Live data from Hacker News

LastPass bug leaks credentials from previous site

zdnet.com

61–70 of 196 posts

Re: LastPass bug leaks credentials from previous site

#61
post #58
post #51

Earlier quoted context omitted.

Why do you trust their implementation more than LastPass?

Not parent, but BW is opensource, and they have not had any high-profile incident yet, afaik.

They also give you the option to self-host, so you don't have to trust their hosting service if you don't want to. Own your data!

Re: LastPass bug leaks credentials from previous site

#62
post #38
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

> KeePass and similar are a better way to go, if slightly more labor intensive.

Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion.

Re: LastPass bug leaks credentials from previous site

#63
post #38

Earlier quoted context omitted.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

What is your phishing protection? Making sure you read the URL?

Just add the original URL into the specified field and copy paste it each time you need to access said website.

KeePass is the best at what it does and stays local as any password manager should do. If you need more security & portability encrypt the DB with VeraCrypt, sync with whatever service you trust.

Re: LastPass bug leaks credentials from previous site

#64
Confused as to why tech people in this thread are giving LastPass flak for a single bug. They've had a pretty good track record for the past half decade or so since I've been using them and they submitted a fix immediately for this bug. Bugs happen, and this is a particularly obscure/esoteric bug. Right?

Re: LastPass bug leaks credentials from previous site

#65

Earlier quoted context omitted.

Really? I find this hard to believe, as a dev and internet user. Facebook, instagram, etc have far worse interfaces. You add the extension, easily add/generate/create/autofill your login info. It's usually as simple as clicking an icon that appears in the relevant field.

The vault UI is horrifyingly difficult. Also their registration flow is horrendously awful. Try setting up a Family plan where you log out of your personal and log into your family plan and you'll see how frustratingly sticky it is. Too many buttons and features for such a simple problem. Development is cancer.

Click plus, click password, fill in fields. That's not too difficult, is it? Although that "click password" step wasn't needed before the recent update. I imagine the typical user is just doing that and using the search field. And most would primarily use the extension or mobile app.

I've seen plenty of awful registration flows, so I'm sure that's true. I haven't had to do that for a few years.

Re: LastPass bug leaks credentials from previous site

#68
post #62
post #38

Earlier quoted context omitted.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

> KeePass and similar are a better way to go, if slightly more labor intensive. Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion.

If you don't require real-time diffing, i.e. only one user modifies the file at a time, dropping your keyDBs in a Keybase shared folder might solve your problems.

Re: LastPass bug leaks credentials from previous site

#69
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

I switched to Bitwarden as well, from 1password, which I switched off of from Lastpass. It’s not as pretty as 1password, but it’s cheaper, platform support is better (1password X helped here but it was too-little-too-late for me,) and it’s open source which is a nice touch. I have no regrets either; paying customer as well.

I tried KeePass XC on the side and I’ve gotta say, very formidable option if you want one that is FOSS and with no central server. My only real issue is the mobile app story.

Re: LastPass bug leaks credentials from previous site

#70
I have been using enpass, and I'm very satisfied. I was a LastPass user once, but never trusted their security model. Then switched to 1password, but the lack of good multiplatform support and their push to a cloud model made me look for alternatives. What I want is support for Mac, Windows, Linux, and Android; possibly one time payment; and local storage (most important). For syncing I use my own nextpass cloud. Bitwarden is close, but enpass fullfills all.
Post reply on HN