Live data from Hacker News

LastPass: Security done wrong

palant.de

11–20 of 221 posts

Re: LastPass: Security done wrong

#13
post #8
post #5

Earlier quoted context omitted.

I used 1Password for quite a long time but have since switched to LastPass mostly due to Linux compatibility and u2f integration

LastPass does not have u2f yet, do you mean 2Fa? They have Yubi Cloud, but not u2f.

My mistake, yes, 2fa

Re: LastPass: Security done wrong

#14
Commentary / Opinions on how this compares to a KeePass+DropBox solution would be quite interesting to me.

It seems password managers please some of the people some of the time, and unnerve many of the people all of the time.

Re: LastPass: Security done wrong

#15
post #5
post #3

Interested to hear what the HN community thinks about 1Password

I used 1Password for quite a long time but have since switched to LastPass mostly due to Linux compatibility and u2f integration

1password's Windows version does run under Wine, including the browser extension. It's been a while since I did it, but I think there was some sort of browser extension validation feature that had to be disabled. Not 100% up to the security standards of their other platforms, but it's functional.

Re: LastPass: Security done wrong

#17
I used it (1P) and it was super, but mac only - no Linux client. Just switched over to Enpass, and its very like 1Password, only they do provide a linux client. So far its great, very happy with it. * reply to comment above re 1Password

Re: LastPass: Security done wrong

#18

Commentary / Opinions on how this compares to a KeePass+DropBox solution would be quite interesting to me. It seems password managers please some of the people some of the time, and unnerve many of the people all of the time.

I use KeePass+SFTP personally. Something like a password manager I won't trust to a cloud service.

Re: LastPass: Security done wrong

#19
I wonder if 1Password is equally susceptible or less so, due to the way that the extension works. Because 1Password has a native application, I believe the browser extensions merely communicate with the native application to retrieve passwords to fill when needed, instead of handling your whole decrypted vault.

Re: LastPass: Security done wrong

#20
post #17

I used it (1P) and it was super, but mac only - no Linux client. Just switched over to Enpass, and its very like 1Password, only they do provide a linux client. So far its great, very happy with it. * reply to comment above re 1Password

1Password is different from LastPass; the article is about the latter.
Post reply on HN