Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

261–266 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#261
post #50

So in response to this story I decided to delete my (premium) account with them. After confirming multiple times (good thing), I was shown this error: https://i.imgur.com/4dpn6d5.png How does error handling like this even make it to production? I got an email as well confirming my account deletion and I can no longer log in. But all in all this clearly does increase my trust in Lastpass's security competence.

I actually have a bone to pick with them too. I tried canceling my families accounts recently. Despite two confirmation emails I was still charged. Their site makes it very hard to find support.

Re: LastPass stores passwords so securely, not even its users can access them

#262

Not actually related to the article, but the headline makes me think of the "Muddy Puddle Test" for crypto, which goes like this: 1) Drop your device(s) into a muddy puddle (destroying them). 2) Slip in said puddle so you hit your head. On waking up you're absolutely fine, but are entirely incapable of remembering your passwords or encryption keys. 3) Can you get your cloud data back? If you can, then it's not actual…

What about biometrics?

Biometrics are good for usernames but not passwords. It's much harder for someone to get something out of your head than cutting off your thumb. - and as playeren says, it's impossible to change it.

http://news.bbc.co.uk/1/hi/world/asia-pacific/4396831.stm

Re: LastPass stores passwords so securely, not even its users can access them

#263
post #173

Earlier quoted context omitted.

Hi, I work for AgileBits, makers of 1Password. I can't comment on the defensive part, but text can often be harder to parse in conversation so perhaps it was that? I generally find our support team to be pretty understanding but I am sorry if our support team didn't properly handle your concerns and feedback. Feature parity is a tricky one. The Mac (and since it's shared code in a lot of ways, the iOS app) have been…

Kyle, for what it's worth as a counterpoint, I've grumbled a couple of times about bugs and the 1P team has not come across as defensive at all to me. Particularly after the nonsense support LastPass gives, it was a pleasant experience, even if my grumbles hold true. It's not a perfect product by any means but still light years better than LastPass in usability.

Hey, thanks!

We can't be the tool for everyone and we're always the first to recognize bugs exist. Unfortunately we also aren't able to fix them all just like I'm sure most people around here have backlogged bugs in the applications they work on. But we do try to prioritize based on severity and how many people are impacted.

I do appreciate the kind words though. We're not perfect, never will be, but we can sure try our best and I think that's all anyone really wants out of themselves.

If you ever run into issues feel free to reach out as well. Happy to help however I can!

Kyle

1Password Security Team

Re: LastPass stores passwords so securely, not even its users can access them

#264
post #144
post #36

Earlier quoted context omitted.

For Firefox there is https://addons.mozilla.org/en-US/firefox/addon/passff/ which I'm quite happy with. When combined with a yubikey set to decrypt only on touch this setup has a very low attack surface compared to other browser password managers.

This used to be my approach, but it prevented grepping through my password store (you have to touch the yubikey to decrypt each password separately) I since switched to a separate on-device key for "low value" passwords and keep the interesting stuff (e-mail pwds) under the yubikey protected key (which does requires touch). Did you find a better solution?

No. But i don't have an need for mass access so the basic case works fine for me. I keep a backup key on a separate yubikey that does not require touch for key maintenance.

Apparently there is a new "cached" option for the touch settings "Touch is cached for 15s after use (valid from 4.3)." Which would work for your use case but also neglect some/most? of the security advantages.

Re: LastPass stores passwords so securely, not even its users can access them

#265
post #49

I'm shocked to see a post of such low quality on hacker news. It reads like an instagram post or twitter replies. I'm not familiar with "theregister.co.uk" but I honestly think it's the lowest quality article I've ever seen on this website

> I'm not familiar with "theregister.co.uk" Then you're not qualified to be discussing software or the tech industry, frankly.

[deleted]

Re: LastPass stores passwords so securely, not even its users can access them

#266
post #49

I'm shocked to see a post of such low quality on hacker news. It reads like an instagram post or twitter replies. I'm not familiar with "theregister.co.uk" but I honestly think it's the lowest quality article I've ever seen on this website

> I'm not familiar with "theregister.co.uk" Then you're not qualified to be discussing software or the tech industry, frankly.

You seem toxic with this completely unnecessary gatekeeping attempt. I bet working with you is a joy. Let me put it to you this way, if your concept of competency in this industry is driven by knowledge of tabloids and not actually skill and talent in engineering, then I'm willing to bet you lack the latter two and rely on the former to fake it.
Post reply on HN