Live data from Hacker News

Even the LastPass will be stolen, deal with it (2015) [pdf]

blackhat.com

11–20 of 23 posts

Re: Even the LastPass will be stolen, deal with it (2015) [pdf]

#11
post #9

Does anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.

People have been dunking on LastPass for a very long time. I haven't seen the same infosec people do the same with 1Password and Bitwarden. The constant criticism was a bit push to finally get me to move to 1P. The one good thing about LastPass was basically how easy it was to set up. Everything else was a bit of a mess. 1Password was tricky to set up, and they took a bit longer to launch a cloud service. One thing t…

> People have been dunking on LastPass for a very long time. I haven't seen the same infosec people do the same with 1Password and Bitwarden.

This is my impression as well. What I wonder is whether this is because they haven't tried to find these issues with the other products, or they just failed to find them so nothing ever got published, or if it did no one noticed it. I find the latter hard to believe as I suspect marketing departments would have been all over it.

That said, to me LastPass was always terrible. Back in the day I moved from KeePass to LP for the browser integration but everything was so buggy and unreliable that eventually I moved away.

1Password was better but the cloud service brings some of the same worries as LastPass.

Re: Even the LastPass will be stolen, deal with it (2015) [pdf]

#12

Does anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.

I still use KeePass, albeit with a ridiculously high iteration count to protect against brute-forcing. It's completely client-side, so no cloud involved and nobody to blame other than you if your vault gets into the wrong hands ;-) Although personally, I use OneDrive to sync it across devices

Yeah, that's what I used to do as well - although I used Dropbox and later iCloud for syncing.

Browser integration, less than great iOS clients and other quality-of-life features eventually made me find an alternative.

I might look into it again.

Re: Even the LastPass will be stolen, deal with it (2015) [pdf]

#13

Does anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.

LastPass is a standout candidate for worst password manager, as has been the case for many years. The other popular password managers, like 1Password and Bitwarden, are certainly not perfect but they're leagues ahead of LastPass.

1Password, for example, has written extensively about their security model and have done so proactively, including a lengthy whitepaper: https://1passwordstatic.com/files/security/1password-white-p...

LastPass is garbage because it's LastPass, not because it's a password manager. The only thing LastPass has ever done well is somehow remain relevant despite being terrible: that's an achievement.

Re: Even the LastPass will be stolen, deal with it (2015) [pdf]

#14
post #9

Earlier quoted context omitted.

People have been dunking on LastPass for a very long time. I haven't seen the same infosec people do the same with 1Password and Bitwarden. The constant criticism was a bit push to finally get me to move to 1P. The one good thing about LastPass was basically how easy it was to set up. Everything else was a bit of a mess. 1Password was tricky to set up, and they took a bit longer to launch a cloud service. One thing t…

> People have been dunking on LastPass for a very long time. I haven't seen the same infosec people do the same with 1Password and Bitwarden. This is my impression as well. What I wonder is whether this is because they haven't tried to find these issues with the other products, or they just failed to find them so nothing ever got published, or if it did no one noticed it. I find the latter hard to believe as I suspec…

[deleted]

Re: Even the LastPass will be stolen, deal with it (2015) [pdf]

#15

Earlier quoted context omitted.

I still use KeePass, albeit with a ridiculously high iteration count to protect against brute-forcing. It's completely client-side, so no cloud involved and nobody to blame other than you if your vault gets into the wrong hands ;-) Although personally, I use OneDrive to sync it across devices

Yeah, that's what I used to do as well - although I used Dropbox and later iCloud for syncing. Browser integration, less than great iOS clients and other quality-of-life features eventually made me find an alternative. I might look into it again.

keepassium for ios is good now.

Re: Even the LastPass will be stolen, deal with it (2015) [pdf]

#16

Does anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.

I still use KeePass, albeit with a ridiculously high iteration count to protect against brute-forcing. It's completely client-side, so no cloud involved and nobody to blame other than you if your vault gets into the wrong hands ;-) Although personally, I use OneDrive to sync it across devices

Keepass, and manual copying to my pfhone along with the keyfile. 100% security on me, myself and I.

Re: Even the LastPass will be stolen, deal with it (2015) [pdf]

#17

Video of the actual talk: https://www.youtube.com/watch?v=MlmEiT5bhxg Aside: I never really understood distributing just slides from a talk. Any good talk most of the information isn’t in the slides.

There are a lot of talks that aren't good. (Not in any way saying this is one of them.)

Re: Even the LastPass will be stolen, deal with it (2015) [pdf]

#18

Does anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.

LastPass is a standout candidate for worst password manager, as has been the case for many years. The other popular password managers, like 1Password and Bitwarden, are certainly not perfect but they're leagues ahead of LastPass. 1Password, for example, has written extensively about their security model and have done so proactively, including a lengthy whitepaper: https://1passwordstatic.com/files/security/1password-…

i’d just like to say thank you for linking to that white paper. really a fascinating read, and nicely written.

i’m a long-time 1password user and absolutely love it. sure, it involves placing some degree of trust with AgileBits, but for the incredible level of practicality it offers, i view it as a decent trade-off. reading that paper now also makes me a great deal more confident in their security standards.

Re: Even the LastPass will be stolen, deal with it (2015) [pdf]

#19

Does anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.

Google/Chrome is probably the most secure password manager. They have the greatest incentives to keep it secure along with the largest bug bounties and number of people attacking it.

Re: Even the LastPass will be stolen, deal with it (2015) [pdf]

#20

Earlier quoted context omitted.

Yeah, that's what I used to do as well - although I used Dropbox and later iCloud for syncing. Browser integration, less than great iOS clients and other quality-of-life features eventually made me find an alternative. I might look into it again.

keepassium for ios is good now.

Thanks, I'll check it out.
Post reply on HN