Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

11–20 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#11
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

Why not use OneDrive to keep your files synced? That's what I do with keepass

Re: What’s in a PR statement: LastPass breach explained

#12

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

I’d be curious to know which one you personally use given all the research into the topic?

Re: What’s in a PR statement: LastPass breach explained

#14
Shows the need for true multi factor. We should not have a bunch of virtual MFAs and passwords in one service even if said service make it convenient.

Password managers should be held to a high standard but we should also never depend just on a password for protection of anything of value.

Re: What’s in a PR statement: LastPass breach explained

#15

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

I don't see any mention of local vaults on the page.

Is there any password manager out there besides keepass that isn't cloud based?

Re: What’s in a PR statement: LastPass breach explained

#16

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

Great overview! I think 1Password's Linux support has been improving [0]. I use 1Password with an Ubuntu desktop and have been happy with it. [0]: https://support.1password.com/explore/linux/

agreed. linux desktop is absolutely fine for me.

Re: What’s in a PR statement: LastPass breach explained

#17

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

Thanks for posting this. I was about to post an "Ask HN" to see what password managers people here are using, but this seems very helpful to compare the various services.

Re: What’s in a PR statement: LastPass breach explained

#18
I'm really curious what people in the know have to say about PM's in general and what the good options are.

I personally really love having an in-browser password manager. It's an incredible convenience and it lets every service have a unique and nearly impossible to crack password.

I have far too many services to remember them all, and using the same password for everything would be terrible.

But of course I see the risk of having "one password to rule them all" and putting so much faith in one service. If it fails, losing everything is possible.

I don't mind paying of course if there's a reason to, though for now the free version of Bitwarden has been fine for years.

Re: What’s in a PR statement: LastPass breach explained

#19
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access.

Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm.

How would KeyPass deal with the same type of situation?

Post reply on HN