What’s in a PR statement: LastPass breach explained
111–120 of 292 posts
Re: What’s in a PR statement: LastPass breach explained
#112Earlier quoted context omitted.
What about just using chrome’s saved passwords and syncing? It would be great if someone can succinctly destroy that idea :D
Then you're stuck with Chrome forever. Same with Firefox or Safari. I wish browser vendors would agree on one password sharing protocol that's just some end-to-end encrypted blob that you could download from any browser and unlock with your password. You login to your Firefox or Google account, add passwords, and if you want to use those from the other browser you just get some http link that points to the encrypted…
Firefox, Chrome, and Edge also allow you to import passwords between browsers natively. I'm not saying that I recommend relying on the browser-based password manager (personally I use KeePassX), but I wouldn't advise against it for the reason you're describing. Just sharing some info! Please let me know if I'm mistaken on any of this.
Re: What’s in a PR statement: LastPass breach explained
#113Earlier quoted context omitted.
Same, I held onto Lastpass much longer than I would have put up with any less-essential SaaS product. Finally moved to Bitwarden and couldn't be happier. Still trying to decide if I want to self-host it or not, but more breaches of cloud-based password managers like this one may push me in that direction.
At least Bitwarden encrypts the whole vault as a blob. I don't bother self-hosting because I figure I know less about hosting a Bitwarden vault than they do so it's not much more secure. If I had a local server on my LAN I might consider it, because then at least I have a few firewalls between me and the internet. I've been a happy paying Bitwarden user for several years now, since just before the first "minor" Lastp…
Re: What’s in a PR statement: LastPass breach explained
#114I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…
Please change your domain, looks like a phishing website. I would never clic on that anywhere else on the internet.
Excuse the self-promotion, but I take it that you're also too wary to click on this link to read my blog: https://dangerous.link/virus.exe
Re: What’s in a PR statement: LastPass breach explained
#115As written in the this post, 1Password uses a randomly generated "secret key" together with the user-chosen master password. This "secret key" is not stored on 1Password's servers, instead it should be printed on a piece of paper and stored safely. While this is a good starting point, it significantly reduces usability, since you need this piece of paper when re-installing 1Password.
At heylogin, we are rethinking this cryptographic design. In our case, a random secret is generated inside the smartphone's security chip. From this secret, all keys for encryption are derived. The smartphone app and the browser extension is end-to-end encrypted and authenticated using an out-of-band QR code. This results in the following UX: To log into a website in the browser, the user needs to confirm on the phone. The app now provides the extension with temporary access to the passwords etc (a little bit more complicated to explain here).
Thus, if the same breach would happen to us, the vaults would still be secure, since the e2ee does not depend on a user chosen master password.
It's not easy to get a foot in this market, but I am confident, we can do it.
Re: What’s in a PR statement: LastPass breach explained
#116Shows the need for true multi factor. We should not have a bunch of virtual MFAs and passwords in one service even if said service make it convenient. Password managers should be held to a high standard but we should also never depend just on a password for protection of anything of value.
Re: What’s in a PR statement: LastPass breach explained
#117Earlier quoted context omitted.
I use and like it
Two questions: 1) How's it do at syncing / conflicts? 2) In the Android app, do you know if there's a way to use the fingerprint feature without storing your master password or an encrypted derivative of it to non-volatile memory? For those scratching their heads at #2, it's motivated by my lukewarm trust of vendor-implemented components of Android Keystore. Some competing apps address it by making you authenticate w…
Re: What’s in a PR statement: LastPass breach explained
#118I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…
I don't think 1Password has any free tier, at least pretty sure it doesn't have free syncing across devices anymore or even ever.
I don't know what would lead you to believe there's any syncing restriction from 1Password, but if that is your experience it's almost certainly a bug, since to the very best of my knowledge 1Password doesn't engage in hostage-taking like that
Re: What’s in a PR statement: LastPass breach explained
#119I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…
The use case is "I want an easy access "todo list" of all passwords to update that are older than (x months|specific date)"
I would use this after notification of a breach or on my own schedule. Having to manually inspect each item is not acceptable.
Bonus points if I can specify a "policy" for items (using tags and groups is acceptable if they can be incorporated into the search without too much effort). Super bonus points if the tool generates notifications and todo list automatically.
Why these features are not standard boggles the mind. LastPass used to have this feature but removed it for who-know-why reasons.
Re: What’s in a PR statement: LastPass breach explained
#120I'm not sure about the insight. But i hate the UI, UX of Lastpass. Why it's so hard to change for simplicty and ease of use ? Is it dark pattern, is it technically impossible due to technical architectural complexity, or tech debt,.. ? At least the UI tells me something about the internal.
No idea what you're talking about. I manage LastPass for 200 not very tech savvy users and no one has any problems using it.
I’ve trained 3-4 non-technical users on LastPass and none of them found it intuitive or easy.
I’ve managed it in a corporate environment for dozens of users who were younger and more tech savvy, for them it was mostly okay.