Live data from Hacker News

LastPass bug leaks credentials from previous site

zdnet.com

191–196 of 196 posts

Re: LastPass bug leaks credentials from previous site

#191
post #124

Earlier quoted context omitted.

> This works if your environment allows a) installing applications and b) cloud sync using consumer clouds (dropbox, gdrive, etc Re a) https://keeweb.info/ toss this onto any ol' free tier web host you want. No app install necessary. It's not as nice as the apps, but it works. Re b) Is there an environment that both has a web browser that you want password management with and doesn't let you access any consumer cloud…

There sure is. Most big companies work that way I would imagine. I can install browser extensions, no problem but local apps are restricted. Also Dropbox and others are blocked at the corporate firewall level.

Surely in such a place, blocking all that access means they care about security and therefore provide you with a password management solution that you also have no choice over.

I mean, installing browser extensions to deliberately get around their security measures seems a little bit counterproductive. They aren't more secure than local apps. Do you take this company's security measures seriously or is it just some hurdle to get around for you?

Re: LastPass bug leaks credentials from previous site

#192
post #62

Earlier quoted context omitted.

> KeePass and similar are a better way to go, if slightly more labor intensive. Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion.

I've had my KeePass file stored in the cloud for years. I use the KeeAnywhere plugin on my Windows boxes for syncing there. And the Keepass2Android app natively supports cloud syncing also. Both even handle merging if the underlying file changes since load.

I didn't know about merging! That's really cool. I'd want to test it out before trusting on it though.

Re: LastPass bug leaks credentials from previous site

#193
post #62

Earlier quoted context omitted.

> KeePass and similar are a better way to go, if slightly more labor intensive. Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion.

> Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion. What are you on about? Synchronization is easy, you can use just about any service you like. The fact that it's not kept on a server by the same commercial party that also sold you the security product, is a feature . And obviously necessary, since KeePass is free and open source. I see leaking credentials…

what people keep forgetting is that not everyone is in the situation where they are able to use those services. Using Keepass with cloud sync via Dropbox (or Gcloud, etc) is not possible in a lot of corporate contexts.

Re: LastPass bug leaks credentials from previous site

#194
post #193

Earlier quoted context omitted.

> Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion. What are you on about? Synchronization is easy, you can use just about any service you like. The fact that it's not kept on a server by the same commercial party that also sold you the security product, is a feature . And obviously necessary, since KeePass is free and open source. I see leaking credentials…

what people keep forgetting is that not everyone is in the situation where they are able to use those services. Using Keepass with cloud sync via Dropbox (or Gcloud, etc) is not possible in a lot of corporate contexts.

But then they should run their own Nextcloud perhaps?

Re: LastPass bug leaks credentials from previous site

#195

Earlier quoted context omitted.

I meant out of all the password managers I've used, and I'm not exaggerating. it's ridiculous that I have to go to the edit page just to copy a password. Neither Keypass, nor LastPass, nor any other password manager I've used, suffers from this. And the amount of time it took for me to figure out how to create a password and allow others access to it is kind of silly.

But you _don't_ have to go to the edit page just to copy a password.

then perhaps you can enlighten me, because to this day it's the only way I've seen to actually copy the password.

Re: LastPass bug leaks credentials from previous site

#196

Password managers are great, just don't use the browser extension. Don't even use the Grammarly extension.

Care to elaborate?

Generally, I don't enjoy sending every keypress to a spellcheck API. Every extension increases the attack surface area. The browser should remain secure, use the native apps.
Post reply on HN