Live data from Hacker News

Changes to LastPass Free

blog.lastpass.com

401–410 of 428 posts

Re: Changes to LastPass Free

#402
post #325

Earlier quoted context omitted.

Keepass is another cross-platform option (open source), though the UI on non-windows environments is a bit... crap. Nontheless, it works, and it works well.

Keepass and all is great. But it doesn't have first class support for anything but passwords. I'm sure many people will cringe when reading this, but I also save credit cards in my password manager and use it to auto fill when I need it. This unfortunately isn't supported by Keepass et al. It has templates, which are supported by some implementation but not others. Which also isn't great.

I store my CC numbers in KeePassXC even though there's no first class support. I put my full name as the username, the number as the password, and the expiration and CVV I put in the comments.

Re: Changes to LastPass Free

#403
post #325

Earlier quoted context omitted.

Keepass and all is great. But it doesn't have first class support for anything but passwords. I'm sure many people will cringe when reading this, but I also save credit cards in my password manager and use it to auto fill when I need it. This unfortunately isn't supported by Keepass et al. It has templates, which are supported by some implementation but not others. Which also isn't great.

I store my CC numbers in KeePassXC even though there's no first class support. I put my full name as the username, the number as the password, and the expiration and CVV I put in the comments.

This is what I keep reading, but when I tried that, auto fill didn't work for this.

Re: Changes to LastPass Free

#404

Earlier quoted context omitted.

Honestly, 90 digit password is only harder to type for you. It’s not more secure than only in theory when compared to, say, 20 digit password.

I choose to have the highest level of security I can afford, of course there are diminishing returns with each layer of security. Im happy to see evidence that a long password is only secure "in theory", until then I will keep my strategy. I can type 100WPM and this password is based off ~uncommon words, so I'm not uncomfortable: I didn't complain about entering, I claimed the issue is 1 wrong character requiring typ…

Well, considering the LastPass master password is stored as a 256bit string on the servers, your 90 character master password has 720 bits making it considerably more its that make up the hash thats stored on the servers! 1 ASCII character is 8 bits!

Re: Changes to LastPass Free

#405
post #140

Earlier quoted context omitted.

> Without a doubt the password manager with the best UX is 1Password. I doubt that. Navigating the sync options and finding one that works with Android phone, iPad and Windows PC was impossible. Throw in two vault formats (with implications for which sync option can work), and it's a mess. That was the paid standalone version, not the subscription model (that was when I finally jumped ship).

They had self hosted sync with the old vault format. They removed it when they switched to the new vault format. Dropbox always worked. Now they push their own service.

> Dropbox always worked.

No, it didn't. I don't remember the details, but the local sync (starting a sync server on the phone) did not work for me with a normal home network, and Dropbox didn't work across all devices, either.

Re: Changes to LastPass Free

#406

I've been wanting to move away from LastPass for a while now for different reasons - it feels very heavy and clunky. It's slow and the autofill can be glitchy. Does anyone have any recommendations from this perspective? 1password seems more Apple-oriented, but my devices are all Windows (chrome), and Android. There's lots of discussion here about "terrible UI," but I imagine none of these password managers are consis…

Hasn’t been mentioned elsewhere here but I can recommend MasterPassword anecdotally, which has a novel approach to cross-device password management.

Re: Changes to LastPass Free

#407

Earlier quoted context omitted.

I choose to have the highest level of security I can afford, of course there are diminishing returns with each layer of security. Im happy to see evidence that a long password is only secure "in theory", until then I will keep my strategy. I can type 100WPM and this password is based off ~uncommon words, so I'm not uncomfortable: I didn't complain about entering, I claimed the issue is 1 wrong character requiring typ…

Well, considering the LastPass master password is stored as a 256bit string on the servers, your 90 character master password has 720 bits making it considerably more its that make up the hash thats stored on the servers! 1 ASCII character is 8 bits!

You don't understand encryption. The master password is not "stored as a 256bit string on the servers".

Re: Changes to LastPass Free

#408

Earlier quoted context omitted.

Well, considering the LastPass master password is stored as a 256bit string on the servers, your 90 character master password has 720 bits making it considerably more its that make up the hash thats stored on the servers! 1 ASCII character is 8 bits!

You don't understand encryption. The master password is not "stored as a 256bit string on the servers".

Yeah it is!!

LastPass stores our master password hashes as a SHA-256 bit key.

All I was quipping at, was the fact that the password you enter in length is a whopping 720 bits!

I find it funny that this bit length gets reduced to a hash which is only 256 bits in length.

Your password has more entropy than the hash that gets produced from it.

Re: Changes to LastPass Free

#409
post #370

LastPass seem to be shooting themselves in the foot with their irrational and inconsistent pricing. - A few years back, their free/premium tiers were looking similar to what they announced today. Only they charged a mere $15/year for premium, which I gladly paid. - Then, overnight, they offered syncing across all types of devices for their free tier. The premium tier was only adding some niche features. I would have…

I bet they are counting on the lock-in factor. It might be worth it to just pay the fee rather than to go through the pain of switching.

Re: Changes to LastPass Free

#410
post #370

LastPass seem to be shooting themselves in the foot with their irrational and inconsistent pricing. - A few years back, their free/premium tiers were looking similar to what they announced today. Only they charged a mere $15/year for premium, which I gladly paid. - Then, overnight, they offered syncing across all types of devices for their free tier. The premium tier was only adding some niche features. I would have…

I bet they are counting on the lock-in factor. It might be worth it to just pay the fee rather than to go through the pain of switching.

Logins data on LastPass can be exported to 1Password, just not straightforward. I did that, not going back to LastPass anymore.
Post reply on HN