Live data from Hacker News

LastPass: Security done wrong

palant.de

111–120 of 221 posts

Re: LastPass: Security done wrong

#111

I am almost ready to file a lawsuit. Context: What I am after is a password manager that has the option to NOT store anything in the cloud at all. I want encrypted storage to be stored locally. No exposure outside my network. Inter-device synchronization done manually or automatically within the confines of said private network. I would also like to store data beyond uid's and pwd's. For example: secret questions and…

Have you looked at https://1password.com/? And it looks like https://www.enpass.io/ has similar capabilities, but I don't use it so I'm not sure exactly.

1Password keeps a local encrypted file. The "integrations" are 1Password knowing default locations to look to store the file in the right directory.

Re: LastPass: Security done wrong

#112

Earlier quoted context omitted.

Would love to hear from someone who has an iPhone and uses Keepass or a derivative. That's my last barrier to using it.

I do. I use the MiniKeePass app, which is free. You can export your KeePass database (.kdbx) from the Dropbox app to MiniKeePass.

Ditto. It doesn't make for a good _write_ experience, since you have to copy back to Dropbox manually, but I find that I almost exclusively _read_ passwords, so it's a non-issue for my use case.

Re: LastPass: Security done wrong

#113
post #55

http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.

You can also add in KeepassHttp + PassIFox. But I wonder if these might have similar vulnerabilities as they too would be handling decrypted passwords.

True, but there are a slew of security issues (and unknowns) with KeePassHttp: https://github.com/pfn/keepasshttp/issues/258 https://github.com/keepassxreboot/keepassxc/issues/147

I've been looking for a alternative with somewhat parity with lastpass with a better security policy.

Re: LastPass: Security done wrong

#114
post #79

It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager?

This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing said API. Other products may be less bug ridden, but they share the same risk vector.

I use pass[1], and I recommend it if you can stand copying and pasting. It's really not much of an inconvenience for the dramatic increase in security you get.

[1]: https://www.passwordstore.org/

Re: LastPass: Security done wrong

#115
post #19

I wonder if 1Password is equally susceptible or less so, due to the way that the extension works. Because 1Password has a native application, I believe the browser extensions merely communicate with the native application to retrieve passwords to fill when needed, instead of handling your whole decrypted vault.

I only had a quick look at 1Password browser extensions source code but there were no obvious red flags - much unlike LastPass. Let's see what Tavis Ormandy digs up, supposedly he found some issues.

Re: LastPass: Security done wrong

#116

http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.

Putting one's keyfile in the cloud just seems to me to be asking for it. You're essentially trusting a 3rd party with the keys to your kingdom.

No. You're trusting the encryption of the password manager. No self-hosted password manager that I know of keeps your passwords in a clear text file.

Re: LastPass: Security done wrong

#117
post #40

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

Dashlane does! Been using it for a year or so. Good experience. https://csdashlane.zendesk.com/hc/en-us/articles/202699141-H...

I love Dashlane, it's pretty magical and a massive timesaver. I use it on OSX primarily but it syncs to my Android very well.

There's an unfixed bug in the OSX client where it crashes rarely (every couple months for me) and I have to kill the process manually and restart, but it has very minor impact.

Is there any security analysis or consensus on Dashlane security vs. other password managers?

Re: LastPass: Security done wrong

#118
post #109
post #79

It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…

Thank you for the reminder, I added the disclaimer noting that I develop Easy Passwords. The claim that vulnerabilities still exist was unsourced six months ago - now you have proof that they do. It would be naive to assume that this was the last of them. As I explained several times already, the issue is a structural one. LastPass keeps the attack surface unnecessarily large and they are pretty bad at securing it. T…

Awesome, thank you!

Re: unsourced vulnerabilities, only complaining about my own ability to know what that means, not questioning the validity. Yes, reports always start unsourced, necessarily.

Re: LastPass: Security done wrong

#119

I am almost ready to file a lawsuit. Context: What I am after is a password manager that has the option to NOT store anything in the cloud at all. I want encrypted storage to be stored locally. No exposure outside my network. Inter-device synchronization done manually or automatically within the confines of said private network. I would also like to store data beyond uid's and pwd's. For example: secret questions and…

KeePass is a free as in freetard application that doesn't have any sort of cloud capabilities.

Re: LastPass: Security done wrong

#120
post #114
post #79

It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

copying and pasting seems to be a vulnerability..especially if you get distracted for a moment, or haven't had your coffee and paste it into your search bar.
Post reply on HN