/issues/detail?id=12.... Fundamental architectural flaws.

For more HN references, see https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...

Post reply on HN