LastPass Now Checks If Your Sites Are Affected by Heartbleed
blog.lastpass.com
LastPass Now Checks If Your Sites Are Affected by Heartbleed
1–10 of 94 posts
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#2Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#3I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#4(I can think of a few process and fee reasons this approach might be picked. Perhaps a CA might offer a free new cert and revocation, if and only if the new cert has the same validity range as the one it replaces. An ops team might prefer one consistent time of year for the ceremony of non-emergency certificate rotation.)
I didn't notice any field in the cert-viewers of Firefox or Chrome that could reliably tell the true issue-date of a new certificate.
Is LastPass just looking at the start of the validity, or does it have some way to know if the certificate is truly new?
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#5I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#6I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
Things like their security check are just icing on the cake.
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#7I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
I use LastPass Premium
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#8I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
You could store your passwords in a git repo to get a sort cross-platform thing going on.
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#9Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#10Notably some sites are using fresh certificates that have the same (months-in-the-past) starting-validity date as their old certificates. For example, Heroku has done this. (I can think of a few process and fee reasons this approach might be picked. Perhaps a CA might offer a free new cert and revocation, if and only if the new cert has the same validity range as the one it replaces. An ops team might prefer one cons…
We wish we had all site's certificate fingerprints from before this started so we could utilize that data -- if anyone has it, an email to securit@lastpass.com would be greatly appreciated.