How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…
I Lost All Faith in LastPass
41–50 of 322 posts
Re: I Lost All Faith in LastPass
#42Just enable webauthn and forget the passwords non-sense
Re: I Lost All Faith in LastPass
#43Earlier quoted context omitted.
> As with most of us, that's a project of serious scope that I do not look forward to. I've spent the better part of the past three days doing just this. Get some good music and some good coffee, and it can actually be pretty cathartic. I enjoyed the hygiene exercise much more than I thought I would.
Some accounts I'm just deep sixing by changing the password with the online service but then not recording it anywhere. Buhbyeeeee!
Also it's been a fascinating exercise in user-interface/-experience competitive research. Some websites just do not give a crap. Here's one gem: https://i.imgur.com/yBLmuHt.png
I can't help but feel pity for the local/city-level websites though. You can tell they've just Frankenstein-d stuff together on meager budgets and under crippling administrative loads.
Re: I Lost All Faith in LastPass
#44Earlier quoted context omitted.
There is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.
Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.
Re: I Lost All Faith in LastPass
#45Earlier quoted context omitted.
There is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.
Which people? I've been very reluctant to use their cloud solution as I trust Dropbox more for security. So I still fight 1password to keep the vault stored in Dropbox. I figure there are maybe 4 organizations who are active enough to prevent a full download of all their user's data. Google, Dropbox, Amazon, and Facebook. (Maybe Apple, but they seem lethargic.) Because they store all the passwords to all of our servi…
Re: I Lost All Faith in LastPass
#46What are the security problems with garbage-collected languages?
(not being sarcastic, don't have an agenda, I have no previous knowledge on this, and am not a security expert. Just had never heard this suggested before, and am curious what he meant. Legit question!)
Re: I Lost All Faith in LastPass
#47I’ve shrugged off a lot of strangeness that has been happening with them as a fledging company’s growing pains. Unfortunately, this incident is the final straw. I think we are going to see a lot more come to light and their lack of any sort of transparency on this is a cardinal sin in the Infosec world. As an aside, it’s interesting to see their fall from grace from their reception section on Wikipedia: https://en.m.wikipedia.org/wiki/LastPass#Reception
I’m moving to bitwarden and not looking back. I would be interested to see some people write about this transition as I’m not sure if I want to export/import or start anew and move things manually.
Re: I Lost All Faith in LastPass
#48Re: I Lost All Faith in LastPass
#49How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…
Personally, I stick to Open Source solutions (KeepassXC), but I don't typically recommend other people use KeePass unless they're technically inclined -- because the biggest risk with a password manager in my opinion is user error, and so I want to focus on that even if it means that someone isn't using an Open Source program.
All that to say, that this line:
> Granted, if I had to chose today, I would instantly pick 1Password
is a pretty good summation of the situation. I do think 1Password is a lot likely to be a lot more secure than LastPass, but even if I wasn't confident about that, the situation many users are in is:
- they should be using a password manager, so they do need one today
- an online password manager is a better fit for most users than an offline solution
- 1Password is (I think) slightly easier to use than Bitwarden and is more often recommended by security professionals.
----
But Bitwarden would still be a fine choice for people who want to use something Open Source, and offline solutions are great for people who feel comfortable with them (I keep my password manager offline because I have the technical skills to do so, so I like the added boost of security from my vault not sitting open on a server someplace). But the important thing is that they use a password manager in the first place, since using actually secure unique passwords across every site is basically impossible for most people without one. It's not so much that I assume 1Password is perfect, I just think it's the best choice for a lot of people right now based on the information we have. I'm not going to recommend KeePassXC to my parents, it's important to me that their solution be online and managed by a professional.
A lot of security is about making the best choice available based on imperfect information and based on individual context.
I used to recommend LastPass to people who I knew weren't willing to pay money, because (again) I wanted them to be using a password manager no matter what, and if they weren't willing to pay for 1Password, they might as well use something free. But even that advantage kind of dried up a little bit, LastPass has gotten a lot less generous about what they offer for free.