Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

221–230 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#221

Earlier quoted context omitted.

I learned another nice trick from GCP the other day; Stackdriver log ingestion was down, at least for me and a number of people on Twitter, and they simply put a yellow warning at the top of status.cloud.google.com while fixing it instead of making an official incident. Magic, 100% uptime!

Saucelabs are kings of the "100% outage for 5% of our users = 95% availability" status update. In particular I'd see repeatable problems where they couldn't launch whatever browser X operating system in under 2 minutes (when our tests would time out) and list allocation time as 'elevated' (say, 8s average vs their normal of 3s). If you start believing your own statistics you get into almost as much trouble as believi…

> the "100% outage for 5% of our users = 95% availability" status update

What's a fair way of producing a single number though?

Re: LastPass stores passwords so securely, not even its users can access them

#222

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

Switched from LastPass to BitWarden over the weekend. I have 1,200+ passwords, and the transition was seamless. I even set up BitWarden on one of my web servers so that I can control my data -- even that took less than 30 minutes, thanks to BitWardenRS docker container. The only thing I have yet to figure out for BitWarden is how to get a little icon to show up next to user/password fields in forms. I just have to ri…

Given you use Firefox, have you considered using the built in Sync service and companion Lockwise mobile app:

https://hacks.mozilla.org/2018/11/firefox-sync-privacy/

I seriously considered Bitwarden not so long ago when I was looking for a password manager, and then realized I also need to maintain bookmarks across platforms and devices. Sadly Bitwarden doesn't offer that as a feature.

I'm curious if there is a differentiating feature of Bitwarden over Sync

Re: LastPass stores passwords so securely, not even its users can access them

#223

I like Enpass (enpass.io): - non-subscription version available - multi-platform (IOS, Android, MacOS, Linux, Windows) - offline access (local DB) - sync via non-Enpass servers (eg use dropbox, google drive, iCloud, box etc) - actively maintained I have been using for ~3 years on a revolving door of devices and have never experienced any issues - just works. (Not affiliated in any way with Enpass)

Mobile free version limited to 25 items. That's not really free for 99% of people.

Re: LastPass stores passwords so securely, not even its users can access them

#224
post #99

What’s the best (translation: easiest) password manager for non-technical users with Windows and iOS devices? I’m trying to find a good solution to help protect the accounts of my older parents. I use a legacy non-subscription 1Password version for myself so I’m not up to date about the subscription model or product changes of recent versions.

I moved myself and the whole family to the often-mentioned Bitwarden 3 years ago. It's been fantastic.

Re: LastPass stores passwords so securely, not even its users can access them

#225
post #221

Earlier quoted context omitted.

Saucelabs are kings of the "100% outage for 5% of our users = 95% availability" status update. In particular I'd see repeatable problems where they couldn't launch whatever browser X operating system in under 2 minutes (when our tests would time out) and list allocation time as 'elevated' (say, 8s average vs their normal of 3s). If you start believing your own statistics you get into almost as much trouble as believi…

> the "100% outage for 5% of our users = 95% availability" status update What's a fair way of producing a single number though?

Per user guarantee levels. i.e 100% outage for 1 user is equivalent to a 0% availability guarantee.

The relationship between client and service is the same irrespective of the number of clients the service has - a number which means exactly nothing to the client.

But more importantly, availability numbers are for informing a client about how much incidents outside their house can affect them, and reasonable courses of action to take when it does.

When using the numbers internally, the fudged number is equally misleading. Unfortunately there exist fewer adversarial relationships internal to an organisation to prevent these short sighted statistical nonsenses.

Re: LastPass stores passwords so securely, not even its users can access them

#226

I continue to use `pass` [0]. Luckily I'm technically minded, so it's not too hard to manage my GPG keys or manage syncing the git repo every now and then. What it lacks in swish UI and automagically-configured browser extensions it gives in configurability, privacy, control over data, and freedom. [0]: https://www.passwordstore.org/

I really want pass or something like it, but the two times I've tried, I got stuck trying to figure out the gpg part. I suppose I should go and learn that properly anyways, since in spite of its UX it's still an extremely widely used and powerful tool, but it's a lot higher barrier to entry compared to "type in password, unlock vault".

I would recommend Keepass. There are a variety of clients available for lots of platforms.

Re: LastPass stores passwords so securely, not even its users can access them

#227

Some alternatives: * https://keepass.info/ * https://bitwarden.com/ * https://1password.com/

Keepass is very difficult to use in an automated way and the open-source clients are buggy. I had to search for hours for an ancient Perl script which amazingly works with both 1.x and 2.x Keepass databases (still the only library I've found that does so), then write a custom app to convert the output into something else.

I help maintain a library called pykeepass which you might be interested in.

Re: LastPass stores passwords so securely, not even its users can access them

#228

KeePass/KeePassXC on each device. Complex keyfile manually copied to each device (never in the cloud). Password database protected by the keyfile and a memorable complex password stored in your cloud folder of choice synced to your devices. You now have a free, open source, secure, cloud synced password service. For additional security, you can manually copy the database between devices as well. Or keep a separate ma…

OK but can you tell my 80 year-old mom how to do this?

You can set it up for a non-techie and then just let it do its thing. I've set this up for a few people who don't have a clue what a key file is.

Re: LastPass stores passwords so securely, not even its users can access them

#229

Earlier quoted context omitted.

I disagree. The SLA ought to be made on a per-customer basis. 1% of users affected would mean 1% of users would be entitled to refunds/remedies that the SLA prescribes.

GCP has different SLAs for each product, but the ones I've seen are per-customer. The details vary by service, but they generally define downtime, like x% errors for y% amount of time, and then have financial penalties for z% downtime[1]. There are sometimes clauses requiring retries with exponential backoff[2]. Their SLAs are short and readable. It is worth reading a few of them, especially if you have a SaaS and ar…

[deleted]

Re: LastPass stores passwords so securely, not even its users can access them

#230

Earlier quoted context omitted.

If the service is down for a limited amount of individuals I consider it still up. This does beg the question of how many constitutes "down". I think the nature of the problem and quantity of users affected is important.

I disagree. The SLA ought to be made on a per-customer basis. 1% of users affected would mean 1% of users would be entitled to refunds/remedies that the SLA prescribes.

I did not realize there is tracking of uptime for individual agreements. I think the status.cloud.google.com from the commenter I was responding to is a general uptime status for all users, correct? I checked out the GCP SLA and see that it is tracked on a monthly basis which affects billing(as antoncohen points out)
Post reply on HN