Live data from Hacker News

LastPass: Security done wrong

palant.de

121–130 of 221 posts

Re: LastPass: Security done wrong

#121
post #88

I use passwords.google.com It works well with chromium on linux and on my android phone. It's free, has all the security of a google account including u2f, chromium integration is flawless on linux, and works well with chrome on Android.

How long has this been around?

Re: LastPass: Security done wrong

#122

http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.

Putting one's keyfile in the cloud just seems to me to be asking for it. You're essentially trusting a 3rd party with the keys to your kingdom.

A) You should presumably still have a good passphrase.

B) You choose which 3rd Party to trust. There are many options with different security/trust/threat models.

(Example: lately I've been using an encrypted share in Resilio Sync where the "cloud" option for me is a dumb VPS that can share the folder torrent but does not have decryption keys into the contents.)

Re: LastPass: Security done wrong

#124
post #77

"Altogether it looks like LastPass is a lot better at PR than they are at security. Yes, that’s harsh but this is what I’ve seen so far." No, it's not harsh enough for a program that knows the right password, shows it to you, but then inputs the wrong one in the password field. Of course, compared to these security issues, such UI issues are almost irrelevant. With such a simple UI to program, you'd think they'd at l…

> If it takes someone with expert skills in computers almost a year to find a good password manager program, not to mention days worth of work importing into and testing various solutions, what chance does your everyday computer user stand?

The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to.

Take this one for example. There's much more discussion about what works for who than the actual content of the article. And then I followed an article linked in the comment here about getting 1Password to run on Linux. And at the bottom of the article there was a link to the HackerNews thread about that article. And the situation is exactly the same.

Out of 57 comments in that thread (https://news.ycombinator.com/item?id=9091691), only four are actually related to running 1Password on Linux, and none of them is actually related to someone actually trying the method from the article and sharing his/her experience. 53/57 comments are basically "I use X because of Y".

Re: LastPass: Security done wrong

#125
post #114

Earlier quoted context omitted.

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

copying and pasting seems to be a vulnerability..especially if you get distracted for a moment, or haven't had your coffee and paste it into your search bar.

It's a risk, albeit a small one. Individual passwords are easy to change if compromised. I have personally never miscopied them. Both pass and KeePass will automatically clear your clipboard a little while after copying the password.

However, losing every single password at once, without your knowledge, direct to an adversary due to a LastPass vulnerability is a much more severe problem.

Re: LastPass: Security done wrong

#126
post #114

Earlier quoted context omitted.

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

copying and pasting seems to be a vulnerability..especially if you get distracted for a moment, or haven't had your coffee and paste it into your search bar.

[deleted]

Re: LastPass: Security done wrong

#127
post #62

I've always been quite nervous that the LastPass two-factor authentication can be easily bypassed if your email account is compromised. On the 2FA screen there's a "If you lost your Google Authenticator device, click here to disable Google Authenticator authentication" link. No. I don't want that to be able to be disabled. I have one-time passwords for that.

You can configure quite a lot of stuff in the 2Fa settings. I have no such option for my 2Fa on Lastpass. Also, my E-Mail also has a 2Fa.

Re: LastPass: Security done wrong

#128
post #79

It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…

+1 Agree. Lastpass has great functionality imo, and I want a level headed analysis before I jump ship to a competitor. I do wonder though if the change in ownership last year has led to a decline in quality.

Anecdotal and personal opinion, but I believe that it has. I've been a LastPass user since February 2014. I used to pay for the annual subscription because it was required to use their phone apps, but now that it isn't I find no benefit to the paid subscription, especially given how poorly some thing seem to be working.

The user experience with extensions for different browsers (Chrome, Firefox, Safari) is inconsistent. Menus look and behave differently. Some options are present (and turned on by default) in one browser's extension and absent in another. For example, Firefox's extension opens the vault every time you log in unless you uncheck a box, so if you're at a password field ready to login, LastPass decides to just get in your way.

But by far the most infuriating part for me has been the iOS app. For the past few months this is what I have to go through to use it:

1.) Open app

2.) Enter password

3.) Scan fingerprint

4.) Start looking for what I want to find

5.) App logs me out after about 30 seconds for no perceivable reason

6.) Enter password

7.) Scan fingerprint

8.) I'm now logged in, but the vault is completely empty

9.) Force close the app

10.) Open the app

11.) Enter password

12.) Scan fingerprint

13.) Finally get what I want

I really do want to switch to something else, preferably self hosted, but I haven't been able to set aside the time to do the research and export/import what I have in LastPass currently.

Re: LastPass: Security done wrong

#129
post #114
post #79

It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

I would love to use pass but I can't figure out a decent way of getting it on my iPhone.

Sometimes I don't have my laptop with me.

Re: LastPass: Security done wrong

#130
post #65

The HN community seems to be giving a lot of praise for 1Password, Lastpass and Keepass occasionally. But rarely mention Dashlane, I'm curious as to why ?

Dashlane isn't open source, nor is it available on Linux. That is going to prevent a lot of people from even considering it.

Lastpass / 1Password are not open source either.
Post reply on HN