Live data from Hacker News

LastPass bug leaks credentials from previous site

zdnet.com

181–190 of 196 posts

Re: LastPass bug leaks credentials from previous site

#181

Earlier quoted context omitted.

No, OP has to be exaggerating

I meant out of all the password managers I've used, and I'm not exaggerating. it's ridiculous that I have to go to the edit page just to copy a password. Neither Keypass, nor LastPass, nor any other password manager I've used, suffers from this. And the amount of time it took for me to figure out how to create a password and allow others access to it is kind of silly.

But you _don't_ have to go to the edit page just to copy a password.

Re: LastPass bug leaks credentials from previous site

#182

Earlier quoted context omitted.

I did that until Dropbox dropped support for ecryptfs. Using Bitwarden now, very happy with it.

It's back now, but that felt like a rather short-sighted decision from management :( https://hardware.slashdot.org/story/19/07/22/1534200/dropbox...

I didn't know that, thanks for the info!

Re: LastPass bug leaks credentials from previous site

#183
post #38

Earlier quoted context omitted.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

KeePass isn't a solution in case you want to share passwords with family or team members. KeePass is barely decent for personal use only, and only for the desktop. The quality of the available apps differs from platform to platform. For example Bitwarden has a decent iOS app, 1Password has a superb iOS app and in contrast the available KeePass app for iOS is a piece of shit – no offense intended but it's basically un…

There is no KeePass-app for iOS (in the sense of the one/official). I think you mean MiniKeePass.

There is Strongbox on iOS and it's by far the best mobile KeePass-experience i've ever had.

Re: LastPass bug leaks credentials from previous site

#184
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

Can confirm BitWarden as a great LastPass alternative. Have been a paying LastPass user for years and have switched the the paid BitWarden. Zero issues and 100% open-source

Re: LastPass bug leaks credentials from previous site

#185
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

My issue with bitwarden (which is why I ended up choosing 1password) is that it doesn't provide an Android keyboard to insert passwords into apps that block clipboard access. (Keepass has this, but I wanted a simpler synchronization story.)

You should make a feature request. These guys are on a fast development pace.

Re: LastPass bug leaks credentials from previous site

#187
post #38
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

Crazy amount of hate on KeePass in this thread ... I really don't get why it's not a more common solution on HN, it's free and open source and leaves the syncing to you, and doesn't live inside a browser extension ... it literally ticks all the boxes that a good password manager should have.

I don't know if the iOS client is that bad, but the Android one is just fine.

Re: LastPass bug leaks credentials from previous site

#188
post #136
post #91

Earlier quoted context omitted.

>> Anything that isn't context aware (i.e. knows which website you're on so can provide the relevant information) is doomed to failure right out the gate. Sorry, not doomed to fail. I'm not gonna use a password manager that is "context aware" and has the capability to auto-fill for sensitive sites - that's just my threat model. I'm okay with context aware storing of less critical passwords.

It's not just usability: The context awareness means it will prevent you from filling a password on a phishing site. I share your wariness of the browser extensions, but you're betting that a software bug is more likely than human error. Even skilled security-aware users fall victim to phishing on a regular basis, so I'd rather trust the software.

> The context awareness means it will prevent you from filling a password on a phishing site.

This is literally one of the last major attack vectors since password managers became somewhat more popular.

They all do encryption well, even the ones that keep the database on a server you don't control it's most probably actually encrypted, etc. They do the basic password manager thing. They keep your passwords.

Every time there's something wrong/vulnerable with a password manager, it is because it's a browser extension and the attack surface between the password manager and the browser is being attacked.

> I share your wariness of the browser extensions, but you're betting that a software bug is more likely than human error.

Well, it literally has been.

(this is why I'm using Keepass and no browser extension for my passwords)

Re: LastPass bug leaks credentials from previous site

#189
post #38

Earlier quoted context omitted.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

KeePass isn't a solution in case you want to share passwords with family or team members. KeePass is barely decent for personal use only, and only for the desktop. The quality of the available apps differs from platform to platform. For example Bitwarden has a decent iOS app, 1Password has a superb iOS app and in contrast the available KeePass app for iOS is a piece of shit – no offense intended but it's basically un…

I dunno what you're using, but KeePass' Android app and the Linux desktop app are pretty great. Sync goes via a separate sync service (Dropbox currently but it could be anything), which is the way I want it.

And just like I think a password manager shouldn't be a browser extension, I also don't think it should encourage behaviour like sharing passwords among people ... I mean, really? That's literally password reuse, don't feel good about it. Of course a password manager shouldn't encourage it.

"Our son Jim made this password using his password manager thingy so it's probably really secure and now we use it for all our banking and government stuff"

I mean it's sincerely better to keep a "family password" on a post-it, so you don't confuse it with passwords you're actually trying to keep secure.

Re: LastPass bug leaks credentials from previous site

#190
post #62
post #38

Earlier quoted context omitted.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

> KeePass and similar are a better way to go, if slightly more labor intensive. Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion.

> Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion.

What are you on about? Synchronization is easy, you can use just about any service you like.

The fact that it's not kept on a server by the same commercial party that also sold you the security product, is a feature. And obviously necessary, since KeePass is free and open source.

I see leaking credentials bugs with browser-extension operated online storage commercial password software all the time on HN. Obviously you're paying for shiny, not security.

Post reply on HN