Sharing a short post I posted a year ago with some thoughts on password managers. ## The password-management promise > I don't buy the promise behind 1Password or LastPass. > You only need to remember one password. The last password you'd need to remember. > They don't tell you that you're also building a one-stop shop for hackers to steal it all at once. > The solution? > Store hints, not passwords. > Don't reuse pa…
I used to be really skeptical of online password vaults. I thought they were an obvious Honeypot begging to be hacked. But if I understand the technology behind 1password correctly, there is literally no way for a hacker to sign into my account on a new device without having one of my other devices or my secret key (the actual 34 digit encryption key used to verify my account and set up new devices). So even if they…
Feds Link Cyberheist to 2022 LastPass Hacks
101–110 of 266 posts
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#102Earlier quoted context omitted.
I used to be really skeptical of online password vaults. I thought they were an obvious Honeypot begging to be hacked. But if I understand the technology behind 1password correctly, there is literally no way for a hacker to sign into my account on a new device without having one of my other devices or my secret key (the actual 34 digit encryption key used to verify my account and set up new devices). So even if they…
> So even if they know my 1password username and password they still can't really do anything with it. And if they steal my device, they would need to know my login password. Or cut off a finger, I guess, but I've got bigger issues if that happens. https://xkcd.com/538/
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#103Earlier quoted context omitted.
Is bitwarden’s only differentiator being open source and self hostable? Im looking at other services and thus far see no reason to leave 1Password.
That, and it's better in most functional and polish regards than LastPass. I haven't used 1Password, so I can't compare those two directly, but I'd strongly recommend BitWarden over LastPass as far as those two are considered.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#104Earlier quoted context omitted.
is that not enough? It's also inexpensive and works very well on all platforms.
Not OP, but UX also matters a lot. I’d strongly prefer an open source and selfhostable option, but each time I’ve evaluated Bitwarden in the past, it was a big enough downgrade from 1Password that I didn’t think switching was a good option. If the experience ever becomes as seamless, I’ll be switching.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#105Earlier quoted context omitted.
>But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypted gzipped file (with the passphrase I’ll leave them) containing my passwords in a csv file. technical possibilities aside, do you presume your grandchildren will be technically apt? I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now.
> I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now. I know reading the docs is considered uncool for some reason, but it really does work.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#106Earlier quoted context omitted.
> Bitwarden truly doesn’t get enough credit for being completely open source It’s their No. 1 selling point. > In 50 years time, who knows if any of these companies will be around 1Password has local clients. If you have the password, you should be able to unlock the vault locally.
Can you walk me through how to do this? I have installed the "1password-cli" package on my airgapped linux machine with no network access ('op --version' gives me 2.30.3). If I run 'op vault list', it tells me I have to add an account. When I run 'op account add' it tries to connect to 1password's servers and won't let me proceed without internet. I don't see how this "local client" is helping if all the auth infrast…
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#107I've never been hacked, never been locked out of any accounts.
I'm getting tired of being proven right about everything over and over after being downvoted. It's a very common pattern for me.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#108Earlier quoted context omitted.
> I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now. I know reading the docs is considered uncool for some reason, but it really does work.
To how many non-SWE members of your family could you say 'here is the Netflix password, you can decrypt it with gpg', and have them be like 'ah yes, let me just `man gpg` this will be no problem'?
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#109Ok, Im not sure "1Password," qualifies as a single world. Oh yeah, 1Password.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#110Me, looking at my local KeepassXC, calm, sticking with it.
This is the kind of control that is really becoming a luxury. And I don't know how we get back to a simple state; Let's say you're a family of three with shared services and accounts: Keeping everything under Keepass means handling the file sync between all the devices and OSes, with potentially your credentials flying through third party sync services, thus negating most of the advantages of Keepass. Moving to somet…