Earlier quoted context omitted.
+1 Agree. Lastpass has great functionality imo, and I want a level headed analysis before I jump ship to a competitor. I do wonder though if the change in ownership last year has led to a decline in quality.
FWIW I manage a couple Lastpass Enterprise installs and I haven't seen any indicators of a reduction in quality. Even @taviso had this (positive) follow up tweet: https://twitter.com/taviso/status/844574176165822465
LastPass: Security done wrong
131–140 of 221 posts
Re: LastPass: Security done wrong
#132Earlier quoted context omitted.
Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…
copying and pasting seems to be a vulnerability..especially if you get distracted for a moment, or haven't had your coffee and paste it into your search bar.
Re: LastPass: Security done wrong
#133Earlier quoted context omitted.
Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…
I would love to use pass but I can't figure out a decent way of getting it on my iPhone. Sometimes I don't have my laptop with me.
KeePass is a good solution, too. It also has iOS apps.
Re: LastPass: Security done wrong
#134Earlier quoted context omitted.
I signed my family up for 1Password a month ago and love it so far. Here's the 1Password Security Design Whitepaper: https://1password.com/files/1Password%20for%20Teams%20White%...
1Password has no Linux support so it's not really a drop in replacement. Android autofill functionality is also significantly worse.
Re: LastPass: Security done wrong
#135Re: LastPass: Security done wrong
#136"Altogether it looks like LastPass is a lot better at PR than they are at security. Yes, that’s harsh but this is what I’ve seen so far." No, it's not harsh enough for a program that knows the right password, shows it to you, but then inputs the wrong one in the password field. Of course, compared to these security issues, such UI issues are almost irrelevant. With such a simple UI to program, you'd think they'd at l…
> If it takes someone with expert skills in computers almost a year to find a good password manager program, not to mention days worth of work importing into and testing various solutions, what chance does your everyday computer user stand? The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to. Take this one for example. The…
I often come to these comments on articles like this precisely because I want to see if the knowledgable folks here suggest the product/service in the article, or if not something else (in the same space).
Re: LastPass: Security done wrong
#137Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?
If you're open to a paid option, 1Password for Teams/Families a good one. You can transfer from LastPass via CSV ( https://support.1password.com/import-lastpass/ ).
Re: LastPass: Security done wrong
#138http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.
Putting one's keyfile in the cloud just seems to me to be asking for it. You're essentially trusting a 3rd party with the keys to your kingdom.
* The database in encrypted with your master password.
* You can optionally also encrypt it with static "Key File" that are on all your devices but not in Dropbox.
Re: LastPass: Security done wrong
#139"Altogether it looks like LastPass is a lot better at PR than they are at security. Yes, that’s harsh but this is what I’ve seen so far." No, it's not harsh enough for a program that knows the right password, shows it to you, but then inputs the wrong one in the password field. Of course, compared to these security issues, such UI issues are almost irrelevant. With such a simple UI to program, you'd think they'd at l…
> If it takes someone with expert skills in computers almost a year to find a good password manager program, not to mention days worth of work importing into and testing various solutions, what chance does your everyday computer user stand? The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to. Take this one for example. The…
I clearly describe the issue: "a program that knows the right password, shows it to you, but then inputs the wrong one in the password field". This isn't a bugtracker. If you want details, I'll gladly supply them. But don't accuse me of not writing something that's clearly in my post.