Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

71–80 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#71
post #62
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

I tried that once but ran into so many errors for passwords that contained characters like ", or ;" that I gave up. Is there a way around this other then copying every entry manually?

You can edit the password recipe for websites that suck and don't allow certain characters.

Re: LastPass stores passwords so securely, not even its users can access them

#72

Why one shouldn't use cloud-based services. I'm sticking to keepass. (I'm syncing the keepass file over a cloud, but I still have a local copy on all my devices against cases like these)

Same, I encrypt my KeePass into VeraCrypt container and sync with dropbox, seems fairly secure to me for my use case.

Re: LastPass stores passwords so securely, not even its users can access them

#73
post #43

LP has a history of problems, but my company forces us to use that crappy product. I've complained about it for years. I use keepassx for personal, 1password for work, and lastpass for anything that I need to share with coworkers. I always wondered who got the kickback from LP.

>LP has a history of problems, but my company forces us to use that crappy product.

I've been using them the better part of a decade, I've never had an issue and find calling it a 'crappy product' to be shocking.

What sort of issues have you had?

Re: LastPass stores passwords so securely, not even its users can access them

#74

Earlier quoted context omitted.

The cost of electricity and my time is probably more than $10 a year.

I hear "the cost of electricity" thrown out a lot for self running a small service. A Pi uses ~2W. At $0.11/kWh, running that constantly is ~$1.93 a year. Of course electricity rates vary, but I usually find the cost of electricity to be overblown when it comes to compute. Power can be very cheap. However, I imagine spending an hour of your time is more than that $10 budget.

Yes, my time is worth more than $10/hour.

Also, I've never run a Pi for more than a few years without the SD card failing. Even when logging to a ram disk, something seems to fail eventually, and it is sometimes not found until the unit is rebooted.

Re: LastPass stores passwords so securely, not even its users can access them

#75

I feel like there have been enough incidents with LastPass that no one should be using them. Am I biased due to reporting, or is it the case that they can't be trusted?

I've been using them the better part of a decade, I've never had a single issue and am quite surprised to see so many people complaining about them/mentioning issues in this thread.

Re: LastPass stores passwords so securely, not even its users can access them

#77

IMO[0] everyone should have at most one password - to their email account. Everything else should be something along the lines of (in order of preference): 1) SSO (federated! Not the Google/Twitter/Facebook/GitHub oligopoly nonsense we have now), using email addresses as ids. 2) Emailed login links, a la Slack's magic links. Email addresses aren't perfect, but they're the globally unique, federated IDs we have, and g…

I hope that emailed login links cease to exist.

I work at a large company. As a combination of lots of security scanning and, I think, intentional slowdown for virus spread mitigation, external email can take minutes to be delivered.

More than 50% of the time I receive such a link (including from Slack, for example), it has timed out before it gets to me.

Just let me use a good, long, randomly-according-to-a-recipe-generated (and, if needed, 2FA) for services and I'm happy.

Re: LastPass stores passwords so securely, not even its users can access them

#79
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

1Password is excellent, been using them for years, but don't be surprised if they take a dip in quality in the coming years: a PEG invested a large amount of money in them late last year. Was really upset when I saw that.

Re: LastPass stores passwords so securely, not even its users can access them

#80

Some alternatives: * https://keepass.info/ * https://bitwarden.com/ * https://1password.com/

I'd recomend the more modern looking and cross-platform by design, KeePassXC, over the original KeePass.

https://keepassxc.org/

Post reply on HN