Live data from Hacker News

LastPass Now Checks If Your Sites Are Affected by Heartbleed

blog.lastpass.com

21–30 of 94 posts

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#21

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

My biggest problem with LastPass, and this is a small problem, is that it fucks up on a fair amount of input fields. So for example, it still works, but its icon is too huge for site example.com so it is awkaward or it thinks it is a username and password form but it is actually a signup form with username password1 password2.

I'd still recommend it, despite those problems.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#22
post #20

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

OK I'll bite ... why should I not use my browser's built in pw manager? (e.g. Safari on OS X Mavericks) I can see an argument about cross-platform use but is there another reason or reasons? thanks,

There are some sites that try to disable the ability to save passwords and 3rd party password managers usually override this. Another thing that's really nice is having the LastPass extension on Firefox, Chrome, and Safari on the same computer and not having to worry about if they are using the system keychain or not. In my experience, form filling with credit card information has been less error prone with LastPass as well. I thought at one point Safari was requiring the CVV number to be manually entered too. I could be mistaken.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#23

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

With a question like this, you're probably going to get a lot of biased options. Not because people want you to use an inferior product, but because obviously one think that what he uses it the best. For example, as a current KeePass user, I'd suggest it.

Lastpass overall is comfy, you do everything within your browser, it sync without much problems and you can use it on the go with the official applications and addons. One downside is that everything is closed source. The other one is that I find their addon is trying to do too much, and it's not polished enough (at least, their Firefox one). I've had tons of annoyances with it.

Keepass instead is awesome because it's opensource and you own your data. But you can feel that not everything is nicely integrated. I use a Firefox addon (PassIFox) for filling username/password, and it works pretty nicely, but you have to set it up (and it's kinda a pain to get it working on Linux). I use an application on Android (Keepass2Android) which has a different UX, and doesn't have the fancy input method that the lastpass app has (instead you just copy/paste, and there is a keyboard for autofilling but I find it mostly annoying). The integrated sync support only ftp/webdav, and not everyone has a server providing those around (and I never got webdav to work anyway). Sure, you can sync the file with dropbox or other "cloud" solutions, but this implies even more software in your chain.

I never got to try OnePass sadly, as there's no Linux version.

Anyway, I'd say: Try both, and see which one you prefer. Keepass is libre, and lastpass has a free tier, so you don't have to put any money in it. Just use them for a bunch of sites for a bunch of days, and then decide.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#24
post #20

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

OK I'll bite ... why should I not use my browser's built in pw manager? (e.g. Safari on OS X Mavericks) I can see an argument about cross-platform use but is there another reason or reasons? thanks,

I don't know about Safari, but the built-in password manager in most browsers are very light on features and have abysmal security. AFAIK Chrome still refuses to let you set a master password to protect your other passwords. Firefox is better, but the user interface is bare bones compared to a dedicated password manager.

I suspect that the password manager in most browsers have received less attention than it deserves, partly because all the vendors been trying very hard to get people to drop passwords altogether. Mozilla pushed Persona, Google pushed Google accounts, Microsoft pushed Microsoft accounts. I wonder if Mozilla will start paying attention to the password manager now that it has given up on Persona.

LastPass et al. have a lot of additional features that make a lot of sense once you accept that you'll be stuck with dozens of passwords for the foreseeable future. For example, LastPass offers to generate a random password for each site, recognizes when you change your password, helps you organize websites into categories, and alerts you to weak passwords.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#25
post #20

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

OK I'll bite ... why should I not use my browser's built in pw manager? (e.g. Safari on OS X Mavericks) I can see an argument about cross-platform use but is there another reason or reasons? thanks,

[deleted]

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#26

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

It's a bad idea to trust your secrets with a proprietary web service. Free software is a prerequisite for digital security. Best to use a free software password manager that you can run on your own computer.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#27
post #20

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

OK I'll bite ... why should I not use my browser's built in pw manager? (e.g. Safari on OS X Mavericks) I can see an argument about cross-platform use but is there another reason or reasons? thanks,

The OS X Keychain, which is used by Safari, can be cracked via John The Ripper.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#28
post #10
post #4

Notably some sites are using fresh certificates that have the same (months-in-the-past) starting-validity date as their old certificates. For example, Heroku has done this. (I can think of a few process and fee reasons this approach might be picked. Perhaps a CA might offer a free new cert and revocation, if and only if the new cert has the same validity range as the one it replaces. An ops team might prefer one cons…

We haven't found a way to do this -- we're using openssl s_client to get the start date, but one of our own certificates for LastPass.eu also reissued without changing the date so we know it's a problem. We wish we had all site's certificate fingerprints from before this started so we could utilize that data -- if anyone has it, an email to securit@lastpass.com would be greatly appreciated.

I believe if you use a new private key but sign the same CSR the dates will not change. Ideally the old certs should be revoked which should provide some info on this. I saw this explanation on the discussion of the herokuapp.com's cert's dates not changing.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#29
I wish there was (or maybe there is) a protocol for updating your password. Then managers like lastpass and 1Password could more easily update your password. Maybe, behind the scenes they could rotate your password every x days automatically. Having a protocol in place would also make breach notices an easy "update all passwords" click away.

There's probably a reason this is a bad idea. Let's hear it! :)

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#30

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

Another one to consider using is the no-frills option of Password Safe. It's designed by the man himself, Bruce Schneier.

http://passwordsafe.sourceforge.net/

Post reply on HN