Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

191–200 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#191
post #102

Earlier quoted context omitted.

> it seems to be three days for a fix, not half an hour. You are trying to conflate 2 different metrics. The first assertion, is from the time the ticket was investigated, not submitted. It might be useful to talk about expectation of service, since that's what you are getting at. 3 days (over a weekend) is reasonable for a free tier, I would think. For a paid tier, maybe it should be more immediate.

> 3 days (over a weekend) is reasonable for a free tier, I would think. For a paid tier, maybe it should be more immediate. This line of reasoning sounds backwards to me. It is the importance of the service that drives the needed level of reliability and people should expect there to be a cost to match that level of urgency and have guarantees that the vendor understands and will meet those needs. If LastPass expects…

They're obviously meeting a minimum reliability level for the free tier or else no one would be using it because they would find it too unreliable. The argument is about whether their resolution time for the free tier is acceptably fast which can be measured by how many people left the service because of this event. Paying money gets you better service is the other idea in what you quoted, it's hard to imagine why you wouldn't give people better service for paying money unless you were getting more value off them through practices such as data collection. But privacy activists hate the poor so it's pretty hard to thoroughly monetize the free tier without someone trying to start a boycott to make their world a better place.

Re: LastPass stores passwords so securely, not even its users can access them

#192
post #188

Earlier quoted context omitted.

Life is so good that we are re-using brain structures evolved to avoid being eaten by lions to complain about buggy software.

Nowdays its more probable that one dies because of buggy software (Boeing MCAS) than get eaten by lions.

If you find out about a bug in MCAS, you definitely should complain about it.

Re: LastPass stores passwords so securely, not even its users can access them

#193
post #69

Earlier quoted context omitted.

It's a nice trick that many companies use. The best way is to build small agents to monitor the service you depend on to know whether they truly respect their SLA. In case of LastPass they don't even have an SLA....so good luck with an updated status.

I think this is an artifact of how SLAs are tied to billing. Anyone who had ever billed a corporation knows how they will jerk you around. It’s obvious that you won’t get a straight answer if you go and ask a company how much they owe you. That’s what a status page is. It’s the company’s first offer in the negotiation on how much they owe you for the outage. You need to calculate your own number in response. Maybe a…

Well, then what's the point in keeping a status page ? Ah, right. Marketing.

That's my conclusion on what status pages have become. Which of course raises the question: what do I do when I see a service with N problems in their status pages over the last X days? Are they being naive, or was their service so bad that they were forced to write it down?

I agree with you, there is a lot of money to make there. I think there are already a few companies doing that, though.

Re: LastPass stores passwords so securely, not even its users can access them

#194

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

Switched from LastPass to BitWarden over the weekend. I have 1,200+ passwords, and the transition was seamless. I even set up BitWarden on one of my web servers so that I can control my data -- even that took less than 30 minutes, thanks to BitWardenRS docker container. The only thing I have yet to figure out for BitWarden is how to get a little icon to show up next to user/password fields in forms. I just have to ri…

LastPass is $36/year now!? It used to be $12/year (prior to their acquisition by LogMeIn, which is when I bailed).

Re: LastPass stores passwords so securely, not even its users can access them

#195
post #193

Earlier quoted context omitted.

I think this is an artifact of how SLAs are tied to billing. Anyone who had ever billed a corporation knows how they will jerk you around. It’s obvious that you won’t get a straight answer if you go and ask a company how much they owe you. That’s what a status page is. It’s the company’s first offer in the negotiation on how much they owe you for the outage. You need to calculate your own number in response. Maybe a…

Well, then what's the point in keeping a status page ? Ah, right. Marketing. That's my conclusion on what status pages have become. Which of course raises the question: what do I do when I see a service with N problems in their status pages over the last X days? Are they being naive, or was their service so bad that they were forced to write it down? I agree with you, there is a lot of money to make there. I think th…

I think when a service provides its own status page, the customers are less likely to build their own status monitoring, so the service can get away with more downtime.

Re: LastPass stores passwords so securely, not even its users can access them

#196
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

I was a longtime LastPass customer, but the service just kept getting worse and worse, to the point where a year ago I realized I was spending more time fighting the user interface than it was saving me. And their support was absolutely useless. So I also switched over to 1Password, and never looked back. It is such a refreshing and trouble free experience compared to LP, and the few times I needed to ask a question,…

>but the service just kept getting worse and worse

And more and more expensive. I used it for 8 years, cancelled this year after I noticed it was $45USD per year (over $50 CAD!). Impossible to justify with so many cheaper or free alternatives.

Re: LastPass stores passwords so securely, not even its users can access them

#197
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

1Password is excellent, been using them for years, but don't be surprised if they take a dip in quality in the coming years: a PEG invested a large amount of money in them late last year. Was really upset when I saw that.

Which password manager would you say has the brightest future, for someone looking to start using one with no prior experience besides Chrome account sync?

Re: LastPass stores passwords so securely, not even its users can access them

#198

Earlier quoted context omitted.

I hear "the cost of electricity" thrown out a lot for self running a small service. A Pi uses ~2W. At $0.11/kWh, running that constantly is ~$1.93 a year. Of course electricity rates vary, but I usually find the cost of electricity to be overblown when it comes to compute. Power can be very cheap. However, I imagine spending an hour of your time is more than that $10 budget.

Yes, my time is worth more than $10/hour. Also, I've never run a Pi for more than a few years without the SD card failing. Even when logging to a ram disk, something seems to fail eventually, and it is sometimes not found until the unit is rebooted.

Have you looked into alternatives? I'm about to swap out a Pi 3 for something a bit faster and without an SD card, but I'm not sure what. I was thinking NUC but they probably aren't nearly as efficient. Efficiency at idle, more than compute efficiency, is really what I'm seeking.

Re: LastPass stores passwords so securely, not even its users can access them

#199

I continue to use `pass` [0]. Luckily I'm technically minded, so it's not too hard to manage my GPG keys or manage syncing the git repo every now and then. What it lacks in swish UI and automagically-configured browser extensions it gives in configurability, privacy, control over data, and freedom. [0]: https://www.passwordstore.org/

I really want pass or something like it, but the two times I've tried, I got stuck trying to figure out the gpg part. I suppose I should go and learn that properly anyways, since in spite of its UX it's still an extremely widely used and powerful tool, but it's a lot higher barrier to entry compared to "type in password, unlock vault".

The gist of it is that you need a keypair (a public and private key), which GPG can generate for you.

Then whenever you insert something into the `pass` database (which is just a directory tree full of encrypted plaintext files) the tool uses the public key to encrypt the password (or anything else):

    pass generate --no-symbols shopping/ebay 16
Later, when you want to read a password, you ask pass to decrypt the file using the private key from your keypair:

    pass shopping/ebay 16
The difficulty is really all in managing the keys, which can be quite a faff to set up and then manage. If you're only using gpg for `pass`, IMO it's easiest to copy the keypair (which gpg generated) to all your other machines.

A quick web search brought up a gist [0] which shows how to quickly get up and running on a single machine.

If you want to use it on another laptop/desktop/*nix-like machine you'll need to export both your public and private gpg keys and then import them on the other machine. When using a phone you have to do something similar. The Android clients were fairly straightforward, but Pass for iOS had a very, very clunky way of getting the keys across. Regardless, it boils down to this: get the gpg keypair on all of the devices and then get them all using the same git repo for pass.

[0]: https://gist.github.com/flbuddymooreiv/a4f24da7e0c3552942ff

Re: LastPass stores passwords so securely, not even its users can access them

#200

Earlier quoted context omitted.

Most people access services from more than one device and are not capable of rolling, managing, and securing their own synchronized password database. That's how. It's not the best option, of course, but certainly better than weak and reused passwords, right?

Is convenience more important than security? That's what you're saying here.

Before using a password manager: I'm using short, memorable (often repeated) passwords that are rarely, if ever, changed.

After using a password manager: I'm using long (generally 64 characters), unique passwords, and if one is compromised, it's a 30s job to change it on all of my devices.

Convenience _enables_ security. I could probably roll my syncing solution, but I would _not_ be convinced it is secure (I don't have that level of expertise), and I would probably end up using a third party anyway (Dropbox/Digital Ocean). I'm not going to sync it manually to the 6 or so devices I regularly use, plus others I use less frequently (it may be more secure, but it's not practical). Because it's low friction, I end up using it more, so it's a _net_ gain in security, even if it isn't perfect.

Post reply on HN