Or is there something else going on that corrupted the users' local copies? If the system is properly secure (i.e. data is encrypted and verifiable with the user's password-derived key) this shouldn't be possible, right?
LastPass stores passwords so securely, not even its users can access them
41–50 of 266 posts
Re: LastPass stores passwords so securely, not even its users can access them
#42Why one shouldn't use cloud-based services. I'm sticking to keepass. (I'm syncing the keepass file over a cloud, but I still have a local copy on all my devices against cases like these)
Lastpass (like pretty much all of these online password managers) will work offline, so if the service goes down, you can still access your data locally.
Re: LastPass stores passwords so securely, not even its users can access them
#43Re: LastPass stores passwords so securely, not even its users can access them
#44For additional security, you can manually copy the database between devices as well. Or keep a separate manually copied database with your most secure logins.
Re: LastPass stores passwords so securely, not even its users can access them
#45If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.
BitWarden is one of the few things I pay for even though I don't have to simply because I really want it to keep existing.
Re: LastPass stores passwords so securely, not even its users can access them
#46www.saaspass.com
(I work for an IAM SI/consultancy and we use and implement SAASPASS for IAM needs including enterprise password management, 2FA, directory services and SAML-based single sign-on).
Re: LastPass stores passwords so securely, not even its users can access them
#47Why one shouldn't use cloud-based services. I'm sticking to keepass. (I'm syncing the keepass file over a cloud, but I still have a local copy on all my devices against cases like these)
Re: LastPass stores passwords so securely, not even its users can access them
#48Some alternatives: * https://keepass.info/ * https://bitwarden.com/ * https://1password.com/
I evaluated a bunch of team password managers last year. Lastpass was really buggy and had a confusing UI. Dashlane also had odd limitations. 1password had a good UI but the "master key" system is difficult for users to use. It was also more expensive. I ended up recommending Bitwarden. Surprisingly the open source option had a great UI and great clients, with the bonus of being open source on both ends.
Re: LastPass stores passwords so securely, not even its users can access them
#49Re: LastPass stores passwords so securely, not even its users can access them
#50How does error handling like this even make it to production?
I got an email as well confirming my account deletion and I can no longer log in.
But all in all this clearly does increase my trust in Lastpass's security competence.