Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

131–140 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#132

I continue to use `pass` [0]. Luckily I'm technically minded, so it's not too hard to manage my GPG keys or manage syncing the git repo every now and then. What it lacks in swish UI and automagically-configured browser extensions it gives in configurability, privacy, control over data, and freedom. [0]: https://www.passwordstore.org/

i love pass on GNU/linux but occasionally have to use OS X for a particular sponsor. the brew impl of pass using zsh does not seem to be autocompleting. i believe i have installed the correct autocompletions and mucked with .zshrc (.zshenv does not seem to be respected on OS X).

any recommendations for OS X? is it worth building from source and/or getting it working outside of brew?

Re: LastPass stores passwords so securely, not even its users can access them

#133
post #128

Earlier quoted context omitted.

LastPass is riddled with problems, and the quality has dropped precipitously since their acquisition by LogMeIn. For a sampling of their problems I suggest searching this site for their name. https://hn.algolia.com/?q=lastpass

I’ve used them for a long time. I noticed zero change in the service.

Ok man if it works for you then keep on keeping on. I have chosen to leave the service due to a huge drop in reliability and several major security and service incidents.

Re: LastPass stores passwords so securely, not even its users can access them

#134
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

I was a longtime LastPass customer, but the service just kept getting worse and worse, to the point where a year ago I realized I was spending more time fighting the user interface than it was saving me. And their support was absolutely useless.

So I also switched over to 1Password, and never looked back. It is such a refreshing and trouble free experience compared to LP, and the few times I needed to ask a question, their support team got right back to me with the correct answer the first time.

Re: LastPass stores passwords so securely, not even its users can access them

#135
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

Bitwarden is also very good

Re: LastPass stores passwords so securely, not even its users can access them

#136

Why one shouldn't use cloud-based services. I'm sticking to keepass. (I'm syncing the keepass file over a cloud, but I still have a local copy on all my devices against cases like these)

A big part of why I use a password manager is so I can easily share passwords between devices and with my wife. While you can do this with a local service, it's a PITA.

All the downsides of online services are mitigated by:

1) Keeping a local backup of your passwords 2) Using a service which only stores encrypted vaults which are decrypted on your device with a locally stored password.

Re: LastPass stores passwords so securely, not even its users can access them

#137
post #69

Earlier quoted context omitted.

It's a nice trick that many companies use. The best way is to build small agents to monitor the service you depend on to know whether they truly respect their SLA. In case of LastPass they don't even have an SLA....so good luck with an updated status.

I learned another nice trick from GCP the other day; Stackdriver log ingestion was down, at least for me and a number of people on Twitter, and they simply put a yellow warning at the top of status.cloud.google.com while fixing it instead of making an official incident. Magic, 100% uptime!

This isn't as bad as Slack, where they will acknowledge an incident, but then if you go back and look at their status history a week ago it ends up being understated and they update the uptime to 100%.

I know there is always the case where "it's just me", but I'm talking about an incident that was widely reported in the media because it was so widespread. While the incident is ongoing, they do provide status updates... but after a couple weeks pass, the global outage that affects everyone silently disappears from their archive. It's quite interesting.

Re: LastPass stores passwords so securely, not even its users can access them

#138
The reactionary nature of the typical HN poster is on full display here.

Lastpass had a bug that affected a small percentage of users. They identified and fixed the bug within several days. What more do you want?

Is there really a competing product out there that guarantees NO BUGS? So, then, why the extreme nod to #CancelCulture for what appeared to be just a temporary issue?

Re: LastPass stores passwords so securely, not even its users can access them

#139

The article went up an hour and a half ago, at the exact same time as https://status.lastpass.com/ updated to say they were investigating. In under an hour, they acknowledged, identified, fixed, and verified the issue. The fix went out less than half an hour after they learned about it, and this HN submission was posted 1 hour ago, so no one learning of the issue by means of this HN submission will have been able to…

Life is so good that we are re-using brain structures evolved to avoid being eaten by lions to complain about buggy software.

Re: LastPass stores passwords so securely, not even its users can access them

#140
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

I was a longtime LastPass customer, but the service just kept getting worse and worse, to the point where a year ago I realized I was spending more time fighting the user interface than it was saving me. And their support was absolutely useless. So I also switched over to 1Password, and never looked back. It is such a refreshing and trouble free experience compared to LP, and the few times I needed to ask a question,…

When you say, "Service kept getting worse and worse..." it means you contacted them multiple times. Yikes!

I've been using LastPass for 8 years and I've never needed any support, but I only pay for a personal version, not corporate.

I realize that's an anecdote, but what kinds of problems are people having?

Post reply on HN