LastPass bug leaks credentials from previous site
161–170 of 196 posts
Re: LastPass bug leaks credentials from previous site
#162Earlier quoted context omitted.
Really? I find this hard to believe, as a dev and internet user. Facebook, instagram, etc have far worse interfaces. You add the extension, easily add/generate/create/autofill your login info. It's usually as simple as clicking an icon that appears in the relevant field.
No, OP has to be exaggerating
it's ridiculous that I have to go to the edit page just to copy a password. Neither Keypass, nor LastPass, nor any other password manager I've used, suffers from this.
And the amount of time it took for me to figure out how to create a password and allow others access to it is kind of silly.
Re: LastPass bug leaks credentials from previous site
#163Is that true about LastPass being the most popular password manager? I just can't imagine it, I'm forced to use it with a client, and it has hands down the worst UI experience I've ever seen.
Really? I find this hard to believe, as a dev and internet user. Facebook, instagram, etc have far worse interfaces. You add the extension, easily add/generate/create/autofill your login info. It's usually as simple as clicking an icon that appears in the relevant field.
password management isn't a hard problem (outside of security concerns), why the hell did they end up with that UI?
Re: LastPass bug leaks credentials from previous site
#164Is that true about LastPass being the most popular password manager? I just can't imagine it, I'm forced to use it with a client, and it has hands down the worst UI experience I've ever seen.
Long time last pass user...what do you recommend? Team of 15-30 people, need shared username/password credentials for web, FTP, and DB systems. Also other arbitrary secure "notes", e.g. SSH key. Needs 2FA as well.
Re: LastPass bug leaks credentials from previous site
#1651Password is very straightforward after they added cloud vaults. Before that, it was kind of a mess, but it works quite decently now.
As far as I know, 1Password has never suffered any hacks or critical vulnerabilities the way that LassPass has. I have used both in the past; I would never, ever recommend LastPass to anyone. 1Password, however? A nearly perfect product (with great support)
Re: LastPass bug leaks credentials from previous site
#166Re: LastPass bug leaks credentials from previous site
#167Earlier quoted context omitted.
Using a programming language to exploit something doesn't mean the programming language is flawed.
So, are they using the phrase "malicious JavaScript" correctly? Shouldn't they remove "malicious"?
Re: LastPass bug leaks credentials from previous site
#168Is that true about LastPass being the most popular password manager? I just can't imagine it, I'm forced to use it with a client, and it has hands down the worst UI experience I've ever seen.
I worked at a company that used LastPass. The whole service was a complete train wreck, but I used it and therefore contributed to their ability to claim to be the most popular password manager.
Re: LastPass bug leaks credentials from previous site
#169Earlier quoted context omitted.
I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.
KeePass isn't a solution in case you want to share passwords with family or team members. KeePass is barely decent for personal use only, and only for the desktop. The quality of the available apps differs from platform to platform. For example Bitwarden has a decent iOS app, 1Password has a superb iOS app and in contrast the available KeePass app for iOS is a piece of shit – no offense intended but it's basically un…
[1] https://play.google.com/store/apps/details?id=keepass2androi...
Re: LastPass bug leaks credentials from previous site
#170Earlier quoted context omitted.
I store the keepass file in a cloud sync service. The file is encrypted. The keepass application can perform "auto-type" which works for all sensible applications and websites that have username/password input fields and a log-in button. Recently, more and more websites split the log-in into two screens, first email and then password. This completely breaks auto-type and is horrible in every way. Please don't do it.
PasswordWallet can auto-type across split login screens since it can be configured to pause between username/password.