Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

231–240 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#231

Not actually related to the article, but the headline makes me think of the "Muddy Puddle Test" for crypto, which goes like this: 1) Drop your device(s) into a muddy puddle (destroying them). 2) Slip in said puddle so you hit your head. On waking up you're absolutely fine, but are entirely incapable of remembering your passwords or encryption keys. 3) Can you get your cloud data back? If you can, then it's not actual…

What about biometrics?

Don't use biometrics for anything but convenience type features. You can't change your fingerprint if bad actors gets a hold of it.

Re: LastPass stores passwords so securely, not even its users can access them

#232

Earlier quoted context omitted.

I was a longtime LastPass customer, but the service just kept getting worse and worse, to the point where a year ago I realized I was spending more time fighting the user interface than it was saving me. And their support was absolutely useless. So I also switched over to 1Password, and never looked back. It is such a refreshing and trouble free experience compared to LP, and the few times I needed to ask a question,…

> but the service just kept getting worse and worse And more and more expensive. I used it for 8 years, cancelled this year after I noticed it was $45USD per year (over $50 CAD!). Impossible to justify with so many cheaper or free alternatives.

My version of Lastpass is free.

Re: LastPass stores passwords so securely, not even its users can access them

#233

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

The "Premium" service offers 2-step login (Yubikey) but is only one account. Is there a "Family Premium" ?

Yes. It's called "Premium Access Addon". They charge additional cost of $40 /year.

More info here - https://blog.bitwarden.com/premium-access-for-families-organ...

Re: LastPass stores passwords so securely, not even its users can access them

#234
post #210
post #182

Earlier quoted context omitted.

Until not so long ago, the browsers' password storages provided absolutely zero security. They are better now, but still password managers offer some advantages. For me the most important is the ability to use multiple browsers. But there's other stuff: random password generator, ability to store custom key/value pairs, 2FA, etc.

> provided absolutely zero security. I've been encrypting my Firefox password store for so many years I can't even remember. Is that not secure or something?

Yes, actually. https://palant.de/2018/03/10/master-password-in-firefox-or-t...

(Maybe they've fixed this since, I'm not sure. It doesn't seem like security is being taken very seriously in any case.)

Re: LastPass stores passwords so securely, not even its users can access them

#236

Earlier quoted context omitted.

I learned another nice trick from GCP the other day; Stackdriver log ingestion was down, at least for me and a number of people on Twitter, and they simply put a yellow warning at the top of status.cloud.google.com while fixing it instead of making an official incident. Magic, 100% uptime!

This isn't as bad as Slack, where they will acknowledge an incident, but then if you go back and look at their status history a week ago it ends up being understated and they update the uptime to 100%. I know there is always the case where "it's just me", but I'm talking about an incident that was widely reported in the media because it was so widespread. While the incident is ongoing, they do provide status updates.…

Yeah slack has some very shady SLA practices. I don’t think we can trust companies to self report uptimes.

There kind of needs to be a third party SLA escrow of some kind to really make things work.

Re: LastPass stores passwords so securely, not even its users can access them

#237

The article went up an hour and a half ago, at the exact same time as https://status.lastpass.com/ updated to say they were investigating. In under an hour, they acknowledged, identified, fixed, and verified the issue. The fix went out less than half an hour after they learned about it, and this HN submission was posted 1 hour ago, so no one learning of the issue by means of this HN submission will have been able to…

That’s bullshit. In reality (I was affected by this and it’s now fixed), this happened 3 days ago, and I kept watching the status to see if they would identify it. I had to upgrade to premium support for them to even respond to the issue. I filed the issue on Friday or Saturday, and they got back to me on Sunday. And it looks like they have fixed it now. This was not a quick response time, don’t give them credit for…

I also have been having the problem in a browser since last Friday. Fortunately, lpass command line tool kept working without issues, so I never bothered to report. The problem is fixed now. Maybe it was related to the MFA as I have been prompted for it today. FWIW, this was with Firefox and FreeBSD.

Re: LastPass stores passwords so securely, not even its users can access them

#239

Earlier quoted context omitted.

1Password is excellent, been using them for years, but don't be surprised if they take a dip in quality in the coming years: a PEG invested a large amount of money in them late last year. Was really upset when I saw that.

Which password manager would you say has the brightest future, for someone looking to start using one with no prior experience besides Chrome account sync?

Honestly it doesn't matter that much, it's fairly easy to change.

1password is nice for the polish especially on Mac; Bitwarden is nice to use, open-source, and the free plan is sufficient for most; and KeepassXC is a stable offline solution (that you can sync yourself).

Re: LastPass stores passwords so securely, not even its users can access them

#240

On a side, am I the only person that doesn't like The Register write style, especially the headings? Yeah, irony and fun all that you want, but it ends up looking like a gossip/tabloid magazine

It is very “British” with wit, puns, long running silly gags, in-jokes, smart headlines, sarcasm, and self-deprecating jokes. However, The Register is usually technically correct and regularly breaks important news (good journalism). Minor technical (or grammatical) errors will be lambasted in comments. Essentially, the style meshes well with it’s target readership, and they are very happy that anyone that doesn’t li…

Didn't mean to question the story quality, but even given the British humour, I still don't like The Register style.
Post reply on HN