http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.
Would love to hear from someone who has an iPhone and uses Keepass or a derivative. That's my last barrier to using it.
LastPass: Security done wrong
101–110 of 221 posts
Re: LastPass: Security done wrong
#102Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?
I use bitwarden. It's open source and works in browser and on phone. I haven't done any auditing myself, so I guess it's a leap of faith in that regard, but it's working great thus far. It can import from a lastpass file. Even though it's open source, there is a hosted instance (so the experience is much like lastpass). There was a kickstarter a while back that failed though, so I'm unsure how it's funded.
The lead developer answered that here:
Re: LastPass: Security done wrong
#103Interested to hear what the HN community thinks about 1Password
I like it. I'd give them a 10/10 if they'd offer a Linux client, too. An official API would be nice as well.
Re: LastPass: Security done wrong
#104With that said, I only use offline managers and this is only for Mac but Locko by Binarynights is clean and easy to use. The downside is that it's browser extension can't remember basic auth credentials but other than that I like it. I can also back up the encrypted database easily with a script.
(Seems the link is gone from their site with the release of forklift3 but the page still exists. http://www.binarynights.com/locko/ )
Re: LastPass: Security done wrong
#105The HN community seems to be giving a lot of praise for 1Password, Lastpass and Keepass occasionally. But rarely mention Dashlane, I'm curious as to why ?
Honestly surprised there aren't more players in this space but it seems really hard to get into.
Re: LastPass: Security done wrong
#106I am almost ready to file a lawsuit. Context: What I am after is a password manager that has the option to NOT store anything in the cloud at all. I want encrypted storage to be stored locally. No exposure outside my network. Inter-device synchronization done manually or automatically within the confines of said private network. I would also like to store data beyond uid's and pwd's. For example: secret questions and…
Re: LastPass: Security done wrong
#107It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…
+1 Agree. Lastpass has great functionality imo, and I want a level headed analysis before I jump ship to a competitor. I do wonder though if the change in ownership last year has led to a decline in quality.
Even @taviso had this (positive) follow up tweet: https://twitter.com/taviso/status/844574176165822465
Re: LastPass: Security done wrong
#108http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.
Re: LastPass: Security done wrong
#109It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…
The claim that vulnerabilities still exist was unsourced six months ago - now you have proof that they do. It would be naive to assume that this was the last of them. As I explained several times already, the issue is a structural one. LastPass keeps the attack surface unnecessarily large and they are pretty bad at securing it.
The recent vulnerability reported was particularly bad, launching an arbitrary external application is really as bad as it goes - this could have resulted in a malware infestation. But the typical threat is "merely" losing all your LastPass data to a random website you are visiting (or a hacked ad script running on it).
How likely it is that bad guys will actually try to target LastPass? They seem to have at least 10 million users judging by AMO and Chrome Web Store numbers. I can clearly see that on some websites trying to exploit LastPass users can actually be lucrative. Whether it will happen to you personally, nobody can tell of course.
Re: LastPass: Security done wrong
#110Earlier quoted context omitted.
+1 Agree. Lastpass has great functionality imo, and I want a level headed analysis before I jump ship to a competitor. I do wonder though if the change in ownership last year has led to a decline in quality.
FWIW I manage a couple Lastpass Enterprise installs and I haven't seen any indicators of a reduction in quality. Even @taviso had this (positive) follow up tweet: https://twitter.com/taviso/status/844574176165822465