Live data from Hacker News

LastPass: Security done wrong

palant.de

131–140 of 221 posts

Re: LastPass: Security done wrong

#131

Earlier quoted context omitted.

+1 Agree. Lastpass has great functionality imo, and I want a level headed analysis before I jump ship to a competitor. I do wonder though if the change in ownership last year has led to a decline in quality.

FWIW I manage a couple Lastpass Enterprise installs and I haven't seen any indicators of a reduction in quality. Even @taviso had this (positive) follow up tweet: https://twitter.com/taviso/status/844574176165822465

Frankly, I cannot really understand him being positive about that. A vendor that rushes out a fix without verifying that they fixed the issue everywhere - that's not great at all. I definitely prefer vendors who take a few days to look at the issue properly. But then again, if LastPass did this they would have addressed the issues back in August last year at the latest and I would have nothing to write about.

Re: LastPass: Security done wrong

#132
post #114

Earlier quoted context omitted.

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

copying and pasting seems to be a vulnerability..especially if you get distracted for a moment, or haven't had your coffee and paste it into your search bar.

If you paste a long, random password in your search bar, what's going to happen in the time between then and changing it?

Re: LastPass: Security done wrong

#133
post #114

Earlier quoted context omitted.

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

I would love to use pass but I can't figure out a decent way of getting it on my iPhone. Sometimes I don't have my laptop with me.

Haven't used it, but it looks like there are a few apps for iOS: https://mssun.github.io/passforios/

KeePass is a good solution, too. It also has iOS apps.

Re: LastPass: Security done wrong

#134
post #29

Earlier quoted context omitted.

I signed my family up for 1Password a month ago and love it so far. Here's the 1Password Security Design Whitepaper: https://1password.com/files/1Password%20for%20Teams%20White%...

1Password has no Linux support so it's not really a drop in replacement. Android autofill functionality is also significantly worse.

I use their webapp but it's really frustrating to have to copy+paste all the time from a browser tab. Considering people have been asking for a linux client for a few years now, you'd think they'd find some time. Then again their windows app isn't really polished either.

Re: LastPass: Security done wrong

#136
post #124
post #77

"Altogether it looks like LastPass is a lot better at PR than they are at security. Yes, that’s harsh but this is what I’ve seen so far." No, it's not harsh enough for a program that knows the right password, shows it to you, but then inputs the wrong one in the password field. Of course, compared to these security issues, such UI issues are almost irrelevant. With such a simple UI to program, you'd think they'd at l…

> If it takes someone with expert skills in computers almost a year to find a good password manager program, not to mention days worth of work importing into and testing various solutions, what chance does your everyday computer user stand? The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to. Take this one for example. The…

> The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to ... comments are basically "I use X because of Y"

I often come to these comments on articles like this precisely because I want to see if the knowledgable folks here suggest the product/service in the article, or if not something else (in the same space).

Re: LastPass: Security done wrong

#137
post #56

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

If you're open to a paid option, 1Password for Teams/Families a good one. You can transfer from LastPass via CSV ( https://support.1password.com/import-lastpass/ ).

So I just did this. Have to say that I really didn't feel comfortable with the unencrypted CSV data transfer. I made sure that time machine doesn't index it, but accessing this file in the time window needed to export/import seems like a prime attack vector to me.

Re: LastPass: Security done wrong

#138

http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.

Putting one's keyfile in the cloud just seems to me to be asking for it. You're essentially trusting a 3rd party with the keys to your kingdom.

* Compared to completely cloud-based password manager like LastPass and 1Password, it's no worse.

* The database in encrypted with your master password.

* You can optionally also encrypt it with static "Key File" that are on all your devices but not in Dropbox.

Re: LastPass: Security done wrong

#139
post #124
post #77

"Altogether it looks like LastPass is a lot better at PR than they are at security. Yes, that’s harsh but this is what I’ve seen so far." No, it's not harsh enough for a program that knows the right password, shows it to you, but then inputs the wrong one in the password field. Of course, compared to these security issues, such UI issues are almost irrelevant. With such a simple UI to program, you'd think they'd at l…

> If it takes someone with expert skills in computers almost a year to find a good password manager program, not to mention days worth of work importing into and testing various solutions, what chance does your everyday computer user stand? The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to. Take this one for example. The…

"The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to."

I clearly describe the issue: "a program that knows the right password, shows it to you, but then inputs the wrong one in the password field". This isn't a bugtracker. If you want details, I'll gladly supply them. But don't accuse me of not writing something that's clearly in my post.

Post reply on HN