I Lost All Faith in LastPass
71–80 of 322 posts
Re: I Lost All Faith in LastPass
#72Leaning strongly towards self-hosting. Name brand cloud managers just make too juicy a target for sophisticated attackers regardless of their competence/care of the pass manager co. I know it's got a bit of security via obscurity vibes, but I've concluded the combo of residential IP, wireguard, firewall and dedicated VM is probably more secure. That would require someone with decent skill targeting me specifically...…
Re: I Lost All Faith in LastPass
#73Earlier quoted context omitted.
Most people don't read open source and instead trust that the experts will catch any issues....
It's turtles all the way down. Would you rather NOT have the option for other experts to see the code?
Being Open Source is in some ways a multiplier on security because it allows more expert review. But the expert review is the important part; if security-critical code is Open Source but hasn't been looked at by anyone other than the main developers, the Open Source part is a multiplier on zero.
It's a little bit more complicated than that, and there are a lot other factors at play as well even outside of security. We're not really getting into stuff like future-proofing and what happens if 1Password gets a lot worse in the future. It's complicated.
But the gist is that while it would be a lot better if 1Password was Open Source, it's still in its current state probably got more eyes on it than some Open Source security projects do.
Re: I Lost All Faith in LastPass
#74> I'm less thrilled about it being written in a garbage collected language What are the security problems with garbage-collected languages? (not being sarcastic, don't have an agenda, I have no previous knowledge on this, and am not a security expert. Just had never heard this suggested before, and am curious what he meant. Legit question!)
Re: I Lost All Faith in LastPass
#75God damnit, but what doesn't. I am sure BitWarden has its own problems and it (seems?) not 100% FOSS but its core is. LP extension and web vault ARE pure garbage: 1. It can't even recognize sites correctly ?! WTF really. I usually get 10 or so (looks like random) hits for any site but not the one that I should. 2. It offers me to extend pro support 5 years after I stopped paying for it. What I need to do for it to st…
Re: I Lost All Faith in LastPass
#76Trusting a 3rd party password manager seems troublesome
The entire web is built on 3rd party solutions. Should we all write our encryption libraries b/c we shouldn't trust any 3rd party solution?
Re: I Lost All Faith in LastPass
#77Well, that sounds bad. I mean, I'm not an infosec expert, but I can follow enough of that to see that it's not good. I use Lastpass at work, because we have a site license, but maybe I'll look into whether I can switch over to bitwarden. I don't expect perfect security, but I expect them to at least try .
Re: I Lost All Faith in LastPass
#78I feel like a shill at this point but just use Bitwarden. open source, cloud sync by default, alternative self-hostable backend if you want to, no device limit, doesn't cost anything which is just about the only thing that concerns me because the free plan seems too good honestly.
Re: I Lost All Faith in LastPass
#79Re: I Lost All Faith in LastPass
#80Earlier quoted context omitted.
Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.
An appeal to authority is not a logical fallacy if the person in question is actually an authority in the domain .
I haven't seen a name mentioned in much of the discussion here.
Who are we talking about from this list, and what else have they done? https://1password.com/company/