Live data from Hacker News

Changes to LastPass Free

blog.lastpass.com

331–340 of 428 posts

Re: Changes to LastPass Free

#331

This is a feature not a productTM. I switched to using safari’s password sync across mobile and desktop. It only works on iPhones and macOS desktop safari, but I adjusted my workflow. It’s both free, and reliable as long as Apple supports it. But I trust Apple to exist or migrate better than a dedicated product company like lastpass. Both for a decent user workflow and for not being breached (much scarier to me). I k…

Quoted post unavailable.

They’re accessible outside of a browser, via a “keychain”, and the entire OS is built to use this keychain, which also syncs appropriately among your devices.

On iOS, it’s Settings > Passwords. On MacOS, it’s Keychain Access, which looks like this:

https://support.apple.com/guide/keychain-access/welcome/mac

There is also a UI in Safari itself, which on MacOS has added some advisory features, including easily guessed, seen in a data leak, or used on multiple sites:

https://support.apple.com/en-sg/guide/safari/sfri40599/mac

On MacOS, you can also use the keychain with ssh on the command line:

https://rderik.com/blog/understanding-ssh-keys-and-using-key...

Re: Changes to LastPass Free

#332
post #61

LastPass costs $36 per year. Operating on the principle of being the customer and not the product, that seems very reasonable for a secure way to store and share the keys to my digital life. That said, it does make it a little bit harder for me to onboard my friends and family when they ask. One of the selling points has always been "Yes, you can use it on your phone and laptop" and "no, it doesn't cost anything".

KeePass database stored in Dropbox is free.

Interestingly this is basically how 1Password did password sync for years - not a Keepass database, but a 1Password folder structure stored within Dropbox saving a bunch of little text files. They added other synced storage options over time before turning up their own cloud service, but third party sync was where they started.

Re: Changes to LastPass Free

#333

Earlier quoted context omitted.

I was not clear. This is the password for the password manager (e.g. 1Password/ lastpass master password). The password to rule them all. It should be extra secure. I also have 2FA, but you must have heard of defense in depth. Anyway, I want to be able to see the password and check for typos before entering it to unlock the vault. I don't want to retype the whole password in when I only mistyped 1 character. When I s…

Honestly, 90 digit password is only harder to type for you. It’s not more secure than only in theory when compared to, say, 20 digit password.

I choose to have the highest level of security I can afford, of course there are diminishing returns with each layer of security. Im happy to see evidence that a long password is only secure "in theory", until then I will keep my strategy. I can type 100WPM and this password is based off ~uncommon words, so I'm not uncomfortable: I didn't complain about entering, I claimed the issue is 1 wrong character requiring typing the whole thing password. It only takes a few seconds, but it is frustrating to type the whole thing again (regardless of length).

https://xkcd.com/936/

Re: Changes to LastPass Free

#334
Anyone considering pass (https://www.passwordstore.org/)? It is written in bash and uses gpg to store credetials on disk. And it is developed by the same guy behind wireguard. Also completely FOSS. On iOS I use passforios (https://github.com/mssun/passforios) and on macOS I am the developer of Pass for macOS (https://github.com/adur1990/Pass-for-macOS) which is a wrapoer for pass containing a Safari extension. Sync across devices is done using git (or cloud drives if you prefer). I use this setup for multiple years now and it works really well.

Re: Changes to LastPass Free

#335
post #325

Earlier quoted context omitted.

Keepass is another cross-platform option (open source), though the UI on non-windows environments is a bit... crap. Nontheless, it works, and it works well.

Keepass and all is great. But it doesn't have first class support for anything but passwords. I'm sure many people will cringe when reading this, but I also save credit cards in my password manager and use it to auto fill when I need it. This unfortunately isn't supported by Keepass et al. It has templates, which are supported by some implementation but not others. Which also isn't great.

> I'm sure many people will cringe when reading this, but I also save credit cards in my password manager

Why would anyone cringe to read that? They're no more valuable than passwords. In fact, I would think they're less valuable, since really the CC company is on the hook if a number gets stolen.

Re: Changes to LastPass Free

#336
post #272

Earlier quoted context omitted.

I have kept my PC version of database as master. All of my tablets mobiles access it in read only basis. This is to avoid the sync conflicts.

So you voluntarily prevent yourself from updating passwords when you’re on your phone or tablet just so that your password manager doesn’t lose data? Isn’t that a ridiculous design oversight? To completely handicap any situation involving more than one computer? That’s exactly why I stopped using Keepass. All that hassle so that you can save $10 a year. https://bitwarden.com/pricing/

My use case is different. My all passwords are in Chrome. Simple. Keypass has some specific passwords like Chrome Sync Phrase, some zip file passwords, some other things. Plus initially I used to use keypass when i started using any password management instead of same password everywhere.

At that time, & still now, I use Dropbox to sync PC KP db with Dropbox. Then FolderSync to sync one way (read only) from Dropbox to Phone. If i need to add password, I wanted to make sure I can add only on PC. PC had the official Keypass, phones had the Offline Keypass App.

$10 now is nothing for me, but few years ago in India it is about 2 days salary of a manual laborour. About 5 meals. Or about 10 litres of Petrol.

I am always wary of anything online which has my passwords. The same reason Chrome does not have all my passwords, but still I trust Google more than any other relatively smaller software like Lastpass or bit warden or anything.

Re: Changes to LastPass Free

#337
I used to be a payed subscriber, and then they made all the features I used free. For some reason, it frustrated me that they made it free, because I felt they were now gunning for some monetization scheme, where I'd rather they just focused on an affordable sustainable offering.

Re: Changes to LastPass Free

#338

Earlier quoted context omitted.

A year from now: "Suddenly I understand why individual consumer choices are not the basis for maintaining a balanced economic system."

Conglomerates that do B2C for money will always beat upstarts as their customer unit average cost will be lower and per unit attributable revenue will be higher. If the only thing that a customer cares about is paying the minimum amount, the customer should not be surprised that their choices would be limited to conglomerates. Independent restaurants are a lot more expensive than national chains and make a lot less m…

Fine but that’s not the parent’s point. You shouldn’t buy from local stores, local restaurants, or small shops because of some notion that you’re sticking it to large companies. You do when, for you, their products and services they offer have better value for you.

If you choose a worse or more expensive product because it’s from a small business then you’re only making yourself worse off.

Re: Changes to LastPass Free

#339

LastPass costs $36 per year. Operating on the principle of being the customer and not the product, that seems very reasonable for a secure way to store and share the keys to my digital life. That said, it does make it a little bit harder for me to onboard my friends and family when they ask. One of the selling points has always been "Yes, you can use it on your phone and laptop" and "no, it doesn't cost anything".

It's ridiculously overpriced for what essentially amounts to storing a tiny binary blob on a server somewhere and making sure it's backed up. I would've been happy to continue paying 12 USD / year for that service, but at triple the cost? I'm now on BitWarden.

I mean the value prop is the software functionality, not the storage. You think lastpass/1password are funding their development with a markup on storage?

I can get the argument that it’s not worth $36 but not because of storage costs.

Post reply on HN