Live data from Hacker News

Security Issues with LastPass on Android

abhyudaya.dev

11–20 of 64 posts

Re: Security Issues with LastPass on Android

#11
I dumped lastpass when they started forcing free accounts to choose between desktop and mobile. I had been considering paying for a family account, but trying to force me to do it by removing features was unacceptable. Because of this, lastpass will never see a dime from me and another company will have the opportunity to serve me.

Re: Security Issues with LastPass on Android

#12
post #11

I dumped lastpass when they started forcing free accounts to choose between desktop and mobile. I had been considering paying for a family account, but trying to force me to do it by removing features was unacceptable. Because of this, lastpass will never see a dime from me and another company will have the opportunity to serve me.

> I had been considering paying for a family account

Your consideration doesn't pay for dev time. No one cares about pushing free users or 'considering' users off the platform at monetization time. Shit or get off the pot.

That said, no one blames you for doing comparison shopping at monetization time either.

Re: Security Issues with LastPass on Android

#13
post #12
post #11

I dumped lastpass when they started forcing free accounts to choose between desktop and mobile. I had been considering paying for a family account, but trying to force me to do it by removing features was unacceptable. Because of this, lastpass will never see a dime from me and another company will have the opportunity to serve me.

> I had been considering paying for a family account Your consideration doesn't pay for dev time. No one cares about pushing free users or 'considering' users off the platform at monetization time. Shit or get off the pot. That said, no one blames you for doing comparison shopping at monetization time either.

>Your consideration doesn't pay for dev time.

But rather than asking users to pay for newly developed premium functionality, they asked long term users to pay for things that they already had and had always been provided for free.

>Shit or get off the pot.

In this metaphor, they started charging people for using a previously freely accessible pot while they were in mid-shit.

Re: Security Issues with LastPass on Android

#14
post #12

Earlier quoted context omitted.

> I had been considering paying for a family account Your consideration doesn't pay for dev time. No one cares about pushing free users or 'considering' users off the platform at monetization time. Shit or get off the pot. That said, no one blames you for doing comparison shopping at monetization time either.

>Your consideration doesn't pay for dev time. But rather than asking users to pay for newly developed premium functionality, they asked long term users to pay for things that they already had and had always been provided for free. >Shit or get off the pot. In this metaphor, they started charging people for using a previously freely accessible pot while they were in mid-shit.

> had always been provided for free

IIRC, mobile usage _was not_ free, but later became free.

Re: Security Issues with LastPass on Android

#15
post #2

That's very interesting. I would love to read this student's paper once it comes out.

Hi! I am the author of this post. Thanks a lot for your feedback! I hope to make it public very soon.

Please let us know when/where you do! This is really cool :D

Re: Security Issues with LastPass on Android

#17

Earlier quoted context omitted.

Thats right, we should blame the victim for trusting the tool. Password managers are increasingly mandated by organisations, and Lastpass is a very common recommendation. Even in the minority of technical users that use this kind of tool I expect small mistakes - like accidentally pasting a password in a URL. A good tool doesn't let you shoot yourself in the foot by escalting that to a non-obvious leak. The password…

Most people realize they can hurt themselves if they use a hammer wrong. If someone can be expected to put four years of their life into a degree or prepatory trade training they can be held accountable for not caring enough to spend 10 minutes reading about effective use of their password manager.

That's not the reality though. The current wisdom in security seems to be to follow reality. To eliminate shooting foots by both users and developers. See NaCl crypto library, libsodium, Noise protocol, Signal app, Tarsnap and restic, Brian Warner's magic-wormhole, Signify/Minisign, Filippo Valsorda's 'age', WireGuard.

Are there more?

Re: Security Issues with LastPass on Android

#18
post #12
post #11

I dumped lastpass when they started forcing free accounts to choose between desktop and mobile. I had been considering paying for a family account, but trying to force me to do it by removing features was unacceptable. Because of this, lastpass will never see a dime from me and another company will have the opportunity to serve me.

> I had been considering paying for a family account Your consideration doesn't pay for dev time. No one cares about pushing free users or 'considering' users off the platform at monetization time. Shit or get off the pot. That said, no one blames you for doing comparison shopping at monetization time either.

Removing features to force conversion is a shady practice and I want no part in a company that finds this acceptable. If they find this acceptable, there is nothing preventing them from doing this again when I am not premium enough. I would rather shit in a pot that won't disable my ability to clean up after I have started.

Re: Security Issues with LastPass on Android

#19

Earlier quoted context omitted.

>Your consideration doesn't pay for dev time. But rather than asking users to pay for newly developed premium functionality, they asked long term users to pay for things that they already had and had always been provided for free. >Shit or get off the pot. In this metaphor, they started charging people for using a previously freely accessible pot while they were in mid-shit.

> had always been provided for free IIRC, mobile usage _was not_ free, but later became free.

It was free when I signed up.

Re: Security Issues with LastPass on Android

#20

Earlier quoted context omitted.

Too short passwords being generated sounds like an issue that IMO violates user expectations, the other two do not.

Hi! I am the author of this post. I think that taking the user to `www.foobar.com` when he/she typed `foobar` does violate the expectations for most users. All browsers which I've used take the user to their selected search engine. Most people outside of HN do not know that what they type in that search bar would be visible to anyone listening on the wire.

It's funny how this expectation had changed over time. In early browsers like Mosaic and Netscape, the expectation was that you'd enter a domain name or full URL and there would be a DNS query. When newer browsers incorporated search into the address bar, many of us considered this to be leaking information to search providers. For quite a while I disabled that feature.
Post reply on HN