Live data from Hacker News

I Lost All Faith in LastPass

infosec.exchange

71–80 of 322 posts

Re: I Lost All Faith in LastPass

#72
post #58

Leaning strongly towards self-hosting. Name brand cloud managers just make too juicy a target for sophisticated attackers regardless of their competence/care of the pass manager co. I know it's got a bit of security via obscurity vibes, but I've concluded the combo of residential IP, wireguard, firewall and dedicated VM is probably more secure. That would require someone with decent skill targeting me specifically...…

Keepass and use dropbox or onedrive to sync. There’s no uptime issue there.

Re: I Lost All Faith in LastPass

#73

Earlier quoted context omitted.

Most people don't read open source and instead trust that the experts will catch any issues....

It's turtles all the way down. Would you rather NOT have the option for other experts to see the code?

Of course not, I'd rather the code be Open and audited.

Being Open Source is in some ways a multiplier on security because it allows more expert review. But the expert review is the important part; if security-critical code is Open Source but hasn't been looked at by anyone other than the main developers, the Open Source part is a multiplier on zero.

It's a little bit more complicated than that, and there are a lot other factors at play as well even outside of security. We're not really getting into stuff like future-proofing and what happens if 1Password gets a lot worse in the future. It's complicated.

But the gist is that while it would be a lot better if 1Password was Open Source, it's still in its current state probably got more eyes on it than some Open Source security projects do.

Re: I Lost All Faith in LastPass

#74

> I'm less thrilled about it being written in a garbage collected language What are the security problems with garbage-collected languages? (not being sarcastic, don't have an agenda, I have no previous knowledge on this, and am not a security expert. Just had never heard this suggested before, and am curious what he meant. Legit question!)

If anything I would intuit such an implementation is sacrificing performance for security, since it rules out some classic vulnerabilities.

Re: I Lost All Faith in LastPass

#75

God damnit, but what doesn't. I am sure BitWarden has its own problems and it (seems?) not 100% FOSS but its core is. LP extension and web vault ARE pure garbage: 1. It can't even recognize sites correctly ?! WTF really. I usually get 10 or so (looks like random) hits for any site but not the one that I should. 2. It offers me to extend pro support 5 years after I stopped paying for it. What I need to do for it to st…

LastPass is my go-to example for poor UI suggesting poor quality throughout.

Re: I Lost All Faith in LastPass

#76

Trusting a 3rd party password manager seems troublesome

By your standards, trusting any 3rd party solution seems troublesome.

The entire web is built on 3rd party solutions. Should we all write our encryption libraries b/c we shouldn't trust any 3rd party solution?

Re: I Lost All Faith in LastPass

#77

Well, that sounds bad. I mean, I'm not an infosec expert, but I can follow enough of that to see that it's not good. I use Lastpass at work, because we have a site license, but maybe I'll look into whether I can switch over to bitwarden. I don't expect perfect security, but I expect them to at least try .

You have to understand that this isn't an isolated event. LastPass is uniquely bad at this, and it is, for many, the last straw.

Re: I Lost All Faith in LastPass

#78

I feel like a shill at this point but just use Bitwarden. open source, cloud sync by default, alternative self-hostable backend if you want to, no device limit, doesn't cost anything which is just about the only thing that concerns me because the free plan seems too good honestly.

Bitwarden is great, and their commercial offering of $10.00 per year is so cheap as to be effectively free. My only issue is the fact their servers could be wiped and I no longer have access to my data, but that's where KeepassXC comes in. I keep one Bitwarden and one Keepass DB as a fallback, and keep them updated with the same login entries. I store my KeepassXC database in various cloud storage services, as-well as keeping various local copies.

Re: I Lost All Faith in LastPass

#79
All online cloud password managers have vulnerabilities of some form or another. As computer people why would you think otherwise? I don't understand any of the assumptions that your data would be safe in the cloud. I had this same point to a past employer that LastPass (or other password in the cloud manager) will always be vulnerable. But it falls on deaf ears. I would never, ever trust my passwords to an online storage provider.

Re: I Lost All Faith in LastPass

#80

Earlier quoted context omitted.

Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.

An appeal to authority is not a logical fallacy if the person in question is actually an authority in the domain .

> if the person in question is actually an authority in the domain

I haven't seen a name mentioned in much of the discussion here.

Who are we talking about from this list, and what else have they done? https://1password.com/company/

Post reply on HN