Live data from Hacker News

LastPass Finds Security Holes In Its Online Password Manager

blog.lastpass.com

11–16 of 16 posts

Re: LastPass Finds Security Holes In Its Online Password Manager

#11
post #3

While this news is a little worrisome, I view LastPass as a "better than what I'd do otherwise" solution, not a "perfect" solution. I no longer use my small set of short, easy-to-remember passwords over and over again across multiple sites. Now most of my passwords are long random strings that I don't even know. The overall increase to my average security offsets the downsides of having a centralized target for attac…

> I view LastPass as a "better than what I'd do otherwise" solution Do you think it's better than, say, using a desktop-based password manager to save passwords to an encrypted file, and then syncing that file to all your machines via Dropbox?

I also use 1Password, which syncs its password database file via Dropbox. Either one is a better alternative than reusing the same easy-to-remember passwords.

Re: LastPass Finds Security Holes In Its Online Password Manager

#13
post #12

Somehow, this poor writeup of LastPass's disclosure is ranking higher than the original post, which predates it on the site: https://news.ycombinator.com/item?id=8022543

Yes. We'll change the url from [1], which points to this. Unfortunately, we don't yet have a way to do any better than that. But see [2] for two things we're working on that will help in these situations.

1. http://techcrunch.com/2014/07/11/lastpass-finds-security-hol...

2. https://news.ycombinator.com/item?id=8016584

Re: LastPass Finds Security Holes In Its Online Password Manager

#14
What do you guys use to store GPG and SSH keys passphrases? Your GPG can be your most valuable stuff. Remembering passphrase of several subkeys seems impossible. The only two passwords I remember are Google Account and LastPass. I could probably remember GPG Master key passphrase but do you think it could also be saved in LastPass.

Re: LastPass Finds Security Holes In Its Online Password Manager

#15
The headline is fearmongery: While the security holes are real, they concern not the security of persistent site-specific passwords but of a) bookmarklets, used by less than 1% of their user base, and b) of one-time passwords (OTPs).

I've been using LastPass for over a year on multiple platforms and many, many sites and didn't even know those features existed....

As written, the headline makes it seem that perhaps, just perhaps, persistent password storage is at risk. Now THAT would freak me out.

But the current news is, for me and many users, nothing to see here, please move along.

Responsible disclosure yes, excellence in headline writing not so much.

Re: LastPass Finds Security Holes In Its Online Password Manager

#16
post #3

While this news is a little worrisome, I view LastPass as a "better than what I'd do otherwise" solution, not a "perfect" solution. I no longer use my small set of short, easy-to-remember passwords over and over again across multiple sites. Now most of my passwords are long random strings that I don't even know. The overall increase to my average security offsets the downsides of having a centralized target for attac…

> I view LastPass as a "better than what I'd do otherwise" solution Do you think it's better than, say, using a desktop-based password manager to save passwords to an encrypted file, and then syncing that file to all your machines via Dropbox?

Used to use lastpass but I've found KeePass & KeeFox (firefox Addon) to be just as sufficient for daily use. Just as usable as lastpass and you have much more options for syncing data you know you own and isn't apart of a juicy targeted password database.
Post reply on HN