Live data from Hacker News

I Lost All Faith in LastPass

infosec.exchange

41–50 of 322 posts

Re: I Lost All Faith in LastPass

#41

How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…

[deleted]

Re: I Lost All Faith in LastPass

#43
post #32

Earlier quoted context omitted.

> As with most of us, that's a project of serious scope that I do not look forward to. I've spent the better part of the past three days doing just this. Get some good music and some good coffee, and it can actually be pretty cathartic. I enjoyed the hygiene exercise much more than I thought I would.

Some accounts I'm just deep sixing by changing the password with the online service but then not recording it anywhere. Buhbyeeeee!

Yes! I too have had many sites fall into that category.

Also it's been a fascinating exercise in user-interface/-experience competitive research. Some websites just do not give a crap. Here's one gem: https://i.imgur.com/yBLmuHt.png

I can't help but feel pity for the local/city-level websites though. You can tell they've just Frankenstein-d stuff together on meager budgets and under crippling administrative loads.

Re: I Lost All Faith in LastPass

#44

Earlier quoted context omitted.

There is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.

Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.

An appeal to authority is not a logical fallacy if the person in question is actually an authority in the domain.

Re: I Lost All Faith in LastPass

#45
post #30

Earlier quoted context omitted.

There is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.

Which people? I've been very reluctant to use their cloud solution as I trust Dropbox more for security. So I still fight 1password to keep the vault stored in Dropbox. I figure there are maybe 4 organizations who are active enough to prevent a full download of all their user's data. Google, Dropbox, Amazon, and Facebook. (Maybe Apple, but they seem lethargic.) Because they store all the passwords to all of our servi…

My company forced us to use Box and actively blocks Dropbox on all work computers. They did an audit and didn’t like what they saw in Dropbox.

Re: I Lost All Faith in LastPass

#46
> I'm less thrilled about it being written in a garbage collected language

What are the security problems with garbage-collected languages?

(not being sarcastic, don't have an agenda, I have no previous knowledge on this, and am not a security expert. Just had never heard this suggested before, and am curious what he meant. Legit question!)

Re: I Lost All Faith in LastPass

#47
I have been a LastPass customer for over 10 years and I think this January when my yearly subscription ends, I will finally not renewing.

I’ve shrugged off a lot of strangeness that has been happening with them as a fledging company’s growing pains. Unfortunately, this incident is the final straw. I think we are going to see a lot more come to light and their lack of any sort of transparency on this is a cardinal sin in the Infosec world. As an aside, it’s interesting to see their fall from grace from their reception section on Wikipedia: https://en.m.wikipedia.org/wiki/LastPass#Reception

I’m moving to bitwarden and not looking back. I would be interested to see some people write about this transition as I’m not sure if I want to export/import or start anew and move things manually.

Re: I Lost All Faith in LastPass

#48
Reading through these comments I am surprised at how many people were/are still using LsstPass. I used it until they had an incident 5 or 7 years ago. And there face need others since. How many chances did an organization get with highly sensitive information before people move on?

Re: I Lost All Faith in LastPass

#49

How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…

Important piece of context here: if LastPass was the only password manager on the market, that's what I would recommend people use, even after the breach. Having a password manager is a big boost in security even if that manager is LastPass.

Personally, I stick to Open Source solutions (KeepassXC), but I don't typically recommend other people use KeePass unless they're technically inclined -- because the biggest risk with a password manager in my opinion is user error, and so I want to focus on that even if it means that someone isn't using an Open Source program.

All that to say, that this line:

> Granted, if I had to chose today, I would instantly pick 1Password

is a pretty good summation of the situation. I do think 1Password is a lot likely to be a lot more secure than LastPass, but even if I wasn't confident about that, the situation many users are in is:

- they should be using a password manager, so they do need one today

- an online password manager is a better fit for most users than an offline solution

- 1Password is (I think) slightly easier to use than Bitwarden and is more often recommended by security professionals.

----

But Bitwarden would still be a fine choice for people who want to use something Open Source, and offline solutions are great for people who feel comfortable with them (I keep my password manager offline because I have the technical skills to do so, so I like the added boost of security from my vault not sitting open on a server someplace). But the important thing is that they use a password manager in the first place, since using actually secure unique passwords across every site is basically impossible for most people without one. It's not so much that I assume 1Password is perfect, I just think it's the best choice for a lot of people right now based on the information we have. I'm not going to recommend KeePassXC to my parents, it's important to me that their solution be online and managed by a professional.

A lot of security is about making the best choice available based on imperfect information and based on individual context.

I used to recommend LastPass to people who I knew weren't willing to pay money, because (again) I wanted them to be using a password manager no matter what, and if they weren't willing to pay for 1Password, they might as well use something free. But even that advantage kind of dried up a little bit, LastPass has gotten a lot less generous about what they offer for free.

Re: I Lost All Faith in LastPass

#50
I feel like a shill at this point but just use Bitwarden. open source, cloud sync by default, alternative self-hostable backend if you want to, no device limit, doesn't cost anything which is just about the only thing that concerns me because the free plan seems too good honestly.
Post reply on HN