Has LastPass always been this bad and nobody noticed or did the new owners change it?
I Lost All Faith in LastPass
51–60 of 322 posts
Re: I Lost All Faith in LastPass
#52Earlier quoted context omitted.
There is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.
Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.
Re: I Lost All Faith in LastPass
#53Earlier quoted context omitted.
Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.
An appeal to authority is not a logical fallacy if the person in question is actually an authority in the domain .
Re: I Lost All Faith in LastPass
#54How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…
1. Bugs get missed all of the time in OSS. There is no guarantee that the more eyes the better, and in fact there may be a negative correlation due to the bystander effect [citation needed].
2. A software service is a complex interaction between many pieces of software. Two perfectly secure, audited pieces of software could interact in an exploitable way.
3. Just because the service provider tells you "this is the code, this is how we keep you secure, etc." doesn't mean it's true in practice. A bad actor could modify the code in production before the next version of "audited, trusted, OSS" is vetted.
4. Security practices outside of the code also matter (arguably more so), and even an organization with good policies can fail to follow them at times.
Ultimately, we're trusting the people behind the services we use to be honest and do their best. It seems that LastPass has demonstrated they aren't as deserving of that trust lately, but THE SAME THING COULD HAPPEN AT ANY ORGANIZATION.
Footnote: LP/1P could push an update that grabs everything necessary to decrypt your password vault the next time you log in.
Re: I Lost All Faith in LastPass
#55Earlier quoted context omitted.
There is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.
Which people? I've been very reluctant to use their cloud solution as I trust Dropbox more for security. So I still fight 1password to keep the vault stored in Dropbox. I figure there are maybe 4 organizations who are active enough to prevent a full download of all their user's data. Google, Dropbox, Amazon, and Facebook. (Maybe Apple, but they seem lethargic.) Because they store all the passwords to all of our servi…
Re: I Lost All Faith in LastPass
#56Earlier quoted context omitted.
Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.
Appeal to authority is not a fallacy, it's basically a necessity to function in the world.
Re: I Lost All Faith in LastPass
#57How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…
I don't buy the "if it's open source we can see/audit/trust the service" argument. 1. Bugs get missed all of the time in OSS. There is no guarantee that the more eyes the better, and in fact there may be a negative correlation due to the bystander effect [citation needed]. 2. A software service is a complex interaction between many pieces of software. Two perfectly secure, audited pieces of software could interact in…
Re: I Lost All Faith in LastPass
#58I know it's got a bit of security via obscurity vibes, but I've concluded the combo of residential IP, wireguard, firewall and dedicated VM is probably more secure. That would require someone with decent skill targeting me specifically...in which case they're probably better off with a wrench attack anyway.
The big unknown is uptime.
Re: I Lost All Faith in LastPass
#59Leaning strongly towards self-hosting. Name brand cloud managers just make too juicy a target for sophisticated attackers regardless of their competence/care of the pass manager co. I know it's got a bit of security via obscurity vibes, but I've concluded the combo of residential IP, wireguard, firewall and dedicated VM is probably more secure. That would require someone with decent skill targeting me specifically...…
NB: Not affiliated with the company, just a very happy customer.
Re: I Lost All Faith in LastPass
#60Use of 3rd party password trackers has been a periodic concern for our organization. We do B2B business with banks , so the temperature is increased somewhat. There are kinds of credentials we have access to that genuinely terrify me. I've been debating building an in-house solution for managing secrets, if for no other reason than to get all of this information off of 3rd party computers. No serious proposals have b…