Live data from Hacker News

LastPass Now Checks If Your Sites Are Affected by Heartbleed

blog.lastpass.com

11–20 of 94 posts

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#11

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

Used to use LastPass, but I've disliked some of their recent decisions. Their Android app is getting bulkier by the update; it includes a full blown web browser inside the app. Their Firefox extension seems to be no longer maintained as well. I switched to KeePass + Dropbox and have been enjoying it. If you use OSX, I strongly recommend http://mstarke.github.io/MacPass/

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#12

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

Used to use LastPass, but I've disliked some of their recent decisions. Their Android app is getting bulkier by the update; it includes a full blown web browser inside the app. Their Firefox extension seems to be no longer maintained as well. I switched to KeePass + Dropbox and have been enjoying it. If you use OSX, I strongly recommend http://mstarke.github.io/MacPass/

We've always had a full blown web browser in the app -- it's been the only viable way to fill passwords in for years. Literally the first option we added.

We also have an extension into Dolphin, and you can utilize Chrome utilizing our fill method -- if you don't like them there are options to disable them too reducing the perceived extra bulk.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#13
post #10
post #4

Notably some sites are using fresh certificates that have the same (months-in-the-past) starting-validity date as their old certificates. For example, Heroku has done this. (I can think of a few process and fee reasons this approach might be picked. Perhaps a CA might offer a free new cert and revocation, if and only if the new cert has the same validity range as the one it replaces. An ops team might prefer one cons…

We haven't found a way to do this -- we're using openssl s_client to get the start date, but one of our own certificates for LastPass.eu also reissued without changing the date so we know it's a problem. We wish we had all site's certificate fingerprints from before this started so we could utilize that data -- if anyone has it, an email to securit@lastpass.com would be greatly appreciated.

You might consider reaching out to the people behind the Perspectives Project. They run 10 public notary servers [0], and chances are good that they have fingerprints for most of the widely-trafficked websites.

For example, here's the Perspectives report on lastpass.com showing the brand-new key as well as the old ones: http://i.imgur.com/hJkFTAy.png

[0]: http://perspectives-project.org/notary-servers/

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#14
post #10
post #4

Notably some sites are using fresh certificates that have the same (months-in-the-past) starting-validity date as their old certificates. For example, Heroku has done this. (I can think of a few process and fee reasons this approach might be picked. Perhaps a CA might offer a free new cert and revocation, if and only if the new cert has the same validity range as the one it replaces. An ops team might prefer one cons…

We haven't found a way to do this -- we're using openssl s_client to get the start date, but one of our own certificates for LastPass.eu also reissued without changing the date so we know it's a problem. We wish we had all site's certificate fingerprints from before this started so we could utilize that data -- if anyone has it, an email to securit@lastpass.com would be greatly appreciated.

You might want to contact the maintainers of HTTPS Everywhere at the EFF. They collect and archive certificates for the SSL Observatory project.

https://www.eff.org/observatory

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#15
post #10

Earlier quoted context omitted.

We haven't found a way to do this -- we're using openssl s_client to get the start date, but one of our own certificates for LastPass.eu also reissued without changing the date so we know it's a problem. We wish we had all site's certificate fingerprints from before this started so we could utilize that data -- if anyone has it, an email to securit@lastpass.com would be greatly appreciated.

You might consider reaching out to the people behind the Perspectives Project. They run 10 public notary servers [0], and chances are good that they have fingerprints for most of the widely-trafficked websites. For example, here's the Perspectives report on lastpass.com showing the brand-new key as well as the old ones: http://i.imgur.com/hJkFTAy.png [0]: http://perspectives-project.org/notary-servers/

Thanks, looks like a good lead.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#16

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

I use Dashlane and its been great! Surprised not seeing too much support for it around here...

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#17
post #12

Earlier quoted context omitted.

Used to use LastPass, but I've disliked some of their recent decisions. Their Android app is getting bulkier by the update; it includes a full blown web browser inside the app. Their Firefox extension seems to be no longer maintained as well. I switched to KeePass + Dropbox and have been enjoying it. If you use OSX, I strongly recommend http://mstarke.github.io/MacPass/

We've always had a full blown web browser in the app -- it's been the only viable way to fill passwords in for years. Literally the first option we added. We also have an extension into Dolphin, and you can utilize Chrome utilizing our fill method -- if you don't like them there are options to disable them too reducing the perceived extra bulk.

"it's been the only viable way to fill passwords in for years"

Call me old fashioned, but I'd rather copy/paste than rely on the web browser within the app. The lack of attention for the desktop Firefox extension is what drove me to alternatives. After switching away, I realized I was paying for a payed proprietary system with no real benefits from an open source solution.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#18
post #16

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

I use Dashlane and its been great! Surprised not seeing too much support for it around here...

I use Dashlane as well, have for about 2 years now, I love the app as an extension in firefox and the mobile app with secure notes.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#19

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

I use LastPass and definitely recommend it. It will generate a random password for you based on definable criteria, which I like and use almost everywhere. The primary vector of mass attacks these days seems to be one compromised database leaks out, and then they use those cracked passwords to get into other sites where you used the same email/pass combination. Keeping track of hundreds of unique and secure passwords without a manager is untenable.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#20

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

OK I'll bite ... why should I not use my browser's built in pw manager? (e.g. Safari on OS X Mavericks)

I can see an argument about cross-platform use but is there another reason or reasons?

thanks,

Post reply on HN