Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

171–180 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#173

Earlier quoted context omitted.

I was a longtime LastPass customer, but the service just kept getting worse and worse, to the point where a year ago I realized I was spending more time fighting the user interface than it was saving me. And their support was absolutely useless. So I also switched over to 1Password, and never looked back. It is such a refreshing and trouble free experience compared to LP, and the few times I needed to ask a question,…

I still use it but their support gets super defensive if you have any criticism about it. Their "new" 1pass X still sucks and recently has been going backwards in terms of usability. They keep promising feature parity between windows/mac too but this new browser plugin seems to be their fallback excuse. If I wasn't so heavily invested in it I'd switch in a heartbeat. I need something that works across ios/mac/windows…

Hi, I work for AgileBits, makers of 1Password.

I can't comment on the defensive part, but text can often be harder to parse in conversation so perhaps it was that? I generally find our support team to be pretty understanding but I am sorry if our support team didn't properly handle your concerns and feedback.

Feature parity is a tricky one. The Mac (and since it's shared code in a lot of ways, the iOS app) have been around a lot longer. Dating back to just a bit after I started here 8 years ago we started work on 1Password 4 for Mac and iOS.

The Windows app was rebooted completely a few years back and has been playing catch up since.

Feature parity is the ideal, but it isn't something that is going to happen overnight and we're still trying to do a variety of things to make that happen. But without slowing down our Mac team the Windows app will never really reach feature parity. With that in mind I know our Windows team really wants to try to be a lot closer and they're working hard to do it, but we're all sorry it hasn't moved faster than we'd all like.

If you have specific feedback feel free to write into our support and mention me (Kyle) and that your support request be answered by me. Please include a link to this thread just for reference and I'll make sure to look into all of your comments and concerns.

Again, very sorry we haven't met your expectations. Know that our expectations haven't been met either and that we're working hard to try to give everyone what they want on our Windows application.

Kyle

1Password Security Team

Re: LastPass stores passwords so securely, not even its users can access them

#174

Earlier quoted context omitted.

The cost of electricity and my time is probably more than $10 a year.

I hear "the cost of electricity" thrown out a lot for self running a small service. A Pi uses ~2W. At $0.11/kWh, running that constantly is ~$1.93 a year. Of course electricity rates vary, but I usually find the cost of electricity to be overblown when it comes to compute. Power can be very cheap. However, I imagine spending an hour of your time is more than that $10 budget.

> However, I imagine spending an hour of your time is more than that $10 budget.

I always find this a weird way to judge things. Are people actually spending the time they'd be earning money to set these kinds of things up?

Re: LastPass stores passwords so securely, not even its users can access them

#175
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

I was a longtime LastPass customer, but the service just kept getting worse and worse, to the point where a year ago I realized I was spending more time fighting the user interface than it was saving me. And their support was absolutely useless. So I also switched over to 1Password, and never looked back. It is such a refreshing and trouble free experience compared to LP, and the few times I needed to ask a question,…

had a brief stint with lastpass and hated my life. 1Password is just infinitely better, no contest.

Re: LastPass stores passwords so securely, not even its users can access them

#176

Let's put our passwords on a remote server which convinces us they're secure. How did we even get here that such information leaves our control?

In theory they can do more security, than you get when you just store a keepass file on a server. Things like temporarily blocking access when GeoIP information for the client changes, or a lot of secrets are accessed in bulk. The keepass file, you only lose once and the attacker has years (or up to your next rotation) to crack it.

Re: LastPass stores passwords so securely, not even its users can access them

#177

Based on this news, I just looked around and discovered that LastPass has a way to export a CSV file of all the passwords in plaintext. I just did that and have a PGP'd archive of my passwords stored locally. Not a bad thing to do with any password manager.

I think I did this once with one password service and was surprised that they don't even send a warning email to inform me, that that just happened... very scary.

Re: LastPass stores passwords so securely, not even its users can access them

#178

I switched to Bitwarden after certain grievances with LastPass which I don't even recall what they were now.

The final straw for me was LastPass being very late on going WebExtension for Firefox. Not having a working password manager was not an option and the move to Bitwarden was very smooth.

Re: LastPass stores passwords so securely, not even its users can access them

#179

Earlier quoted context omitted.

I hear "the cost of electricity" thrown out a lot for self running a small service. A Pi uses ~2W. At $0.11/kWh, running that constantly is ~$1.93 a year. Of course electricity rates vary, but I usually find the cost of electricity to be overblown when it comes to compute. Power can be very cheap. However, I imagine spending an hour of your time is more than that $10 budget.

> However, I imagine spending an hour of your time is more than that $10 budget. I always find this a weird way to judge things. Are people actually spending the time they'd be earning money to set these kinds of things up?

Any time they spent is time they could have spent earning money instead. They may not have wanted to earn money with their free time, but did they want to set up a password manager with their free time either? It's not exactly a leisure activity for most users

Re: LastPass stores passwords so securely, not even its users can access them

#180

The article went up an hour and a half ago, at the exact same time as https://status.lastpass.com/ updated to say they were investigating. In under an hour, they acknowledged, identified, fixed, and verified the issue. The fix went out less than half an hour after they learned about it, and this HN submission was posted 1 hour ago, so no one learning of the issue by means of this HN submission will have been able to…

> The fix went out less than half an hour after they learned about it

That's doesn't appear to be true. In one of the twitter feeds linked to in the article, "LastPass Support" says they are "actively investigating" reports on the 17th, so they knew something was up at least that far back.

Post reply on HN