Live data from Hacker News

LastPass bug leaks credentials from previous site

zdnet.com

31–40 of 196 posts

Re: LastPass bug leaks credentials from previous site

#31
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

Yeah, BitWarden absolutely has the best UX of any password manager out there (for the subset of password managers that are cross-platform... it's possible there's something better out there for a single platform, but that's not terribly useful for me).

Re: LastPass bug leaks credentials from previous site

#32
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

Does Bitwarden do a phone app?

Yep, both iOS and Android.

Re: LastPass bug leaks credentials from previous site

#33
I've love to switch away from LastPass. I switched to LastPass Families when it came out due to their "digital contingency plan" so family members (or the trusted family attorney) can get access to passwords rather conveniently if I or another family member passes away. At the time, I didn't see that other offerings made this as easy. Any other good options out there for this use case?

Re: LastPass bug leaks credentials from previous site

#34
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

Does Bitwarden do a phone app?

Yes and it integrates with the OS level password autofill systems.

Re: LastPass bug leaks credentials from previous site

#35
The bug report says:

    by iframing popupfilltab.html (i.e. via moz-extension, 
    ms-browser-extension, chrome-extension, etc). It's a
    valid web_accessible_resource.
    [...]
    y.src="chrome-extension://hdokiejnpimakedhajhdlcegeplioahd/popupfilltab.html";
    // or y.src="moz-extension://...";
My understanding is that this should not work with the Firefox version of LastPass, since each installation of the extension is given a unique id which can't be guessed by web pages -- that is unless the unique id is made visible to web pages by the extension itself.

Re: LastPass bug leaks credentials from previous site

#36

Was prepared to change all my darn credentials when clicking on that. For those clicking the comments first, the byline is: "LastPass has released a fix last week. Vulnerability details are now public. Users advised to update."

Your comment implies that you're no longer changing your credentials?

Re: LastPass bug leaks credentials from previous site

#37

Is that true about LastPass being the most popular password manager? I just can't imagine it, I'm forced to use it with a client, and it has hands down the worst UI experience I've ever seen.

Have you used Amazon Web Services Web Console? Worst UI experience I've had up to this point. However, it's a great product.

I think companies like this devote their resources to back end shit and keep the front end shit simple on purpose to prevent even the hint of a security bug that would make them look bad.

Re: LastPass bug leaks credentials from previous site

#38
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

Re: LastPass bug leaks credentials from previous site

#40
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

I use LastPass and hate it (searching 'gmail' shows every site where I use my email address before it shows Gmail).

How does BitWarden compare to 1Password?

Post reply on HN