Live data from Hacker News

LastPass bug leaks credentials from previous site

zdnet.com

11–20 of 196 posts

Re: LastPass bug leaks credentials from previous site

#13
post #4

I am seriously considering alternatives to LastPass. Since they moved to a dedicated app instead of just a plugin on Mac, it is borderline unusable for me. Almost never actually fills in my passwords (often have to click copy password), often thinks I am on a different website than I am, or just gives me an empty white box when I click the LastPass button.

While it's definitely more work to setup, I've been using KeePassXC + NextCloud for syncing. I've got it working on my phone with keepass2android (think that's the name) and also use a yubikey challenge-response key to help ensure that even with a bad password i've got decent protection of my passwords. There's browser extensions for basically every browser out there, and it even supports auto-typing into non-browser…

I've been using something very similar, though I only have a local keyfile that I independently put on my synced machines rather than the yubikey thing. How do you like the yubikey process? Not too much of a pain?

Re: LastPass bug leaks credentials from previous site

#14
It's interesting to note that browser extensions continue to be the primary point of vulnerability for password management solutions. IIRC, it's been quite a long time since vaults themselves were breached.

It is an undeniably more secure option to use password managers without their associated extensions. Certainly less convenient, but ponder carefully your threat model.

Re: LastPass bug leaks credentials from previous site

#16

Is that true about LastPass being the most popular password manager? I just can't imagine it, I'm forced to use it with a client, and it has hands down the worst UI experience I've ever seen.

Long time last pass user...what do you recommend?

Team of 15-30 people, need shared username/password credentials for web, FTP, and DB systems. Also other arbitrary secure "notes", e.g. SSH key. Needs 2FA as well.

Re: LastPass bug leaks credentials from previous site

#17

Is that true about LastPass being the most popular password manager? I just can't imagine it, I'm forced to use it with a client, and it has hands down the worst UI experience I've ever seen.

Really? I find this hard to believe, as a dev and internet user. Facebook, instagram, etc have far worse interfaces.

You add the extension, easily add/generate/create/autofill your login info. It's usually as simple as clicking an icon that appears in the relevant field.

Re: LastPass bug leaks credentials from previous site

#18
post #4

I am seriously considering alternatives to LastPass. Since they moved to a dedicated app instead of just a plugin on Mac, it is borderline unusable for me. Almost never actually fills in my passwords (often have to click copy password), often thinks I am on a different website than I am, or just gives me an empty white box when I click the LastPass button.

> Since they moved to a dedicated app instead of just a plugin on Mac, it is borderline unusable for me.

What do you mean? They still have browser extensions for all major browsers.

Re: LastPass bug leaks credentials from previous site

#19
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

+1 for Bitwarden.

Considered doing the self-hosted approach, but wound up paying to support the project.

Re: LastPass bug leaks credentials from previous site

#20
post #4

I am seriously considering alternatives to LastPass. Since they moved to a dedicated app instead of just a plugin on Mac, it is borderline unusable for me. Almost never actually fills in my passwords (often have to click copy password), often thinks I am on a different website than I am, or just gives me an empty white box when I click the LastPass button.

I moved to 1Password from LastPass a little over a year ago and have no complaints.
Post reply on HN