Live data from Hacker News

LastPass bug leaks credentials from previous site

zdnet.com

41–50 of 196 posts

Re: LastPass bug leaks credentials from previous site

#41
post #33

I've love to switch away from LastPass. I switched to LastPass Families when it came out due to their "digital contingency plan" so family members (or the trusted family attorney) can get access to passwords rather conveniently if I or another family member passes away. At the time, I didn't see that other offerings made this as easy. Any other good options out there for this use case?

1Password has a Families plan for this.

Re: LastPass bug leaks credentials from previous site

#43
post #39

I quit LastPass when they were acquired by LogmeIn and doubled their prices to $24 a year, and their constant issues with autofill (atleast for websites in my country). I switched to Bitwarden and haven't faced an issue since.

I, too, began looking after the doubling in cost (without any notice that I noticed) plus the autofill issues, and switched to Bitwarden.

This story reminded me that I hadn't deleted my LastPass account yet, and when I did I got a buggy error message, something to the effect of "Error: .A" after the double-confirm. Looks like the deletion went through, though... just an error in the process, which is uninspiring.

Re: LastPass bug leaks credentials from previous site

#44
post #33

I've love to switch away from LastPass. I switched to LastPass Families when it came out due to their "digital contingency plan" so family members (or the trusted family attorney) can get access to passwords rather conveniently if I or another family member passes away. At the time, I didn't see that other offerings made this as easy. Any other good options out there for this use case?

I use BitWarden for this. If it's just you and a partner, their free version works. If you have a larger set of people you want to share sets of credentials with (up to 5), the family version is $1/mo.

It's not exactly the same as LastPass' "contingency plan" feature (since you're simply sharing some credentials all the time), but it works well enough for me.

Re: LastPass bug leaks credentials from previous site

#46

Was prepared to change all my darn credentials when clicking on that. For those clicking the comments first, the byline is: "LastPass has released a fix last week. Vulnerability details are now public. Users advised to update."

Your comment implies that you're no longer changing your credentials?

Perhaps they mean just not all of them Right Now.

Re: LastPass bug leaks credentials from previous site

#47
post #38
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

What is your phishing protection? Making sure you read the URL?

Re: LastPass bug leaks credentials from previous site

#48
post #45

I've been just using Chrome's built-in password storage feature, though I see a lot of people are still using extensions. Any reason to prefer an extension or third party over just using the built-in Chrome feature?

Works outside of browser, I use mine for things on my phone with the LastPass Autofill.

Doesn't tie me to one browser or their security model.

Re: LastPass bug leaks credentials from previous site

#49
post #33

I've love to switch away from LastPass. I switched to LastPass Families when it came out due to their "digital contingency plan" so family members (or the trusted family attorney) can get access to passwords rather conveniently if I or another family member passes away. At the time, I didn't see that other offerings made this as easy. Any other good options out there for this use case?

Just store your master password in your spouse's vault and make sure they know where the vault is stored if you use an offline tool/service.

This of course assumes you are comfortable knowing that they could access your accounts while you're still alive if they wanted to, and trusting that they won't.

Re: LastPass bug leaks credentials from previous site

#50
post #45

I've been just using Chrome's built-in password storage feature, though I see a lot of people are still using extensions. Any reason to prefer an extension or third party over just using the built-in Chrome feature?

I like using a third party alternative since it gives me the option to use it outside the google ecosystem. I use Firefox and Chrome regularly so the seamless syncing without depending on any particular browser is important for me.

The other feature I like in dedicated password managers is that they tend to have a lot more options about what kind of password/passphrase you can generate. Some other features that i regularly use is storing non password content like software licenses, sharing certain passwords with my spouse, etc.

Post reply on HN