Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

41–50 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#41
Wait, are they saying that the clients don't store a local copy? Or that the local copy is inaccessible without the servers working?? That seems incredibly irresponsible and I can't imagine a single reason for doing that.

Or is there something else going on that corrupted the users' local copies? If the system is properly secure (i.e. data is encrypted and verifiable with the user's password-derived key) this shouldn't be possible, right?

Re: LastPass stores passwords so securely, not even its users can access them

#42

Why one shouldn't use cloud-based services. I'm sticking to keepass. (I'm syncing the keepass file over a cloud, but I still have a local copy on all my devices against cases like these)

I'm sorry, what is your justification for not using cloud-based services?

Lastpass (like pretty much all of these online password managers) will work offline, so if the service goes down, you can still access your data locally.

Re: LastPass stores passwords so securely, not even its users can access them

#43
LP has a history of problems, but my company forces us to use that crappy product. I've complained about it for years. I use keepassx for personal, 1password for work, and lastpass for anything that I need to share with coworkers. I always wondered who got the kickback from LP.

Re: LastPass stores passwords so securely, not even its users can access them

#44
KeePass/KeePassXC on each device. Complex keyfile manually copied to each device (never in the cloud). Password database protected by the keyfile and a memorable complex password stored in your cloud folder of choice synced to your devices. You now have a free, open source, secure, cloud synced password service.

For additional security, you can manually copy the database between devices as well. Or keep a separate manually copied database with your most secure logins.

Re: LastPass stores passwords so securely, not even its users can access them

#45

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

BitWarden is one of the few things I pay for even though I don't have to simply because I really want it to keep existing.

Same. And at 10$/year, its not like its un-affordable. Its probably my 3-4th most used piece of software, after win10, firefox, and thunderbird.

Re: LastPass stores passwords so securely, not even its users can access them

#46
SAASPASS personal password manager and Authenticator works offline (with cloud syncing options). You can also use it for teams or companies (online and offline options set by admin) and it is by default protected by 2FA.

www.saaspass.com

(I work for an IAM SI/consultancy and we use and implement SAASPASS for IAM needs including enterprise password management, 2FA, directory services and SAML-based single sign-on).

Re: LastPass stores passwords so securely, not even its users can access them

#47

Why one shouldn't use cloud-based services. I'm sticking to keepass. (I'm syncing the keepass file over a cloud, but I still have a local copy on all my devices against cases like these)

For passwords, fully agree. This is how I make incremental backups of my keepass database (synced via Google Drive) so I accidentally bork a login in the file, I can go back to a previous version... https://gist.github.com/harryf/d23a1ceda84806a099782558fc317...

Re: LastPass stores passwords so securely, not even its users can access them

#48

Some alternatives: * https://keepass.info/ * https://bitwarden.com/ * https://1password.com/

I evaluated a bunch of team password managers last year. Lastpass was really buggy and had a confusing UI. Dashlane also had odd limitations. 1password had a good UI but the "master key" system is difficult for users to use. It was also more expensive. I ended up recommending Bitwarden. Surprisingly the open source option had a great UI and great clients, with the bonus of being open source on both ends.

[deleted]

Re: LastPass stores passwords so securely, not even its users can access them

#50
So in response to this story I decided to delete my (premium) account with them. After confirming multiple times (good thing), I was shown this error: https://i.imgur.com/4dpn6d5.png

How does error handling like this even make it to production?

I got an email as well confirming my account deletion and I can no longer log in.

But all in all this clearly does increase my trust in Lastpass's security competence.

Post reply on HN