Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

251–260 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#251

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

The "Premium" service offers 2-step login (Yubikey) but is only one account. Is there a "Family Premium" ?

There is. If you plan on sharing some credentials with only one more person, you can make an "organization" for free and put some credentials in there. My Netflix account is in there for my wife, so if I decide to rotate the password she'll have access to it.

There's also some other stuff like our Wifi password, etc so that she doesn't have to write it down.

Re: LastPass stores passwords so securely, not even its users can access them

#252
post #226

Earlier quoted context omitted.

I really want pass or something like it, but the two times I've tried, I got stuck trying to figure out the gpg part. I suppose I should go and learn that properly anyways, since in spite of its UX it's still an extremely widely used and powerful tool, but it's a lot higher barrier to entry compared to "type in password, unlock vault".

I would recommend Keepass. There are a variety of clients available for lots of platforms.

I'm currently using keepassx(c) currently, actually:) That's mostly a good system for me, but I'm hitting some issues, mostly around syncing; syncthing is great, but it kinda sucks at taking care of conflicts, which pass (git) very much should manage nicely.

Re: LastPass stores passwords so securely, not even its users can access them

#253
post #220

Earlier quoted context omitted.

LP to Bitwarden as well here. The only issue I've found so far is MFA doesn't seem to be working on the (Linux) Firefox plugin, this could be a user error issue as I've not had time to look into it yet (only noticed it this morning).

MFA is working fine for me with Firefox on both Ubuntu and Fedora.

Just had a quick dig it appears that it will ask for MFA when logging in for the first time or if you log out and then back in but not when just unlocking the vault which is a little disappointing but not the end of the world.

Re: LastPass stores passwords so securely, not even its users can access them

#254
This will probably get buried, but this story had me shudder at the possibility of being locked out of my 1password vault in a similar scenario. In case anyone is in the same boat:

* My airplane-mode test passed both on my mobile device and browser (1password X).

* The team is aware of the situation with LP and wrote a very thoughtful response: https://discussions.agilebits.com/discussion/comment/544136/...

* From the response above, 1password is SOC2 certified, so availability is taken very seriously.

Re: LastPass stores passwords so securely, not even its users can access them

#255

Earlier quoted context omitted.

The "Premium" service offers 2-step login (Yubikey) but is only one account. Is there a "Family Premium" ?

Yes. It's called "Premium Access Addon". They charge additional cost of $40 /year. More info here - https://blog.bitwarden.com/premium-access-for-families-organ...

Thanks!

After reviewing what you actually get from a family plan, I'm not needing to be sharing enough credentials to make it worth the cost. I opted for a premium plan instead so that I can make use of yubikeys.

Re: LastPass stores passwords so securely, not even its users can access them

#256

Earlier quoted context omitted.

I'm sorry, what is your justification for not using cloud-based services? Lastpass (like pretty much all of these online password managers) will work offline, so if the service goes down, you can still access your data locally.

I've been wondering why people keep saying this. Do they not understand how password managers work??? LastPass and 1Password both work offline, the cloud is just for sync. Oy.

does 1pass have a desktop client?

Re: LastPass stores passwords so securely, not even its users can access them

#257

Earlier quoted context omitted.

Yes, my time is worth more than $10/hour. Also, I've never run a Pi for more than a few years without the SD card failing. Even when logging to a ram disk, something seems to fail eventually, and it is sometimes not found until the unit is rebooted.

Have you looked into alternatives? I'm about to swap out a Pi 3 for something a bit faster and without an SD card, but I'm not sure what. I was thinking NUC but they probably aren't nearly as efficient. Efficiency at idle, more than compute efficiency, is really what I'm seeking.

Running a Pi with a SSD over USB seems to be the best option at the moment. There are other SBCs with m.2 storage options which look neat as well but are obviously not nearly as well supported as the Pi line.

Re: LastPass stores passwords so securely, not even its users can access them

#258
post #210

Earlier quoted context omitted.

> provided absolutely zero security. I've been encrypting my Firefox password store for so many years I can't even remember. Is that not secure or something?

Yes, actually. https://palant.de/2018/03/10/master-password-in-firefox-or-t... (Maybe they've fixed this since, I'm not sure. It doesn't seem like security is being taken very seriously in any case.)

[deleted]

Re: LastPass stores passwords so securely, not even its users can access them

#259
As an alternative, lately, I've been using Passfindr. It's web-based but they have an offline solution so that as long as you have made a backup. This kind of crap won't shut you down. It will read out of the backup file through the browser. And I use it for a lot more than passwords. I pretty much use it for any kind of access. Works good.

Re: LastPass stores passwords so securely, not even its users can access them

#260
post #236

Earlier quoted context omitted.

This isn't as bad as Slack, where they will acknowledge an incident, but then if you go back and look at their status history a week ago it ends up being understated and they update the uptime to 100%. I know there is always the case where "it's just me", but I'm talking about an incident that was widely reported in the media because it was so widespread. While the incident is ongoing, they do provide status updates.…

Yeah slack has some very shady SLA practices. I don’t think we can trust companies to self report uptimes. There kind of needs to be a third party SLA escrow of some kind to really make things work.

Yeah, I've always encountered resistance when wanting to report accurate SLAs. I have found that typically SLAs are based on what the marketing team thinks sounds good, not what the technology can provide, so the goal is to hide outages and write legal documents that say "when we say uptime is guaranteed, what we mean is that we'll give you some insignificant amount of money when you're down for several days." So everything is legally in the clear, but customers assume some sort of reliability that doesn't exist. What this means is that it's a race to the bottom; if one company claims 100% uptime, the next company either has to explain why that's bullshit (and people react negatively to negativity, even when it's true), or do the same thing. The result is that everyone now has 100% uptime.

The problem with this model is that it doesn't allow engineering teams to set realistic goals to improve reliability. Because a customer being down for 3 days doesn't cost the company any money, you can't deploy expensive engineering resources to prevent that sort of thing from happening again. Meanwhile, if you track your SLA accurately, and compensate customers in a way that's commiserate with the inconvenience they experienced (something like "the entire month is free if we're down for 8 hours in a row"), then you can start doing real engineering. You have a clear number that shows where you're at now, and you have a goal for where you want to be, and you have a cost associated with that goal... suddenly you can make intelligent decisions about what to work on. This class of outage costs us $600,000 a year. It would take one engineer at $200,000 a year 3 months to fix it. There's $550,000 of free money. Instead of being a cost center, you're a profit center! And customers get a better product. How is that not a win? I'll never understand.

One thing I liked about working on Google Fiber back in the day is that US-based telephone support was not something that we would compromise on. It was expensive! So when we could eliminate classes of problems that people call in about, like poor WiFi connectivity or bad TV remote Bluetooth pairing, you could directly see the savings in support cost. You could spend a year debugging WiFi, and instead of looking like flushing money down the toilet, it looked like making money. It was a joy to work on. But obviously a very uncommon way of accounting. It's easier to say "everything is perfect, we dare you to cancel" than to invest in engineering. As an engineer, that's sad; we want the world to work better... but it's only possible with resources.

Post reply on HN