https://www.lastpass.com/delete
Whoever is implementing these changes, shame on you.
edit: this one works: https://lastpass.com/delete_account.php Let's see whether they remove it or not.
81–90 of 210 posts
https://www.lastpass.com/delete
Whoever is implementing these changes, shame on you.
edit: this one works: https://lastpass.com/delete_account.php Let's see whether they remove it or not.
After reaching out to support with screenshots, they fixed the issue and I gained full access, but it is clear to me that Lastpass uses 'display: none' as feature gating and that their software is absolute garbage.
This was 100% intentional on Lastpass' side
In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…
The average person, when not allowed to use a convenient password manager, will either use the same password for every site or come up with a predictable pattern. Encouraging a password manager helps make sure they don't get destroyed completely when a blog they signed up on 5 years ago is hacked. This is partly because so many things want an account now. I have over 500 passwords saved, it would be straight up impos…
Earlier quoted context omitted.
The average person, when not allowed to use a convenient password manager, will either use the same password for every site or come up with a predictable pattern. Encouraging a password manager helps make sure they don't get destroyed completely when a blog they signed up on 5 years ago is hacked. This is partly because so many things want an account now. I have over 500 passwords saved, it would be straight up impos…
> This is partly because so many things want an account now. I have over 500 passwords saved, it would be straight up impossible to remember unique strings for each site. How many of those accounts are essential? I create throw-away accounts on the regular. There are many accounts, but few that really matter. For the ones that matter I take care to make sure I have the passwords. For the rest, who cares :)
Earlier quoted context omitted.
Well, what's the alternative besides a local keepass DB or something?
A local keepass is a great alternative, been doing that for ages and honestly copying my keepass db to a device every once in a while is way less troublesome than quadruple factoring into lastpass/1password or whatever.
What’s the difference, security wise, to an all in one offering that works the same way under the hood, like 1password cloud or bitwarden?
It seems to me that those syncing keepass databases around are just incurring pain without any real increase in security.
Earlier quoted context omitted.
If one site gets breached/exposed, your memorized username/password combination used all across the internet is now immediately available to the bad actors and you might not even know or remember everywhere it was used. Having a unique password for each site is the main advantage of a password manager to mitigate the damage in this case (to just the 1 site that was breached). Talking about your vault/passwords and "s…
I don't think that having a unique password per site is unachievable. I do it and I don't use a PW manager. Even something as simple as prepending the site name in ROT13 to a reused password greatly reduces your exposure to the sort of background infosec threat radiation that's like 99.99% of the threat model for most people
Is LastPass one of those password managers that only encrypt passwords and leave other data as is? I always cringe when password managers do that. This is a funny joke for anyone who understands even a little about cryptography.
I think both no longer do, but the fact that they once did was very surprising to me.
[1]: https://1password.community/discussion/12237/metadata-is-not...
So I've been happily using LastPass for a long time, but it looks like it's time to migrate off this dumpster fire. What's the HN consensus on the best replacement (which must be usable by my entire family) and, at least as importantly, is there a reasonably painless migration path?