Live data from Hacker News

LastPass: Security done wrong

palant.de

141–150 of 221 posts

Re: LastPass: Security done wrong

#141
post #55

Earlier quoted context omitted.

You can also add in KeepassHttp + PassIFox. But I wonder if these might have similar vulnerabilities as they too would be handling decrypted passwords.

True, but there are a slew of security issues (and unknowns) with KeePassHttp: https://github.com/pfn/keepasshttp/issues/258 https://github.com/keepassxreboot/keepassxc/issues/147 I've been looking for a alternative with somewhat parity with lastpass with a better security policy.

Enpass seems to be your (and mine) best choice at the moment. At least it's a standalone Qt application (not a JS-based browser one), with it's separate UI and without any autofills without asking. Bonus points for reasonably good integration with your usual clouds (Dropbox, GoogleDrive, OwnCloud, etc) for synchronization.

Cons: NOT open-source, paid cellphone apps.

Re: LastPass: Security done wrong

#142
post #114

Earlier quoted context omitted.

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

copying and pasting seems to be a vulnerability..especially if you get distracted for a moment, or haven't had your coffee and paste it into your search bar.

In Firefox, I believe there's a way to turn off asynchronous searching so that it won't attempt to search as you're typing. Even though DuckDuckGo is my search provider, I have that enabled anyway; I figure I'm okay with having to press ENTER to see results as a trade-off for not having my data sent to someone as soon as I start typing. Not sure if this is an option in Chrome/Chromium.

Re: LastPass: Security done wrong

#143

http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.

Putting one's keyfile in the cloud just seems to me to be asking for it. You're essentially trusting a 3rd party with the keys to your kingdom.

[deleted]

Re: LastPass: Security done wrong

#144
post #139
post #124

Earlier quoted context omitted.

> If it takes someone with expert skills in computers almost a year to find a good password manager program, not to mention days worth of work importing into and testing various solutions, what chance does your everyday computer user stand? The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to. Take this one for example. The…

"The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to." I clearly describe the issue: "a program that knows the right password, shows it to you, but then inputs the wrong one in the password field". This isn't a bugtracker. If you want details, I'll gladly supply them. But don't accuse me of not writing something that's cle…

I wasn't referring to your own comment, but to the discussions about password managers in general (hence, the usage of "we" instead of "you"). I apologize my comment led you to believe otherwise. I found your comment relevant to the discussion and went on trying to discuss how these threads in general might have something to do with us taking so long to chose a password manager.

Re: LastPass: Security done wrong

#145
post #114

Earlier quoted context omitted.

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

I would love to use pass but I can't figure out a decent way of getting it on my iPhone. Sometimes I don't have my laptop with me.

I use password safe which is a windows app but also has a database format so there are lots of cross platform apps that can act on the safe file. I sync it with Google drive and have a Linux and Android app that I use to access the safe.

Re: LastPass: Security done wrong

#146

Earlier quoted context omitted.

+1 Agree. Lastpass has great functionality imo, and I want a level headed analysis before I jump ship to a competitor. I do wonder though if the change in ownership last year has led to a decline in quality.

Anecdotal and personal opinion, but I believe that it has. I've been a LastPass user since February 2014. I used to pay for the annual subscription because it was required to use their phone apps, but now that it isn't I find no benefit to the paid subscription, especially given how poorly some thing seem to be working. The user experience with extensions for different browsers (Chrome, Firefox, Safari) is inconsiste…

My experience (with the risk appetite and settings to match said appetite): 1) open app 2) scan fingerprint 3) search "ycomb.." (which limits my results to HN account) 4) tap/copy password --------------------------------------- 5) switch to HN 6) login to HN to write this comment 7) ok I lied I wrote this on my laptop, but still..!!

I was also scared when they were bought but no tragedies so far.

Re: LastPass: Security done wrong

#148
post #88

I use passwords.google.com It works well with chromium on linux and on my android phone. It's free, has all the security of a google account including u2f, chromium integration is flawless on linux, and works well with chrome on Android.

Note that you can't use the web interface if you've encrypted your Chrome password store with a passphrase

Re: LastPass: Security done wrong

#149

Earlier quoted context omitted.

+1 Agree. Lastpass has great functionality imo, and I want a level headed analysis before I jump ship to a competitor. I do wonder though if the change in ownership last year has led to a decline in quality.

Anecdotal and personal opinion, but I believe that it has. I've been a LastPass user since February 2014. I used to pay for the annual subscription because it was required to use their phone apps, but now that it isn't I find no benefit to the paid subscription, especially given how poorly some thing seem to be working. The user experience with extensions for different browsers (Chrome, Firefox, Safari) is inconsiste…

I've been using the iOS app since it came out and have never had a problem with it.

TouchID integration has been a godsend.

Re: LastPass: Security done wrong

#150
post #114

Earlier quoted context omitted.

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

copying and pasting seems to be a vulnerability..especially if you get distracted for a moment, or haven't had your coffee and paste it into your search bar.

While I don't use pass, KeePassXC and KeePassDroid clear the clipboard shortly after use.
Post reply on HN