I've been debating building an in-house solution for managing secrets, if for no other reason than to get all of this information off of 3rd party computers. No serious proposals have been put forth, but I don't think this stuff is exactly rocket science either. Our requirements are functionally-equivalent to a copy of passwords.xlsx on a network share.
I Lost All Faith in LastPass
31–40 of 322 posts
Re: I Lost All Faith in LastPass
#32After reading this, I acted on a decision I was on the fence about. I already have moved to Bitwarden and like it a lot better, but this post prompted me to go into LastPass and actively delete my account. The next thing to do will be to start changing passwords. As with most of us, that's a project of serious scope that I do not look forward to.
> As with most of us, that's a project of serious scope that I do not look forward to. I've spent the better part of the past three days doing just this. Get some good music and some good coffee, and it can actually be pretty cathartic. I enjoyed the hygiene exercise much more than I thought I would.
Re: I Lost All Faith in LastPass
#33God damnit, but what doesn't. I am sure BitWarden has its own problems and it (seems?) not 100% FOSS but its core is. LP extension and web vault ARE pure garbage: 1. It can't even recognize sites correctly ?! WTF really. I usually get 10 or so (looks like random) hits for any site but not the one that I should. 2. It offers me to extend pro support 5 years after I stopped paying for it. What I need to do for it to st…
The UIX of Bitwarden can be a bit meh at times but it's also boring, predictable, and solid. I'm just saying this as someone who hates save buttons in the upper-right hand corner of things - just... small nitpicky stuff like that. Sometimes I have to look for a button or their use of iconography confuses me a bit.
I would do my own hosting for a distributed password database but the older I get the less I trust myself to keep that stuff locked down and patched. Given the number of users I feel Bitwarden has more skin in the game to keep their solutions tight.
If you're not looking to self-host I can't recommend Bitwarden enough!
Re: I Lost All Faith in LastPass
#34Has LastPass always been this bad and nobody noticed or did the new owners change it?
Yes. But prior to this breach it was easy to look the other way due to the extremely large amount of inertia associated with changing a manager and all your passwords. I know this was the case for me. In August we thought it was simply another "simple" breach. E.g. they got hold of some information that would be useful to spearphish or whatever but not the vaults themselves. No big deal, just be on the lookout for em…
https://www.wired.com/story/the-full-story-of-the-stunning-r...
Re: I Lost All Faith in LastPass
#35Earlier quoted context omitted.
Still doesn't explain why it's all not at least source-available. I'm not going to complain if they don't use open-source licenses such as MIT or (A)GPL, but straight up not making the source code publicly readable at all is a big strike against it.
There is good insight into this from this comment from them in 2014: https://1password.community/discussion/comment/114870/#Comme...
I see no reason not to do this, especially for such a security-oriented service. You should be striving for as much transparency as possible.
Re: I Lost All Faith in LastPass
#36How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…
There is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.
Source for this?
To me, the celebrity endorsement makes me doubt it's a serious business.
Re: I Lost All Faith in LastPass
#37After reading this, I acted on a decision I was on the fence about. I already have moved to Bitwarden and like it a lot better, but this post prompted me to go into LastPass and actively delete my account. The next thing to do will be to start changing passwords. As with most of us, that's a project of serious scope that I do not look forward to.
My workflow is to launch the login from LP (using the app), use those credentials, and change the passwords using Bitwarden. Otherwise, you might accidentally set a new password that doesn't actually work and have to go through painful password reset processes.
Re: I Lost All Faith in LastPass
#38Re: I Lost All Faith in LastPass
#39I then stopped using my account on LastPass and literally a few weeks later they revealed the "security incident". Had to change all my passwords but I'll never get near this company ever again.
Re: I Lost All Faith in LastPass
#40Just enable webauthn and forget the passwords non-sense