Thoughts on LastPass vs 1Password?
LastPass Security Notice
11–20 of 311 posts
Re: LastPass Security Notice
#12If you don't use a password manager, you've got 99 problems, but a centralized store of your credentials for everything that's a huge target by virtue of having thousands of similarly centralized users ain't one.
Using a password manager (good idea) and then storing all your passwords on a 3rd party service of which you have no control seems inherently risky. Lastpass is a huge target, and while I believe they generally take reasonable security measures, for many the risk of compromise may be greater than an encrypted stand-alone password database. Use a password manager, please, but keep it offline and don't aggregate it with loads of other people's databases.
This is one area where I feel strongly that the conveniences of 'Cloud' are outweighed by the risks.
Re: LastPass Security Notice
#13Re: LastPass Security Notice
#14Thoughts on LastPass vs 1Password?
For company wide use, LastPass Enterprise is a better fit. Centralized management is essential when dealing with larger numbers of not particularly tech savvy and security conscious users.
And despite this incident, I trust a specialized operation like Lastpass more with keeping the data secure 24/7 than myself or company IT.
Re: LastPass Security Notice
#15Oh great, just the day before yesterday I finally jumped to LastPass (because obviously WinKee is not compatible to my new Lumia phone), using my best password (long, no real syllables, memorized). It sounds like the password is still safe enough, but it's a very unfortunate, inconvenient timing indeed.
Try 1Password.
OTOH I'm not terribly sold on LastPass's UI, either.
I don't know, but I'm going to sleep a few days over it and check out my options on the weekend. This isn't an "everything's on fire" event, anyway.
Re: LastPass Security Notice
#16Thoughts on LastPass vs 1Password?
Re: LastPass Security Notice
#17While LastPass seems to be responding well, I find their entire service exceeds my tolerance for risk. If you don't use a password manager, you've got 99 problems, but a centralized store of your credentials for everything that's a huge target by virtue of having thousands of similarly centralized users ain't one. Using a password manager (good idea) and then storing all your passwords on a 3rd party service of which…
Although I share you discomfort, looking at it rationally I prefer to trust a specialized service, who's very existence and reputation depends on it, more than the alternatives.
The other alternative for sharing is stuff like 1Password over Dropbox, which is imho the worst of both worlds.
Re: LastPass Security Notice
#18While LastPass seems to be responding well, I find their entire service exceeds my tolerance for risk. If you don't use a password manager, you've got 99 problems, but a centralized store of your credentials for everything that's a huge target by virtue of having thousands of similarly centralized users ain't one. Using a password manager (good idea) and then storing all your passwords on a 3rd party service of which…
Maybe if there was a way to deploy our own personal password manager server on a dedicated server that would help the "one big target" issue.
Re: LastPass Security Notice
#19While LastPass seems to be responding well, I find their entire service exceeds my tolerance for risk. If you don't use a password manager, you've got 99 problems, but a centralized store of your credentials for everything that's a huge target by virtue of having thousands of similarly centralized users ain't one. Using a password manager (good idea) and then storing all your passwords on a 3rd party service of which…
STRIP supports mobile-desktop synchronization over local wifi or remote cloud (Dropbox & Gdrive).
Re: LastPass Security Notice
#20I don't use LastPass, but one thing that impresses me about their blog post: they didn't hide behind "your passwords are hashed" or something equally weaselly, but instead said exactly and clearly how passwords are hashed. Every online company should take note.
I'm reading this as an embarrassing security lapse in general security, so they misdirect by talking in depth about password hashing.