Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

111–120 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#111

Earlier quoted context omitted.

I learned another nice trick from GCP the other day; Stackdriver log ingestion was down, at least for me and a number of people on Twitter, and they simply put a yellow warning at the top of status.cloud.google.com while fixing it instead of making an official incident. Magic, 100% uptime!

If the service is down for a limited amount of individuals I consider it still up. This does beg the question of how many constitutes "down". I think the nature of the problem and quantity of users affected is important.

[deleted]

Re: LastPass stores passwords so securely, not even its users can access them

#112

Some alternatives: * https://keepass.info/ * https://bitwarden.com/ * https://1password.com/

I evaluated a bunch of team password managers last year. Lastpass was really buggy and had a confusing UI. Dashlane also had odd limitations. 1password had a good UI but the "master key" system is difficult for users to use. It was also more expensive. I ended up recommending Bitwarden. Surprisingly the open source option had a great UI and great clients, with the bonus of being open source on both ends.

Which enterprise password managers did you evaluate? Did you get a chance to take a look at SAASPASS? Is there a link to it? And what were your evaluation criteria?

Re: LastPass stores passwords so securely, not even its users can access them

#113
post #50

So in response to this story I decided to delete my (premium) account with them. After confirming multiple times (good thing), I was shown this error: https://i.imgur.com/4dpn6d5.png How does error handling like this even make it to production? I got an email as well confirming my account deletion and I can no longer log in. But all in all this clearly does increase my trust in Lastpass's security competence.

Reading this post reminded me of my LP account so I went to delete it and had the exact same experience than you...

Re: LastPass stores passwords so securely, not even its users can access them

#114
I have been using and paying LastPass since it launched with no serious issues and a few minor ones.

The Register article makes gives no indication as to the number of users having trouble with the current issue.

My single issue with LastPass is that they don't offer an APK download options separate from the Google Play store, so my slow and steady migration will require, at some point, migrating to a different password manager.

I made a trouble ticket regarding this issue and they informed me they have no plans to offer a separately downloadable APK.

Re: LastPass stores passwords so securely, not even its users can access them

#116
I’ll never forget when I was issued a new computer at a new job with LastPass installed. It kept popping up a modal dialog (modal to the entire browser) with some inscrutable network error message. I never even bothered trying to use it after that.

Re: LastPass stores passwords so securely, not even its users can access them

#117

Earlier quoted context omitted.

Same. And at 10$/year, its not like its un-affordable. Its probably my 3-4th most used piece of software, after win10, firefox, and thunderbird.

I just wish I could donate. I don't need the premium features, and I don't need yet-another-subscription-plan to worry about.

I subscribe to Bitwarden but this is a real issue with a lot of things: subscription overload.

It is especially bad with newspapers where everyone seems to be optimizing only for subscribers, not for sale of individual news items or even single day access.

Consequently I don't buy (except one local and one national one.)

The Guardian seems to be the winner in my case. They accept donations and get $10 for each thing I read there it seems :-]

Re: LastPass stores passwords so securely, not even its users can access them

#118
Based on this news, I just looked around and discovered that LastPass has a way to export a CSV file of all the passwords in plaintext. I just did that and have a PGP'd archive of my passwords stored locally. Not a bad thing to do with any password manager.

Re: LastPass stores passwords so securely, not even its users can access them

#119

Why one shouldn't use cloud-based services. I'm sticking to keepass. (I'm syncing the keepass file over a cloud, but I still have a local copy on all my devices against cases like these)

I had been on keepass for years. My wife never liked it. Last month, I switched to self-hosted bitwarden, hosted on digital ocean with automatic snapshots. The experience is so much better. Easy password management on multiple devices and now my wife actively uses it. Highly recommend.

Re: LastPass stores passwords so securely, not even its users can access them

#120
post #50

So in response to this story I decided to delete my (premium) account with them. After confirming multiple times (good thing), I was shown this error: https://i.imgur.com/4dpn6d5.png How does error handling like this even make it to production? I got an email as well confirming my account deletion and I can no longer log in. But all in all this clearly does increase my trust in Lastpass's security competence.

I got the same error while deleting my account over a month ago when it was announced that their parent company LogMeIn had been bought by private equity: https://www.zdnet.com/article/logmein-sells-to-private-equit...

So the deletion process has been erroring in that way for at least a month now.

Post reply on HN