Live data from Hacker News

LastPass bug leaks credentials from previous site

zdnet.com

161–170 of 196 posts

Re: LastPass bug leaks credentials from previous site

#162

Earlier quoted context omitted.

Really? I find this hard to believe, as a dev and internet user. Facebook, instagram, etc have far worse interfaces. You add the extension, easily add/generate/create/autofill your login info. It's usually as simple as clicking an icon that appears in the relevant field.

No, OP has to be exaggerating

I meant out of all the password managers I've used, and I'm not exaggerating.

it's ridiculous that I have to go to the edit page just to copy a password. Neither Keypass, nor LastPass, nor any other password manager I've used, suffers from this.

And the amount of time it took for me to figure out how to create a password and allow others access to it is kind of silly.

Re: LastPass bug leaks credentials from previous site

#163

Is that true about LastPass being the most popular password manager? I just can't imagine it, I'm forced to use it with a client, and it has hands down the worst UI experience I've ever seen.

Really? I find this hard to believe, as a dev and internet user. Facebook, instagram, etc have far worse interfaces. You add the extension, easily add/generate/create/autofill your login info. It's usually as simple as clicking an icon that appears in the relevant field.

yes, I was blown away by how bad it is the first time I saw it.

password management isn't a hard problem (outside of security concerns), why the hell did they end up with that UI?

Re: LastPass bug leaks credentials from previous site

#164

Is that true about LastPass being the most popular password manager? I just can't imagine it, I'm forced to use it with a client, and it has hands down the worst UI experience I've ever seen.

Long time last pass user...what do you recommend? Team of 15-30 people, need shared username/password credentials for web, FTP, and DB systems. Also other arbitrary secure "notes", e.g. SSH key. Needs 2FA as well.

1pass has a much better UI imo.

Re: LastPass bug leaks credentials from previous site

#165
post #154
post #6

1Password is very straightforward after they added cloud vaults. Before that, it was kind of a mess, but it works quite decently now.

As far as I know, 1Password has never suffered any hacks or critical vulnerabilities the way that LassPass has. I have used both in the past; I would never, ever recommend LastPass to anyone. 1Password, however? A nearly perfect product (with great support)

LastPass support is positively abysmal by comparison, good lord does everything suck about that experience.

Re: LastPass bug leaks credentials from previous site

#166
I looked into LastPass and similar options a couple years ago, and ultimately decided on the Chrome password manager (with option for the never-transmitted encryption passphrase). Among other reasons, the Google Security Team seemed bigger and better funded, and I already trust them with my e-mail anyway. I supplement this with a text file that I encrypt/decrypt with the OpenSSL command-line utility, since the latter is available on Linux, Mac, and Windows via Cygwin. So far it’s been a pleasant experience.

Re: LastPass bug leaks credentials from previous site

#167
post #81

Earlier quoted context omitted.

Using a programming language to exploit something doesn't mean the programming language is flawed.

So, are they using the phrase "malicious JavaScript" correctly? Shouldn't they remove "malicious"?

"malicious code" is code that was written with the express purpose of exploiting a weakness or flaw. they're not saying javascript is malicious. they're saying someone could write malicious javascript code (and then trick a user into executing it) that exploits a flaw in lastpass.

Re: LastPass bug leaks credentials from previous site

#168

Is that true about LastPass being the most popular password manager? I just can't imagine it, I'm forced to use it with a client, and it has hands down the worst UI experience I've ever seen.

Unfortunately, the word "popular" is ambiguous. It can mean either the most used, or the most liked. Given that they provide a useful service and have a free tier, it's almost certain that their 'popularity' (sense 1) is much higher than their 'popularity' (sense 2).

I worked at a company that used LastPass. The whole service was a complete train wreck, but I used it and therefore contributed to their ability to claim to be the most popular password manager.

Re: LastPass bug leaks credentials from previous site

#169
post #38

Earlier quoted context omitted.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

KeePass isn't a solution in case you want to share passwords with family or team members. KeePass is barely decent for personal use only, and only for the desktop. The quality of the available apps differs from platform to platform. For example Bitwarden has a decent iOS app, 1Password has a superb iOS app and in contrast the available KeePass app for iOS is a piece of shit – no offense intended but it's basically un…

We use Keepass2Android[1] on Android and KeePass Touch[2] on iOS, synchronize it via Google drive and share it with family across various devices on Linux and Windows. Separate DB for family outside the country and it works beautifully.

[1] https://play.google.com/store/apps/details?id=keepass2androi...

[2] https://apps.apple.com/us/app/keepass-touch/id966759076

Re: LastPass bug leaks credentials from previous site

#170
post #102
post #94

Earlier quoted context omitted.

I store the keepass file in a cloud sync service. The file is encrypted. The keepass application can perform "auto-type" which works for all sensible applications and websites that have username/password input fields and a log-in button. Recently, more and more websites split the log-in into two screens, first email and then password. This completely breaks auto-type and is horrible in every way. Please don't do it.

PasswordWallet can auto-type across split login screens since it can be configured to pause between username/password.

You can configure this in KeePass as well, I've done this for a few sites I actually use a lot. But I can't be bothered for every single service that decides to re-invent login.
Post reply on HN