I use passwords.google.com It works well with chromium on linux and on my android phone. It's free, has all the security of a google account including u2f, chromium integration is flawless on linux, and works well with chrome on Android.
LastPass: Security done wrong
121–130 of 221 posts
Re: LastPass: Security done wrong
#122http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.
Putting one's keyfile in the cloud just seems to me to be asking for it. You're essentially trusting a 3rd party with the keys to your kingdom.
B) You choose which 3rd Party to trust. There are many options with different security/trust/threat models.
(Example: lately I've been using an encrypted share in Resilio Sync where the "cloud" option for me is a dumb VPS that can share the folder torrent but does not have decryption keys into the contents.)
Re: LastPass: Security done wrong
#123Re: LastPass: Security done wrong
#124"Altogether it looks like LastPass is a lot better at PR than they are at security. Yes, that’s harsh but this is what I’ve seen so far." No, it's not harsh enough for a program that knows the right password, shows it to you, but then inputs the wrong one in the password field. Of course, compared to these security issues, such UI issues are almost irrelevant. With such a simple UI to program, you'd think they'd at l…
The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to.
Take this one for example. There's much more discussion about what works for who than the actual content of the article. And then I followed an article linked in the comment here about getting 1Password to run on Linux. And at the bottom of the article there was a link to the HackerNews thread about that article. And the situation is exactly the same.
Out of 57 comments in that thread (https://news.ycombinator.com/item?id=9091691), only four are actually related to running 1Password on Linux, and none of them is actually related to someone actually trying the method from the article and sharing his/her experience. 53/57 comments are basically "I use X because of Y".
Re: LastPass: Security done wrong
#125Earlier quoted context omitted.
Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…
copying and pasting seems to be a vulnerability..especially if you get distracted for a moment, or haven't had your coffee and paste it into your search bar.
However, losing every single password at once, without your knowledge, direct to an adversary due to a LastPass vulnerability is a much more severe problem.
Re: LastPass: Security done wrong
#126Earlier quoted context omitted.
Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…
copying and pasting seems to be a vulnerability..especially if you get distracted for a moment, or haven't had your coffee and paste it into your search bar.
Re: LastPass: Security done wrong
#127I've always been quite nervous that the LastPass two-factor authentication can be easily bypassed if your email account is compromised. On the 2FA screen there's a "If you lost your Google Authenticator device, click here to disable Google Authenticator authentication" link. No. I don't want that to be able to be disabled. I have one-time passwords for that.
Re: LastPass: Security done wrong
#128It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…
+1 Agree. Lastpass has great functionality imo, and I want a level headed analysis before I jump ship to a competitor. I do wonder though if the change in ownership last year has led to a decline in quality.
The user experience with extensions for different browsers (Chrome, Firefox, Safari) is inconsistent. Menus look and behave differently. Some options are present (and turned on by default) in one browser's extension and absent in another. For example, Firefox's extension opens the vault every time you log in unless you uncheck a box, so if you're at a password field ready to login, LastPass decides to just get in your way.
But by far the most infuriating part for me has been the iOS app. For the past few months this is what I have to go through to use it:
1.) Open app
2.) Enter password
3.) Scan fingerprint
4.) Start looking for what I want to find
5.) App logs me out after about 30 seconds for no perceivable reason
6.) Enter password
7.) Scan fingerprint
8.) I'm now logged in, but the vault is completely empty
9.) Force close the app
10.) Open the app
11.) Enter password
12.) Scan fingerprint
13.) Finally get what I want
I really do want to switch to something else, preferably self hosted, but I haven't been able to set aside the time to do the research and export/import what I have in LastPass currently.
Re: LastPass: Security done wrong
#129It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…
Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…
Sometimes I don't have my laptop with me.
Re: LastPass: Security done wrong
#130The HN community seems to be giving a lot of praise for 1Password, Lastpass and Keepass occasionally. But rarely mention Dashlane, I'm curious as to why ?
Dashlane isn't open source, nor is it available on Linux. That is going to prevent a lot of people from even considering it.