Live data from Hacker News

LastPass Now Checks If Your Sites Are Affected by Heartbleed

blog.lastpass.com

41–50 of 94 posts

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#41

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

It's a bad idea to trust your secrets with a proprietary web service. Free software is a prerequisite for digital security. Best to use a free software password manager that you can run on your own computer.

And what do I do when I have 3 or 4 devices? Home desktop, work desktop, laptop, tablet, etc?

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#42
post #16

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

I use Dashlane and its been great! Surprised not seeing too much support for it around here...

Just taking a guess but the lack of Linux support might be the culprit.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#43

Earlier quoted context omitted.

It's a bad idea to trust your secrets with a proprietary web service. Free software is a prerequisite for digital security. Best to use a free software password manager that you can run on your own computer.

And what do I do when I have 3 or 4 devices? Home desktop, work desktop, laptop, tablet, etc?

Couple options

1) Dropbox

2) USB stick

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#45

This is very cool and answers my, and i'm pretty sure many other's questions about what passwords are safe to change. Thanks guys!

If I were you, I would change ALL of your passwords. Regardless of what lastpass says.

The point is, there's no point changing them until the site fixes their certificates.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#47

Earlier quoted context omitted.

It's a bad idea to trust your secrets with a proprietary web service. Free software is a prerequisite for digital security. Best to use a free software password manager that you can run on your own computer.

And what do I do when I have 3 or 4 devices? Home desktop, work desktop, laptop, tablet, etc?

I keep my KeePass database synced between devices using a Dropbox-like service that I self-host, so the file is never out of my control. But even if someone grabs the database off my machine or in transit, it's no good if they don't know my master password.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#48

I wish there was (or maybe there is) a protocol for updating your password. Then managers like lastpass and 1Password could more easily update your password. Maybe, behind the scenes they could rotate your password every x days automatically. Having a protocol in place would also make breach notices an easy "update all passwords" click away. There's probably a reason this is a bad idea. Let's hear it! :)

there are some obvious discouragements, as outlined by grrowl in another comment, but I agree with you that it would be nice. Security and convenience have a well known relationship.

I've thought it would be nice to consolidate 2-factor authentication methods in a single service, then require a single, 2nd factor authenticator for access to the service or vault. So a yubi-key like authenticator with your lastpass that then authenticates using 2-factor protocols of some sort automatically; again, trading security for convenience, but would also allow for things like auto-changing of all passwords (which happening more often couldn't hurt security) while still under protection of a 2-factor authentication.

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#49

Earlier quoted context omitted.

It's a bad idea to trust your secrets with a proprietary web service. Free software is a prerequisite for digital security. Best to use a free software password manager that you can run on your own computer.

And what do I do when I have 3 or 4 devices? Home desktop, work desktop, laptop, tablet, etc?

KeePass ftp sync, or what sliverstorm said

Re: LastPass Now Checks If Your Sites Are Affected by Heartbleed

#50
post #20

I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others? Edit just to say I think this is a very nice feature by LastPass and thanks for posting.

OK I'll bite ... why should I not use my browser's built in pw manager? (e.g. Safari on OS X Mavericks) I can see an argument about cross-platform use but is there another reason or reasons? thanks,

This is why: http://raidersec.blogspot.com/2013/06/how-browsers-store-you...

TL;DR Firefox with a strong master password was considered safe at the time of that article's writing (June 2013). That + Firefox Sync is what I use - I would also be interested in anything more up to date on why this is or isn't a good idea.

Post reply on HN