Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

51–60 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#51

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

If you have a Raspberry Pi lying around, there's a docker image for the excellent bitwarden_rs server available that makes it a snap to get up and running: https://github.com/dani-garcia/bitwarden_rs/wiki/Which-conta...

Forgive my ignorance, and possibly laziness, but if the Pi SD card dies do your passwords go with it?

Re: LastPass stores passwords so securely, not even its users can access them

#52

On a side, am I the only person that doesn't like The Register write style, especially the headings? Yeah, irony and fun all that you want, but it ends up looking like a gossip/tabloid magazine

Not at all the only person.

Re: LastPass stores passwords so securely, not even its users can access them

#53

Why one shouldn't use cloud-based services. I'm sticking to keepass. (I'm syncing the keepass file over a cloud, but I still have a local copy on all my devices against cases like these)

I'm sorry, what is your justification for not using cloud-based services? Lastpass (like pretty much all of these online password managers) will work offline, so if the service goes down, you can still access your data locally.

Not the OP and personally less radically against cloud-based services... But storing something as critical as passwords with a SAAS company which is obviously going to be target of attack and may or may not have the engineering resources to provide a reliable quality of service... seems like a bad idea.

Google(Drive) at least I trust to have the engineering resources to keep data secure, perhaps not from government secret services but at least random hackers

Re: LastPass stores passwords so securely, not even its users can access them

#54
IMO[0] everyone should have at most one password - to their email account. Everything else should be something along the lines of (in order of preference):

1) SSO (federated! Not the Google/Twitter/Facebook/GitHub oligopoly nonsense we have now), using email addresses as ids.

2) Emailed login links, a la Slack's magic links.

Email addresses aren't perfect, but they're the globally unique, federated IDs we have, and good enough. Plus they have the advantage of years of figuring out how to handle of realities of federation.

[0] I am biased. I recently launched a service in this space: https://emauth.io

Re: LastPass stores passwords so securely, not even its users can access them

#55

The article went up an hour and a half ago, at the exact same time as https://status.lastpass.com/ updated to say they were investigating. In under an hour, they acknowledged, identified, fixed, and verified the issue. The fix went out less than half an hour after they learned about it, and this HN submission was posted 1 hour ago, so no one learning of the issue by means of this HN submission will have been able to…

[deleted]

Re: LastPass stores passwords so securely, not even its users can access them

#56
post #51

Earlier quoted context omitted.

If you have a Raspberry Pi lying around, there's a docker image for the excellent bitwarden_rs server available that makes it a snap to get up and running: https://github.com/dani-garcia/bitwarden_rs/wiki/Which-conta...

Forgive my ignorance, and possibly laziness, but if the Pi SD card dies do your passwords go with it?

Yes but for something like this backups (NAS, google drive, even a usb) are a must

Re: LastPass stores passwords so securely, not even its users can access them

#57

The article went up an hour and a half ago, at the exact same time as https://status.lastpass.com/ updated to say they were investigating. In under an hour, they acknowledged, identified, fixed, and verified the issue. The fix went out less than half an hour after they learned about it, and this HN submission was posted 1 hour ago, so no one learning of the issue by means of this HN submission will have been able to…

That’s bullshit.

In reality (I was affected by this and it’s now fixed), this happened 3 days ago, and I kept watching the status to see if they would identify it.

I had to upgrade to premium support for them to even respond to the issue. I filed the issue on Friday or Saturday, and they got back to me on Sunday. And it looks like they have fixed it now.

This was not a quick response time, don’t give them credit for this one.

Re: LastPass stores passwords so securely, not even its users can access them

#58
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

Same. I switched to 1Password a few years back after one of the lastpass security issues. I’ve been incredibly happy with the service and quality of software.

Re: LastPass stores passwords so securely, not even its users can access them

#59
A lot of people here are saying this is why you shouldn't trust cloud services for password management. And I agree. I use Keepass myself, however, that is not a viable solution for most of my family and friends. They need something dead simple, which is what cloud services like LastPass, Bitwarden etc. offer. I think the LastPass user interface is horrible, though...

Re: LastPass stores passwords so securely, not even its users can access them

#60

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

If you have a Raspberry Pi lying around, there's a docker image for the excellent bitwarden_rs server available that makes it a snap to get up and running: https://github.com/dani-garcia/bitwarden_rs/wiki/Which-conta...

The cost of electricity and my time is probably more than $10 a year.
Post reply on HN