I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
LastPass Now Checks If Your Sites Are Affected by Heartbleed
11–20 of 94 posts
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#12I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
Used to use LastPass, but I've disliked some of their recent decisions. Their Android app is getting bulkier by the update; it includes a full blown web browser inside the app. Their Firefox extension seems to be no longer maintained as well. I switched to KeePass + Dropbox and have been enjoying it. If you use OSX, I strongly recommend http://mstarke.github.io/MacPass/
We also have an extension into Dolphin, and you can utilize Chrome utilizing our fill method -- if you don't like them there are options to disable them too reducing the perceived extra bulk.
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#13Notably some sites are using fresh certificates that have the same (months-in-the-past) starting-validity date as their old certificates. For example, Heroku has done this. (I can think of a few process and fee reasons this approach might be picked. Perhaps a CA might offer a free new cert and revocation, if and only if the new cert has the same validity range as the one it replaces. An ops team might prefer one cons…
We haven't found a way to do this -- we're using openssl s_client to get the start date, but one of our own certificates for LastPass.eu also reissued without changing the date so we know it's a problem. We wish we had all site's certificate fingerprints from before this started so we could utilize that data -- if anyone has it, an email to securit@lastpass.com would be greatly appreciated.
For example, here's the Perspectives report on lastpass.com showing the brand-new key as well as the old ones: http://i.imgur.com/hJkFTAy.png
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#14Notably some sites are using fresh certificates that have the same (months-in-the-past) starting-validity date as their old certificates. For example, Heroku has done this. (I can think of a few process and fee reasons this approach might be picked. Perhaps a CA might offer a free new cert and revocation, if and only if the new cert has the same validity range as the one it replaces. An ops team might prefer one cons…
We haven't found a way to do this -- we're using openssl s_client to get the start date, but one of our own certificates for LastPass.eu also reissued without changing the date so we know it's a problem. We wish we had all site's certificate fingerprints from before this started so we could utilize that data -- if anyone has it, an email to securit@lastpass.com would be greatly appreciated.
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#15Earlier quoted context omitted.
We haven't found a way to do this -- we're using openssl s_client to get the start date, but one of our own certificates for LastPass.eu also reissued without changing the date so we know it's a problem. We wish we had all site's certificate fingerprints from before this started so we could utilize that data -- if anyone has it, an email to securit@lastpass.com would be greatly appreciated.
You might consider reaching out to the people behind the Perspectives Project. They run 10 public notary servers [0], and chances are good that they have fingerprints for most of the widely-trafficked websites. For example, here's the Perspectives report on lastpass.com showing the brand-new key as well as the old ones: http://i.imgur.com/hJkFTAy.png [0]: http://perspectives-project.org/notary-servers/
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#16I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#17Earlier quoted context omitted.
Used to use LastPass, but I've disliked some of their recent decisions. Their Android app is getting bulkier by the update; it includes a full blown web browser inside the app. Their Firefox extension seems to be no longer maintained as well. I switched to KeePass + Dropbox and have been enjoying it. If you use OSX, I strongly recommend http://mstarke.github.io/MacPass/
We've always had a full blown web browser in the app -- it's been the only viable way to fill passwords in for years. Literally the first option we added. We also have an extension into Dolphin, and you can utilize Chrome utilizing our fill method -- if you don't like them there are options to disable them too reducing the perceived extra bulk.
Call me old fashioned, but I'd rather copy/paste than rely on the web browser within the app. The lack of attention for the desktop Firefox extension is what drove me to alternatives. After switching away, I realized I was paying for a payed proprietary system with no real benefits from an open source solution.
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#18I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
I use Dashlane and its been great! Surprised not seeing too much support for it around here...
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#19I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed
#20I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
I can see an argument about cross-platform use but is there another reason or reasons?
thanks,