Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

21–30 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#21

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

I don't see any mention of local vaults on the page. Is there any password manager out there besides keepass that isn't cloud based?

There’s also Enpass (https://www.enpass.io/) which markets itself as an offline password manager.

Re: What’s in a PR statement: LastPass breach explained

#22

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

This is a cool page. One thing that is important for me that is lacking here is emergency access (e.g. https://www.lastpass.com/features/emergency-access). It would be great to see side-by-side comparisons of that.

Re: What’s in a PR statement: LastPass breach explained

#23
post #13

The know it all tone of this article is kind of annoying. Security professionals seem to have a common trait of thinking they know better. Some good points in there, but limited pragmatism.

I disagree, this article did not come off this way to me, as all the comments were brief and backed up with supporting materials. In addition, the usage of words that would convey feelings the author had about the company were nonexistent — they described the actions taken (or not taken) by the company and left the reader to come to their own conclusions.

Re: What’s in a PR statement: LastPass breach explained

#24
post #20

For non-tech-savvy people - https://www.amazon.ca/Password-Book-Alphabetical-Colorful-Le... For tech-savvy people - https://www.passwordstore.org/ The rest doesn't work unfortunately, proven over and over.

Self-hosted instance of Bitwarden works pretty well, and you can make it accessible behind a VPN to your local network only (plus there are multiple implementations of its back-end). Less-automated solutions make impractical concessions in usability.

Reference impl. in C#: https://github.com/bitwarden/server

Self-host friendly impl. in Rust: https://github.com/dani-garcia/vaultwarden

p.s.: reference implementation is by far one of the better examples of how to do microservice-based C# solution of high code quality right.

Re: What’s in a PR statement: LastPass breach explained

#25
post #9

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

Bitwarden has a useful status page that you can subscribe to with RSS: https://status.bitwarden.com/ Would be happy to submit a PR, but I couldn't find a link to a repo and couldn't find the code on GitHub.

https://github.com/Soft-wa-re/password-manager-comparer

Re: What’s in a PR statement: LastPass breach explained

#26
post #13

The know it all tone of this article is kind of annoying. Security professionals seem to have a common trait of thinking they know better. Some good points in there, but limited pragmatism.

Given author's apparent history with LastPass, the tone comes across more as "told you so" to me.

Re: What’s in a PR statement: LastPass breach explained

#27
post #19
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

My wife and I have the password to our vaults in each others vaults, however I am not sure what would happen if both of us die.

Edit: as a site note, have used keepass + file on my (vpn reachable) synology for like 10 years, never had any issues. I use it in linux, android, ios and windows.

Re: What’s in a PR statement: LastPass breach explained

#28
post #13

The know it all tone of this article is kind of annoying. Security professionals seem to have a common trait of thinking they know better. Some good points in there, but limited pragmatism.

Disclaimer: I am the author of this article.

What kind of pragmatism would you prefer? LastPass messed up way more than they are willing to admit. And it’s not like nobody warned them before, quite a few of the issues which turn out to be very problematic now aren’t news – I brought them up years ago as did others. LastPass should be warning users now and suggesting mitigation steps, instead they claim that nobody has a reason to worry.

Re: What’s in a PR statement: LastPass breach explained

#29
post #19
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

Have to plan ahead and have the keypass password in an envelope in the safe deposit box.

Re: What’s in a PR statement: LastPass breach explained

#30

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

Great overview! I think 1Password's Linux support has been improving [0]. I use 1Password with an Ubuntu desktop and have been happy with it. [0]: https://support.1password.com/explore/linux/

You can submit a PR here.

https://github.com/Soft-wa-re/password-manager-comparer

Post reply on HN