The first paragraph very nearly lost me – irrational, rage bait, directly contradicts later stated facts – but there’s some good content later. The chief complaint seems to be that LastPass is not forcing this upgrade, they are just blast emailing unaffected people that they “forced” it while not actually doing so. And they’ve pulled similar stunts in the past, and in current communication seem to clearly be blaming…
> Everybody with a clue knows LastPass is a lost cause, Yeah at this point, I have to wonder how there are still lastpass users to worry about whatever the latest lastpass scandal is.
LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password
51–60 of 77 posts
Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password
#52>>> KrebsOnSecurity last month interviewed a victim who recently saw more than three million dollars worth of cryptocurrency siphoned from his account. That user signed up with LastPass nearly a decade ago, stored their cryptocurrency seed phrase there, and yet never changed his master password — which was just eight characters. Nor was he ever forced to improve his master password. This does fascinate me. How many p…
I still hold ~1M US worth of crypto all together, which is roughly the majority of my net worth. Been in since early days. If I'd guess I've probably "realized" (sold/used for payment for non-crypto goods or services) ~20~30k$ or so over the years? I still donate here and there and use it for payment for goods and services when I can. I probably lost at least another ~1M$ worth (not projected: at the time. it sucks b…
Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password
#53Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password
#54Earlier quoted context omitted.
If you are complaining about the idea of iterating a hash multiple times, this is actually a fairly standard construction to increase the cpu cost of brute forcing hashes.
Asking a question isn’t complaining.
Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password
#55The whole approach that LastPass uses of only encrypting the vault with the master password is just bad security - it really doesn't matter how many rounds of a key derivation algorithm they use. The 1Password approach provides much better security. The vault is protected with the master password together with a long randomly generated string. That random string is saved on device on first login, so subsequent decryp…
Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password
#56The first paragraph very nearly lost me – irrational, rage bait, directly contradicts later stated facts – but there’s some good content later. The chief complaint seems to be that LastPass is not forcing this upgrade, they are just blast emailing unaffected people that they “forced” it while not actually doing so. And they’ve pulled similar stunts in the past, and in current communication seem to clearly be blaming…
Can someone explain to me what is the advantage of using something like LastPass over simply the in-built password manager that Firefox or other browsers have? I know that LastPass can be used for desktop applications too, but if you are only using a password for the web, is LastPass offering anything more than the in-built browser password manager?
I'm also not sure if those built-in password managers sync to other devices and if you want to trust them with it.
Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password
#57The whole approach that LastPass uses of only encrypting the vault with the master password is just bad security - it really doesn't matter how many rounds of a key derivation algorithm they use. The 1Password approach provides much better security. The vault is protected with the master password together with a long randomly generated string. That random string is saved on device on first login, so subsequent decryp…
Serious question - I've never used 1Password - what happens if you only ever use one device and that device becomes permanently unavailable for some reason (stolen, destroyed, etc)?
But you are absolutely correct, if you lose your device and the Emergency Kit you're SOL. It reality, though, that is mitigated by the fact that:
1. I think it's probably pretty rare to install 1P on only a single device, as the biggest benefit of any hosted password manager is syncing. I think the vast majority of people will install it at least on their phone and a laptop/PC.
2. I think the user experience for setting up the Emergency Kit is done well and most people are likely to do it.
Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password
#58Earlier quoted context omitted.
Can someone explain to me what is the advantage of using something like LastPass over simply the in-built password manager that Firefox or other browsers have? I know that LastPass can be used for desktop applications too, but if you are only using a password for the web, is LastPass offering anything more than the in-built browser password manager?
Who only logs in on websites? So many apps also require logging in. I'm also not sure if those built-in password managers sync to other devices and if you want to trust them with it.
Upside is that it also syncs to my Firefox on Linux, which Apple’s doesn’t.
Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password
#59Earlier quoted context omitted.
Can someone explain to me what is the advantage of using something like LastPass over simply the in-built password manager that Firefox or other browsers have? I know that LastPass can be used for desktop applications too, but if you are only using a password for the web, is LastPass offering anything more than the in-built browser password manager?
credentials/certificates/keys/data storage, secure sharing etc. Pretty much anything that's more complex than single user username + password doesn't seem to be served by the current built-in managers.
Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password
#60Earlier quoted context omitted.
Can someone explain to me what is the advantage of using something like LastPass over simply the in-built password manager that Firefox or other browsers have? I know that LastPass can be used for desktop applications too, but if you are only using a password for the web, is LastPass offering anything more than the in-built browser password manager?
Safari's built-in pw manager: - until recently, didn't have 2fa - doesn't support multiple domains under the same account (e.g., the stackexchange network is considered one site per subdomain) - doesn't support generating complex passwords (it'll generate passwords but I'd hardly call them complex…) - doesn't support credentials not associated with websites (e.g., an SSH login, a bank pin…)