Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

121–130 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#121

On a side, am I the only person that doesn't like The Register write style, especially the headings? Yeah, irony and fun all that you want, but it ends up looking like a gossip/tabloid magazine

It is very “British” with wit, puns, long running silly gags, in-jokes, smart headlines, sarcasm, and self-deprecating jokes.

However, The Register is usually technically correct and regularly breaks important news (good journalism). Minor technical (or grammatical) errors will be lambasted in comments.

Essentially, the style meshes well with it’s target readership, and they are very happy that anyone that doesn’t like the style auto-excludes themselves from the readership/community.

Re: LastPass stores passwords so securely, not even its users can access them

#122

Let's put our passwords on a remote server which convinces us they're secure. How did we even get here that such information leaves our control?

Most people access services from more than one device and are not capable of rolling, managing, and securing their own synchronized password database. That's how. It's not the best option, of course, but certainly better than weak and reused passwords, right?

Is convenience more important than security? That's what you're saying here.

Re: LastPass stores passwords so securely, not even its users can access them

#123

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

It's also much cheaper than LastPass. I was going to convert over to BitWarden the last time I was up to renew LastPass but that means I also have to retrain my family on how to use it. I'm gunning for sometime in the next year though.

Re: LastPass stores passwords so securely, not even its users can access them

#124
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

1Password is excellent, been using them for years, but don't be surprised if they take a dip in quality in the coming years: a PEG invested a large amount of money in them late last year. Was really upset when I saw that.

> a PEG invested a large amount of money in them late last year.

What is a PEG?

Re: LastPass stores passwords so securely, not even its users can access them

#125
post #61

Earlier quoted context omitted.

> The fix went out less than half an hour after they learned about it, The article says the issues started on Friday and users told them then. So, it seems to be three days for a fix, not half an hour.

> it seems to be three days for a fix, not half an hour. You are trying to conflate 2 different metrics. The first assertion, is from the time the ticket was investigated, not submitted. It might be useful to talk about expectation of service, since that's what you are getting at. 3 days (over a weekend) is reasonable for a free tier, I would think. For a paid tier, maybe it should be more immediate.

> 3 days (over a weekend) is reasonable for a free tier, I would think. For a paid tier, maybe it should be more immediate.

For most services, I'd expect free tiers to be strict subsets of paid tiers. I'd expect them to be running the same code, often on the same servers, as paid tiers. Free tier accounts would for the most part just have different per account settings.

If that is the case, and I was a paid tier user, I would be upset if it takes days to respond to problems on the free tier because if free tier accounts are running into problems there is a good chance paid tier accounts are also running into problems.

Maybe the problem really is one that only affects free tiers--something like, say, a load balancer mistakenly thinking the servers are overloaded and dropping free tier requests to ensure that paid tiers get served.

Perhaps then maybe you can make a case that it is OK to not fix it over a weekend. But even in that case there should be a prompt investigation when the free tier users start reporting problems in order to determine if it is something that will also hurt paid tier users.

If that investigation finds that it won't affect paid tiers, there should then at least be a status update explaining this. Free tier users are going to be Tweeting about, posting to HN and Reddit, etc., where paid tier users are going to see it.

You need to assure your paid tier users that things are fine for them and they aren't going to have their weekend messed up dealing with your outage.

Re: LastPass stores passwords so securely, not even its users can access them

#126

Earlier quoted context omitted.

Most people access services from more than one device and are not capable of rolling, managing, and securing their own synchronized password database. That's how. It's not the best option, of course, but certainly better than weak and reused passwords, right?

Is convenience more important than security? That's what you're saying here.

No. I'm saying that the vast majority of people are not capable of doing this, and that it's a better option than weak passwords.

Re: LastPass stores passwords so securely, not even its users can access them

#127

Earlier quoted context omitted.

I learned another nice trick from GCP the other day; Stackdriver log ingestion was down, at least for me and a number of people on Twitter, and they simply put a yellow warning at the top of status.cloud.google.com while fixing it instead of making an official incident. Magic, 100% uptime!

If the service is down for a limited amount of individuals I consider it still up. This does beg the question of how many constitutes "down". I think the nature of the problem and quantity of users affected is important.

I disagree. The SLA ought to be made on a per-customer basis. 1% of users affected would mean 1% of users would be entitled to refunds/remedies that the SLA prescribes.

Re: LastPass stores passwords so securely, not even its users can access them

#128

Earlier quoted context omitted.

>LP has a history of problems, but my company forces us to use that crappy product. I've been using them the better part of a decade, I've never had an issue and find calling it a 'crappy product' to be shocking. What sort of issues have you had?

LastPass is riddled with problems, and the quality has dropped precipitously since their acquisition by LogMeIn. For a sampling of their problems I suggest searching this site for their name. https://hn.algolia.com/?q=lastpass

I’ve used them for a long time. I noticed zero change in the service.

Re: LastPass stores passwords so securely, not even its users can access them

#129

I continue to use `pass` [0]. Luckily I'm technically minded, so it's not too hard to manage my GPG keys or manage syncing the git repo every now and then. What it lacks in swish UI and automagically-configured browser extensions it gives in configurability, privacy, control over data, and freedom. [0]: https://www.passwordstore.org/

With the dmenu wrapper (passmenu) or something similar for rofi there is almost no need for a browser extension.

I assume this approach doesn't auto-fill forms?

Re: LastPass stores passwords so securely, not even its users can access them

#130

Earlier quoted context omitted.

1Password is excellent, been using them for years, but don't be surprised if they take a dip in quality in the coming years: a PEG invested a large amount of money in them late last year. Was really upset when I saw that.

> a PEG invested a large amount of money in them late last year. What is a PEG?

I believe it stands for Private Equity Group.
Post reply on HN