Live data from Hacker News

LastPass: Security done wrong

palant.de

101–110 of 221 posts

Re: LastPass: Security done wrong

#101

http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.

Would love to hear from someone who has an iPhone and uses Keepass or a derivative. That's my last barrier to using it.

I do. I use the MiniKeePass app, which is free. You can export your KeePass database (.kdbx) from the Dropbox app to MiniKeePass.

Re: LastPass: Security done wrong

#102
post #91

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

I use bitwarden. It's open source and works in browser and on phone. I haven't done any auditing myself, so I guess it's a leap of faith in that regard, but it's working great thus far. It can import from a lastpass file. Even though it's open source, there is a hosted instance (so the experience is much like lastpass). There was a kickstarter a while back that failed though, so I'm unsure how it's funded.

> There was a kickstarter a while back that failed though, so I'm unsure how it's funded.

The lead developer answered that here:

https://news.ycombinator.com/item?id=13926031

Re: LastPass: Security done wrong

#103
post #3

Interested to hear what the HN community thinks about 1Password

I like it. I'd give them a 10/10 if they'd offer a Linux client, too. An official API would be nice as well.

The database format is open, and there are linux tools for it:

http://www.lucianofiandesio.com/1password-in-linux

Re: LastPass: Security done wrong

#104
Not sure how people like online password managers. The consequence will be far worse than selling your online attitude to Google by using their online services in case of a security breach. It pretty much gives your online self up to hackers.

With that said, I only use offline managers and this is only for Mac but Locko by Binarynights is clean and easy to use. The downside is that it's browser extension can't remember basic auth credentials but other than that I like it. I can also back up the encrypted database easily with a script.

(Seems the link is gone from their site with the release of forklift3 but the page still exists. http://www.binarynights.com/locko/ )

Re: LastPass: Security done wrong

#105
post #65

The HN community seems to be giving a lot of praise for 1Password, Lastpass and Keepass occasionally. But rarely mention Dashlane, I'm curious as to why ?

I used to be a Dashlane user. It just got worse and worse over time, the password sharing was incredibly buggy. Their support would always give me excuses and never have fixes. It got to be a nightmare. I switched to 1Password and love it.

Honestly surprised there aren't more players in this space but it seems really hard to get into.

Re: LastPass: Security done wrong

#106

I am almost ready to file a lawsuit. Context: What I am after is a password manager that has the option to NOT store anything in the cloud at all. I want encrypted storage to be stored locally. No exposure outside my network. Inter-device synchronization done manually or automatically within the confines of said private network. I would also like to store data beyond uid's and pwd's. For example: secret questions and…

They don't make it obvious, but 1Password still offers a standalone version on Windows/macOS. And KeePassX allows you to manage your own synchronisation.

Re: LastPass: Security done wrong

#107
post #79

It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…

+1 Agree. Lastpass has great functionality imo, and I want a level headed analysis before I jump ship to a competitor. I do wonder though if the change in ownership last year has led to a decline in quality.

FWIW I manage a couple Lastpass Enterprise installs and I haven't seen any indicators of a reduction in quality.

Even @taviso had this (positive) follow up tweet: https://twitter.com/taviso/status/844574176165822465

Re: LastPass: Security done wrong

#108

http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.

Putting one's keyfile in the cloud just seems to me to be asking for it. You're essentially trusting a 3rd party with the keys to your kingdom.

Re: LastPass: Security done wrong

#109
post #79

It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…

Thank you for the reminder, I added the disclaimer noting that I develop Easy Passwords.

The claim that vulnerabilities still exist was unsourced six months ago - now you have proof that they do. It would be naive to assume that this was the last of them. As I explained several times already, the issue is a structural one. LastPass keeps the attack surface unnecessarily large and they are pretty bad at securing it.

The recent vulnerability reported was particularly bad, launching an arbitrary external application is really as bad as it goes - this could have resulted in a malware infestation. But the typical threat is "merely" losing all your LastPass data to a random website you are visiting (or a hacked ad script running on it).

How likely it is that bad guys will actually try to target LastPass? They seem to have at least 10 million users judging by AMO and Chrome Web Store numbers. I can clearly see that on some websites trying to exploit LastPass users can actually be lucrative. Whether it will happen to you personally, nobody can tell of course.

Re: LastPass: Security done wrong

#110

Earlier quoted context omitted.

+1 Agree. Lastpass has great functionality imo, and I want a level headed analysis before I jump ship to a competitor. I do wonder though if the change in ownership last year has led to a decline in quality.

FWIW I manage a couple Lastpass Enterprise installs and I haven't seen any indicators of a reduction in quality. Even @taviso had this (positive) follow up tweet: https://twitter.com/taviso/status/844574176165822465

yup. I checked my LastPass extension and it had updated and needed a browser restart.
Post reply on HN