Live data from Hacker News

LastPass Now Checks If Your Sites Are Affected by Heartbleed

blog.lastpass.com

1–10 of 94 posts

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#2
I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others?

Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#3

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

I use both LastPass and 1Password (in different contexts). I find 1Password more polished and nicer to use, by LastPass works fine too.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#4
Notably some sites are using fresh certificates that have the same (months-in-the-past) starting-validity date as their old certificates. For example, Heroku has done this.

(I can think of a few process and fee reasons this approach might be picked. Perhaps a CA might offer a free new cert and revocation, if and only if the new cert has the same validity range as the one it replaces. An ops team might prefer one consistent time of year for the ceremony of non-emergency certificate rotation.)

I didn't notice any field in the cert-viewers of Firefox or Chrome that could reliably tell the true issue-date of a new certificate.

Is LastPass just looking at the start of the validity, or does it have some way to know if the certificate is truly new?

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#5

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

In a vote for lastpass (I haven't tried the others) - they just added auto filling passwords for the android app. It works pretty well (typing their generated passwords into apps that blocked copy/paste was my biggest gripe until then). I'd say that it's pretty easy to get duplicate entries for a single site which can get annoying, but it's relatively easy to delete ones if you don't get mixed up with which is the "correct" entry first.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#6

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

I use and really like LastPass. In particular, its integration with browsers (and my smartphone) with the random password generation means that my passwords are all unique and non-rememberable (and thus unphishable, since I rely on LastPass to fill the password for me, which it only does on a domain match).

Things like their security check are just icing on the cake.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#7

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

You are likely not to see a clear victor in this thread either. People who use/like LastPass will say so, and those who use others will throw in the vote there. You can also google 'Option 1 vs Option 2' and get a bunch of results. Best you try them yourself and see which one you like!

I use LastPass Premium

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#8

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

I use pass http://www.zx2c4.com/projects/password-store/

You could store your passwords in a git repo to get a sort cross-platform thing going on.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#10
post #4

Notably some sites are using fresh certificates that have the same (months-in-the-past) starting-validity date as their old certificates. For example, Heroku has done this. (I can think of a few process and fee reasons this approach might be picked. Perhaps a CA might offer a free new cert and revocation, if and only if the new cert has the same validity range as the one it replaces. An ops team might prefer one cons…

We haven't found a way to do this -- we're using openssl s_client to get the start date, but one of our own certificates for LastPass.eu also reissued without changing the date so we know it's a problem.

We wish we had all site's certificate fingerprints from before this started so we could utilize that data -- if anyone has it, an email to securit@lastpass.com would be greatly appreciated.

Post reply on HN