Live data from Hacker News

I Lost All Faith in LastPass

infosec.exchange

271–280 of 322 posts

Re: I Lost All Faith in LastPass

#272

Thoughts on Bitwarden vs 1Password? I have seen them both suggested by users on this site.

Not sure about 1Password, but I am using Bitwarden free and there's no authenticator app. I just use Authy on Android, though, it works great

> but I am using Bitwarden free and there's no authenticator app

There is if you pay $10 annually for Bitwarden Pro.

I use it, and it was the game changer I needed in terms of user-experience, to bother actually start using 2FA/MFA for all sites where it was an option (compared to before where I would only do it if required).

I definitely recommend giving it a try.

Re: I Lost All Faith in LastPass

#273

Earlier quoted context omitted.

Not dismissing anything you said regarding 1PW but they also had cure53 audits. See e.g. - https://cure53.de/pentest-report_1password-b5.pdf - https://cure53.de/pentest-report_1password-mobile.pdf Edit: overview of audits https://support.1password.com/security-assessments/

These are pen-tests and black-box security audits. While they're definitely better than nothing, and they would show that their security is better than LastPass', the code was never audited.

Are we reading the same reports? At least the two latest reports by Cure53 mentions "source code audit". In addition, the audits by ISE and AppSec explicitly mentions code review as part of the audit.

I am in no way familiar with these kinds of reports, but does this not mean that (at least parts of) the source code was audited?

Re: I Lost All Faith in LastPass

#274

question for those who know: for those of us in apple ecosystem, is just relying on their keychain an acceptable alternative to a third-party password manager company?

If your passcode(s) on your device are longer than 6 digits, sure. As it stands, you can recover your iCloud Keychain by either[0]: (A) signing into iCloud (Requires Apple ID Password) + approving the new device on an existing device that has Keychain access or (B) signing into iCloud (Requires Apple ID Password) + performing SMS 2FA + entering the device passcode of your primary device The threat model here is where…

> As it stands, you can recover your iCloud Keychain by either...

I remember, a long time ago when i created an AppleID, there was a yes/no choice whether or not to upload [something related to the password] to Apple, so it would become possible to recover the AppleID password if needed in the future.

Is that still a thing, or has it been replaced by new features now?

Re: I Lost All Faith in LastPass

#275

Earlier quoted context omitted.

Not sure about 1Password, but I am using Bitwarden free and there's no authenticator app. I just use Authy on Android, though, it works great

> but I am using Bitwarden free and there's no authenticator app There is if you pay $10 annually for Bitwarden Pro. I use it, and it was the game changer I needed in terms of user-experience, to bother actually start using 2FA/MFA for all sites where it was an option (compared to before where I would only do it if required). I definitely recommend giving it a try.

I have pro subscription too. Definitely worth it to be able to do 2fa on all sites. Also can require yubikey when logging into Bitwarden.

Re: I Lost All Faith in LastPass

#276

Earlier quoted context omitted.

Not sure about 1Password, but I am using Bitwarden free and there's no authenticator app. I just use Authy on Android, though, it works great

Does bitwarden work well with autofill? Lastpass was awful with that and very finicky.

For the sites I normally visit, it works well.

GitHub and some famous banks/credit card providers.

Mfa code doesn't autofill, but it's just a click to copy.

Re: I Lost All Faith in LastPass

#277
post #58

Leaning strongly towards self-hosting. Name brand cloud managers just make too juicy a target for sophisticated attackers regardless of their competence/care of the pass manager co. I know it's got a bit of security via obscurity vibes, but I've concluded the combo of residential IP, wireguard, firewall and dedicated VM is probably more secure. That would require someone with decent skill targeting me specifically...…

Keepass and use dropbox or onedrive to sync. There’s no uptime issue there.

Yeah still considering how exactly. Not exactly thrilled about removing it from one cloud only to stick it onto a different one with arguable even less security features (geo blocks etc)...

Ideally I'd sync it directly against home server, but iphone limits options on sync to own server a bit. Maybe via git...

Re: I Lost All Faith in LastPass

#278

I feel like a shill at this point but just use Bitwarden. open source, cloud sync by default, alternative self-hostable backend if you want to, no device limit, doesn't cost anything which is just about the only thing that concerns me because the free plan seems too good honestly.

Bitwarden is great, and their commercial offering of $10.00 per year is so cheap as to be effectively free. My only issue is the fact their servers could be wiped and I no longer have access to my data, but that's where KeepassXC comes in. I keep one Bitwarden and one Keepass DB as a fallback, and keep them updated with the same login entries. I store my KeepassXC database in various cloud storage services, as-well a…

> My only issue is the fact their servers could be wiped and I no longer have access to my data

So is the Bitwarden database not also stored/always up to date local (like how IMAP works for e-mail, if the server goes offline you still have all your emails locally) ?

Re: I Lost All Faith in LastPass

#279

All online cloud password managers have vulnerabilities of some form or another. As computer people why would you think otherwise? I don't understand any of the assumptions that your data would be safe in the cloud. I had this same point to a past employer that LastPass (or other password in the cloud manager) will always be vulnerable. But it falls on deaf ears. I would never, ever trust my passwords to an online st…

All-or-nothing thinking aka "Splitting": https://en.wikipedia.org/wiki/Splitting_(psychology)

Re: I Lost All Faith in LastPass

#280
post #70

This is why we need good OS-level password managers. Phones and now computers have dedicated security chips which are infinitely more secure than any cloud solution. Such an easy market to grab that it boggles me why Apple and Google aren't aggressively going for it.

iCloud Keychain syncing, strong password suggestions in Safari, and WebAuthn passkeys are all part of Apple's strategy. When they don't buy a third party and deeply integrate it, they tend to operate by insinuating themselves as the platform default. What would you have them add to that?

I’d say - ability to use it across platform or across system accounts. I like to use my personal LastPass when logged into my work laptop with corp account. Mind you, not to store work passwords, no, to have access to e.g. my Amazon account.

Additionally, I share my LastPass with my partner. Probably not a setup for most, but we find it convenient.

All that is achievable only when the password manager is not tied to the system login.

Post reply on HN