Earlier quoted context omitted.
> it seems to be three days for a fix, not half an hour. You are trying to conflate 2 different metrics. The first assertion, is from the time the ticket was investigated, not submitted. It might be useful to talk about expectation of service, since that's what you are getting at. 3 days (over a weekend) is reasonable for a free tier, I would think. For a paid tier, maybe it should be more immediate.
> 3 days (over a weekend) is reasonable for a free tier, I would think. For a paid tier, maybe it should be more immediate. For most services, I'd expect free tiers to be strict subsets of paid tiers. I'd expect them to be running the same code, often on the same servers, as paid tiers. Free tier accounts would for the most part just have different per account settings. If that is the case, and I was a paid tier user…
LastPass stores passwords so securely, not even its users can access them
201–210 of 266 posts
Re: LastPass stores passwords so securely, not even its users can access them
#202Yeah I will never trust a third party password system. Writing down on paper works great. For most unimportant accounts use oauth or make up a random password and forget it - if you need it again reset the password.
I'm sorry but that is just ridiculous and time prohibitive.
Is this generally considered to be not viable?
Re: LastPass stores passwords so securely, not even its users can access them
#203Earlier quoted context omitted.
I hear "the cost of electricity" thrown out a lot for self running a small service. A Pi uses ~2W. At $0.11/kWh, running that constantly is ~$1.93 a year. Of course electricity rates vary, but I usually find the cost of electricity to be overblown when it comes to compute. Power can be very cheap. However, I imagine spending an hour of your time is more than that $10 budget.
> However, I imagine spending an hour of your time is more than that $10 budget. I always find this a weird way to judge things. Are people actually spending the time they'd be earning money to set these kinds of things up?
Re: LastPass stores passwords so securely, not even its users can access them
#204Earlier quoted context omitted.
> I'm not familiar with "theregister.co.uk" Then you're not qualified to be discussing software or the tech industry, frankly.
Or we're in an era where that sneering prototype for clickbait blogs is being rightly consigned to the dustbin of history. When faced with a link to an article on The Register, searching for the source it's been copied from is a good first step.
Re: LastPass stores passwords so securely, not even its users can access them
#205IMO[0] everyone should have at most one password - to their email account. Everything else should be something along the lines of (in order of preference): 1) SSO (federated! Not the Google/Twitter/Facebook/GitHub oligopoly nonsense we have now), using email addresses as ids. 2) Emailed login links, a la Slack's magic links. Email addresses aren't perfect, but they're the globally unique, federated IDs we have, and g…
Email is an incredibly vulnerable single point of failure. Plus the existing password infrastructure of the web isn't going away. Password managers are the best and most realistic option for most people.
I found out that when I added a backup email to my gmail that it had the opposite effect that was desired - losing access to the backup email meant I couldn't recover the account even though I still had access to the primary. I still can't get over the perverse, Kafka-esque feeling, years later. Partly because I am still logged in, yet I have no way of restoring my "ownership" and using it again.
Re: LastPass stores passwords so securely, not even its users can access them
#206Earlier quoted context omitted.
> it seems to be three days for a fix, not half an hour. You are trying to conflate 2 different metrics. The first assertion, is from the time the ticket was investigated, not submitted. It might be useful to talk about expectation of service, since that's what you are getting at. 3 days (over a weekend) is reasonable for a free tier, I would think. For a paid tier, maybe it should be more immediate.
> 3 days (over a weekend) is reasonable for a free tier, I would think. For a paid tier, maybe it should be more immediate. This line of reasoning sounds backwards to me. It is the importance of the service that drives the needed level of reliability and people should expect there to be a cost to match that level of urgency and have guarantees that the vendor understands and will meet those needs. If LastPass expects…
Re: LastPass stores passwords so securely, not even its users can access them
#207So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/
Bitwarden is also very good
Re: LastPass stores passwords so securely, not even its users can access them
#208Earlier quoted context omitted.
I was a longtime LastPass customer, but the service just kept getting worse and worse, to the point where a year ago I realized I was spending more time fighting the user interface than it was saving me. And their support was absolutely useless. So I also switched over to 1Password, and never looked back. It is such a refreshing and trouble free experience compared to LP, and the few times I needed to ask a question,…
I've never used LastPass, why do people use it (or other password managers) instead of the built in browser password manager?
There's no (non-cloud) syncing, or easy backups. There's no file attachments, or custom fields, or non-website-based accounts. There's no automatic checking for duplicate passwords, or old passwords, or alerts for websites known to have been compromised.
I don't use a web-based password manager like LastPass because I don't really trust it (for either security or reliability), but local password managers are great for storing all kinds of private data. How would I store my driver's license, my storage unit lockbox combo, or my marrow donor registry ID in a web browser?
Re: LastPass stores passwords so securely, not even its users can access them
#209Earlier quoted context omitted.
I was a longtime LastPass customer, but the service just kept getting worse and worse, to the point where a year ago I realized I was spending more time fighting the user interface than it was saving me. And their support was absolutely useless. So I also switched over to 1Password, and never looked back. It is such a refreshing and trouble free experience compared to LP, and the few times I needed to ask a question,…
I still use it but their support gets super defensive if you have any criticism about it. Their "new" 1pass X still sucks and recently has been going backwards in terms of usability. They keep promising feature parity between windows/mac too but this new browser plugin seems to be their fallback excuse. If I wasn't so heavily invested in it I'd switch in a heartbeat. I need something that works across ios/mac/windows…
Overall, I've been quite happy with it and my family has loved it.
Re: LastPass stores passwords so securely, not even its users can access them
#210Earlier quoted context omitted.
I've never used LastPass, why do people use it (or other password managers) instead of the built in browser password manager?
Until not so long ago, the browsers' password storages provided absolutely zero security. They are better now, but still password managers offer some advantages. For me the most important is the ability to use multiple browsers. But there's other stuff: random password generator, ability to store custom key/value pairs, 2FA, etc.
I've been encrypting my Firefox password store for so many years I can't even remember.
Is that not secure or something?