Live data from Hacker News

Changes to LastPass Free

blog.lastpass.com

141–150 of 428 posts

Re: Changes to LastPass Free

#141

LastPass costs $36 per year. Operating on the principle of being the customer and not the product, that seems very reasonable for a secure way to store and share the keys to my digital life. That said, it does make it a little bit harder for me to onboard my friends and family when they ask. One of the selling points has always been "Yes, you can use it on your phone and laptop" and "no, it doesn't cost anything".

I agree with other comments that in the current market, Lastpass is not worth it at $36/y. The way they increased the price is arguably more annoying than the price tag. I happily paid for Lastpass at $12/y. Logmein raised price and I switched to free. Logmein limited free capabilities and I will switch to Bitwarden or 1Password and pay them. I'm not staying with Lastpass to get the rug pulled out under me the third…

I switched to Bitwarden in early 2019. The migration was really easy, and I was surprised to find that it was accurate, too. Bitwarden has its flaws, but I'm happy with it.

Re: Changes to LastPass Free

#142

LastPass is making a huge change to their Free product and giving users only a month to adjust. This is irresponsible at best. I completely empathize with the notion that good software is worth paying for, but a widely-used password manager needs to provide more time for users to transition into another product if they choose not to convert to paid.

> This is irresponsible at best. Not sure i agree, they make it very easy to export your info/passwords and are just returning to a previous business model. As another user here commented, it only took 15 min to switch to another option. > but a widely-used password manager needs to provide more time for users to transition into another product if they choose not to convert to paid curious how much time that would be

I'm sure some users will find an alternative solution and switch easily. I'm also sure that some users will not. My assumption - take it or leave it - is that the folks who would find this more inconvenient are those who were introduced to LastPass by more security-minded friend or family member. They aren't necessarily inclined or well-equipped to transition their devices over from one password manager to another. This may cause them to abandon password management altogether or do something dangerous like temporarily store their passwords in plain text while they find someone to help them transition to another product.

Re: Changes to LastPass Free

#143

Recently switched to 1Password from LastPass and I love it. The autofill is much better.

5 or 6 years ago I was talking to coworker about password managers, and they told me how much they liked 1Password. I decided to give it a shot, and after a week or so decided to switch permanently and delete my LastPass account.

When I told them that I had made the switch, they laughed told me they had done the same: they tried LastPass and decided to delete their 1Password account!

Personal preference is funny like that.

Re: Changes to LastPass Free

#144
People seem to be very positive about Bitwarden. I've been using Lockwise from Mozilla. Any thoughts about it?

I've been using it for a few months to sync between Win, Mac and iOS and it has been working pretty nicely.

Re: Changes to LastPass Free

#145
I think the issue with lastpass is its popularity, which would make it a target for hackers. If someone brute forces your password, then they've got access to everything

Are there any less popular but well featured password managers, or any roll your own solutions that wouldn't be so easily targeted

Re: Changes to LastPass Free

#146

The title is slightly off. The limit is to a single device type, not device. If you only use LastPass on 2 devices of the same type (on your desktop and your laptop or if you only use it on your Mobile and your Tablet) you will be fine to stay on Free, However if you use it on your Desktop and your Mobile (like me) you will need to swap password managers or pay up for the service. Before LogMeIn brought them the serv…

I've been using KeePassXC for a few years now. Before this, I was using LastPass and then before that, the original KeePass. Feature-wise, KeePassXC does a really good job replacing and going beyond LastPass.

It can have folders, it generates passwords, it can hold TOTP (2FA) tokens and it can even hold SSH keys acting as your SSH agent. Having your password safe be an SSH agent is a really nice feature which means less copying passwords around. The browser plug-ins have worked well for me as well.

I like that it can use any file sync tool for storing the key database - similar to why I like Joplin for note taking. I also like that there are many different clients for it since it is an open standard. To keep things secure you can use a password plus a key file. As long as you keep the keyfile only on the devices or on separate sync services, it raises the bar of security quite a lot.

There are KeePass clients on Andriod (Keepass2Android and KeePassDX) as well as iOS (Keepassium and another that I forgot the name of). All of the mobile clients support filling passwords. I have them all looking at the same file share and have not had any issues with corruption or file sync. I have it configured to immediately save all changes to disk and it writes and merges conflict files automatically as needed.

There are a few areas that it isn't as strong. First is sharing passwords - it has a feature for it but I haven't actually tried it out yet. Since you need to have the shared file ahead of time, you're really relying on your file sync provider to share that part of things. Second, the integration between programs works well but it isn't as seamless as a cloud service would be. For example, prompts will pop up in KeePassXC when there is a request to access a new password by a website. I believe this is probably more secure but it is an extra thing to come up when auto-filling passwords.

I have yet to try bitwarden but I would guess that sharing and lower-friction in web browsers would work better with it since those were the key benefits of LastPass when I'd used it.

Re: Changes to LastPass Free

#147

Terminal gurus might like what I've been working on lately: https://github.com/timvisee/prs Free and open-source, keep control in your own hands, forever. Encryption with gpg, sync with git. Compatible with pass, which means better support and easy migration.

How does this differ from pass? At first look it appears to be pretty much the same?

Re: Changes to LastPass Free

#148
post #23

LastPass is making a huge change to their Free product and giving users only a month to adjust. This is irresponsible at best. I completely empathize with the notion that good software is worth paying for, but a widely-used password manager needs to provide more time for users to transition into another product if they choose not to convert to paid.

Caveat Emptor.

The emptor's counterpart, the venditor, also has a responsibility. I wouldn't dream of offering a free product that handles one of the most important aspects of consumer data security and then drastically altering it with only four weeks' notice. Many were introduced to LastPass, probably reluctantly, by more security-literate friends and family. These are the folks most likely to be squeezed in this very short transition period because they won't necessarily know how to navigate to a different product and would probably be more likely to do something risky in response.

Re: Changes to LastPass Free

#149

Earlier quoted context omitted.

FYI Bitwarden is only $10 a year. Before Bitwarden I used a combination of Keepass and Google Drive to sync all my passwords between devices. That was a workable solution, but Bitwarden is certainly easier, and I think more polished too.

To me, the unbeatable feature of Keepass is the fact that I'm not limited to user/password combination. I use it to store important notes and even files.

last pass also has secure notes

Re: Changes to LastPass Free

#150

I've been on 1Password since 2007. Unfortunately, software quality seems to have taken a nosedive since version 7 came out (disregarding the subscription issue). Random beachballs and slowdowns, annoying 2FA and duplicate password warnings, and decoupling of stored files from login entries. I have been considering a replacement but haven't found anything up to the ease of use and Mac/iOS integration of 1Password yet.

I tried 1Password, but there was a basic missing feature, you can't toggle reading the password. This was a deal breaker for me when I have a ~90 character password (I often mistype one specific key everytime). Bitwarden doesn't have this problem.

Why would you type a 90 character password instead of copy / paste or have the manager fill it in?

Also why 90 characters when 2FA would be the safer option? Or half that is already infeasibly long to brute force?

Also what do you mean 'reading the password', like via a screen reader? I mean that would be pretty bad for accessibility, but if you mean displaying the password, my version has buttons for it (regular inline, and a popup with the password pasted large on the screen).

I have so many questions.

Post reply on HN