Earlier quoted context omitted.
An appeal to authority is not a logical fallacy if the person in question is actually an authority in the domain .
The truth of a statement is what matters, not who uttered it.
I Lost All Faith in LastPass
101–110 of 322 posts
Re: I Lost All Faith in LastPass
#102I have been a LastPass customer for over 10 years and I think this January when my yearly subscription ends, I will finally not renewing. I’ve shrugged off a lot of strangeness that has been happening with them as a fledging company’s growing pains. Unfortunately, this incident is the final straw. I think we are going to see a lot more come to light and their lack of any sort of transparency on this is a cardinal sin…
I just did the migration (to 1password though, sorry the lack of tags is very bad for organization), 6 years old customer. Key points: - Refresh the website list from the extension before starting, ideally clear the extension cache first (will sign out) - export from the extension - attachments and password history are not exported - there is a lastpass-cli that will help you export attachments - there is a hacked to…
I didn't understand any of your explanation of how to migrate from Lastpass to 1Password.
Re: I Lost All Faith in LastPass
#103Re: I Lost All Faith in LastPass
#104Earlier quoted context omitted.
Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.
An appeal to authority is not a logical fallacy if the person in question is actually an authority in the domain .
Now, it's grounds for an (extremely) persuasive inference! And we know very little of what we consider known by strict deductive logic: we rely on weaker inferential reasoning the vast majority of the time. Grandparent's "means almost nothing" is much, much too strong.
But when we really want to know for sure that something is true, people are going to want to see proof, not a statement from someone who probably knows of proof.
Re: I Lost All Faith in LastPass
#105> I'm less thrilled about it being written in a garbage collected language What are the security problems with garbage-collected languages? (not being sarcastic, don't have an agenda, I have no previous knowledge on this, and am not a security expert. Just had never heard this suggested before, and am curious what he meant. Legit question!)
That said, I'm sure there are workarounds even in GCed languages. For instance, you can usually create C extensions which could allocate and manage memory outside of the GC's control. So, such extesion could potentially give back memory control of certain special memory regions where secrets can be stored, while everything else just goes through normal GC.
Re: I Lost All Faith in LastPass
#106How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…
The older versions of 1Password are BYOH, bring your own hosting. I use it because I don’t want a single source of failure. My information is encrypted and stored in another cloud service. It doesn’t matter if that cloud service is breached. It doesn’t matter if 1Password is breached.
Re: I Lost All Faith in LastPass
#107Earlier quoted context omitted.
There is good insight into this from this comment from them in 2014: https://1password.community/discussion/comment/114870/#Comme...
That seems to be about transitioning to an open-source model. I don't mean that. I mean simply having their git repo publicly accesible in a read-only fashion. No external contributions, no license, etc. I see no reason not to do this, especially for such a security-oriented service. You should be striving for as much transparency as possible .
Re: I Lost All Faith in LastPass
#108Re: I Lost All Faith in LastPass
#109Earlier quoted context omitted.
That seems to be about transitioning to an open-source model. I don't mean that. I mean simply having their git repo publicly accesible in a read-only fashion. No external contributions, no license, etc. I see no reason not to do this, especially for such a security-oriented service. You should be striving for as much transparency as possible .
Because they like being in business vs just giving away their software? Where is the repo of software that you've paid an unknown number of developers to work on for multiple years over multiple versions that you charge for and run a viable business employing all of the peoples?
Re: I Lost All Faith in LastPass
#110Earlier quoted context omitted.
That seems to be about transitioning to an open-source model. I don't mean that. I mean simply having their git repo publicly accesible in a read-only fashion. No external contributions, no license, etc. I see no reason not to do this, especially for such a security-oriented service. You should be striving for as much transparency as possible .
Because they like being in business vs just giving away their software? Where is the repo of software that you've paid an unknown number of developers to work on for multiple years over multiple versions that you charge for and run a viable business employing all of the peoples?