Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

61–70 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#61

The article went up an hour and a half ago, at the exact same time as https://status.lastpass.com/ updated to say they were investigating. In under an hour, they acknowledged, identified, fixed, and verified the issue. The fix went out less than half an hour after they learned about it, and this HN submission was posted 1 hour ago, so no one learning of the issue by means of this HN submission will have been able to…

> The fix went out less than half an hour after they learned about it,

The article says the issues started on Friday and users told them then. So, it seems to be three days for a fix, not half an hour.

Re: LastPass stores passwords so securely, not even its users can access them

#62
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

I tried that once but ran into so many errors for passwords that contained characters like ", or ;" that I gave up. Is there a way around this other then copying every entry manually?

Re: LastPass stores passwords so securely, not even its users can access them

#65

I continue to use `pass` [0]. Luckily I'm technically minded, so it's not too hard to manage my GPG keys or manage syncing the git repo every now and then. What it lacks in swish UI and automagically-configured browser extensions it gives in configurability, privacy, control over data, and freedom. [0]: https://www.passwordstore.org/

Pass changed my life. I cannot recommend it highly enough!

Re: LastPass stores passwords so securely, not even its users can access them

#66

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

The "Premium" service offers 2-step login (Yubikey) but is only one account. Is there a "Family Premium" ?

Re: LastPass stores passwords so securely, not even its users can access them

#67
Not actually related to the article, but the headline makes me think of the "Muddy Puddle Test" for crypto, which goes like this:

1) Drop your device(s) into a muddy puddle (destroying them).

2) Slip in said puddle so you hit your head. On waking up you're absolutely fine, but are entirely incapable of remembering your passwords or encryption keys.

3) Can you get your cloud data back?

If you can, then it's not actually secure.

Re: LastPass stores passwords so securely, not even its users can access them

#68
post #61

The article went up an hour and a half ago, at the exact same time as https://status.lastpass.com/ updated to say they were investigating. In under an hour, they acknowledged, identified, fixed, and verified the issue. The fix went out less than half an hour after they learned about it, and this HN submission was posted 1 hour ago, so no one learning of the issue by means of this HN submission will have been able to…

> The fix went out less than half an hour after they learned about it, The article says the issues started on Friday and users told them then. So, it seems to be three days for a fix, not half an hour.

> it seems to be three days for a fix, not half an hour.

You are trying to conflate 2 different metrics. The first assertion, is from the time the ticket was investigated, not submitted.

It might be useful to talk about expectation of service, since that's what you are getting at. 3 days (over a weekend) is reasonable for a free tier, I would think. For a paid tier, maybe it should be more immediate.

Re: LastPass stores passwords so securely, not even its users can access them

#69

The article went up an hour and a half ago, at the exact same time as https://status.lastpass.com/ updated to say they were investigating. In under an hour, they acknowledged, identified, fixed, and verified the issue. The fix went out less than half an hour after they learned about it, and this HN submission was posted 1 hour ago, so no one learning of the issue by means of this HN submission will have been able to…

That’s bullshit. In reality (I was affected by this and it’s now fixed), this happened 3 days ago, and I kept watching the status to see if they would identify it. I had to upgrade to premium support for them to even respond to the issue. I filed the issue on Friday or Saturday, and they got back to me on Sunday. And it looks like they have fixed it now. This was not a quick response time, don’t give them credit for…

It's a nice trick that many companies use.

The best way is to build small agents to monitor the service you depend on to know whether they truly respect their SLA. In case of LastPass they don't even have an SLA....so good luck with an updated status.

Re: LastPass stores passwords so securely, not even its users can access them

#70

Earlier quoted context omitted.

If you have a Raspberry Pi lying around, there's a docker image for the excellent bitwarden_rs server available that makes it a snap to get up and running: https://github.com/dani-garcia/bitwarden_rs/wiki/Which-conta...

The cost of electricity and my time is probably more than $10 a year.

I hear "the cost of electricity" thrown out a lot for self running a small service. A Pi uses ~2W. At $0.11/kWh, running that constantly is ~$1.93 a year. Of course electricity rates vary, but I usually find the cost of electricity to be overblown when it comes to compute. Power can be very cheap.

However, I imagine spending an hour of your time is more than that $10 budget.

Post reply on HN