Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?
If you're open to a paid option, 1Password for Teams/Families a good one. You can transfer from LastPass via CSV ( https://support.1password.com/import-lastpass/ ).
LastPass: Security done wrong
151–160 of 221 posts
Re: LastPass: Security done wrong
#152I've always been quite nervous that the LastPass two-factor authentication can be easily bypassed if your email account is compromised. On the 2FA screen there's a "If you lost your Google Authenticator device, click here to disable Google Authenticator authentication" link. No. I don't want that to be able to be disabled. I have one-time passwords for that.
You can configure quite a lot of stuff in the 2Fa settings. I have no such option for my 2Fa on Lastpass. Also, my E-Mail also has a 2Fa.
Re: LastPass: Security done wrong
#153"Altogether it looks like LastPass is a lot better at PR than they are at security. Yes, that’s harsh but this is what I’ve seen so far." No, it's not harsh enough for a program that knows the right password, shows it to you, but then inputs the wrong one in the password field. Of course, compared to these security issues, such UI issues are almost irrelevant. With such a simple UI to program, you'd think they'd at l…
> If it takes someone with expert skills in computers almost a year to find a good password manager program, not to mention days worth of work importing into and testing various solutions, what chance does your everyday computer user stand? The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to. Take this one for example. The…
The reason why I hate these kinds of threads in IT communities is that they always devolve into criticism of what other people want to talk about.
Re: LastPass: Security done wrong
#154It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…
Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…
Re: LastPass: Security done wrong
#155http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.
Re: LastPass: Security done wrong
#156Re: LastPass: Security done wrong
#157> Altogether it looks like LastPass is a lot better at PR than they are at security. Yes, that’s harsh but this is what I’ve seen so far. In particular, security vulnerabilities have been addressed punctually, only the exact scenario reported has been tested by the developers.
This seems unfair.
LastPass fixes the initial vulnerability punctually - we do not know what they will do in the future. Is it better for them to wait, come out with a defense in depth approach, and then patch? Seems silly.
Of course, how long do we wait? Historically, I would argue, LastPass has down defense in depth fairly well - when their was a breach they were quick to not only address the vulnerabilities immediately but soon after they rolled out Content Security Policy and HSTS, two technologies that were rarely deployed in the wild at the time (and are still sadly too rare).
My suggestion to LastPass users is to:
1) Enable 2FA 2) Up your PBKDF2 Rounds 3) Disable as many browser integration features as possible
I don't recommend dropping LastPass and trying to roll your own key-sync store with KeyPass/Dropbox as some have done. I don't know of any other browser-based password manager that isn't equally weak to attacks based on browser-integration.
Alternatively, don't use a browser-based solution. This is less convenient but you'll avoid by far the largest area of attack surface.
Re: LastPass: Security done wrong
#158Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?
If you're open to a paid option, 1Password for Teams/Families a good one. You can transfer from LastPass via CSV ( https://support.1password.com/import-lastpass/ ).
I've read a lot of reviews but many predate 1Password's cloud option.
Re: LastPass: Security done wrong
#159It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…
+1 Agree. Lastpass has great functionality imo, and I want a level headed analysis before I jump ship to a competitor. I do wonder though if the change in ownership last year has led to a decline in quality.
To me, the point is managing the dozens of separate logins you have to manage to use the web. I often can't be bothered to remember which sites I've signed up for, let alone what the username and passwords are.
For critical accounts (email, financial stuff, etc.) I'll always take the effort to memorize some high quality and unique usernames and passwords. I find this to be the best trade-off.
Re: LastPass: Security done wrong
#160I've been a LastPass user for a few years and I use the browser extension everyday. As an admin of several websites, the the extension has been a time saver. I thought I had no illusions about the inherent insecurity in using LastPass, but I guess I was wrong. I use Yubikey and disabled autofill long ago, but I was still vulnerable. Their response to these exploits is maddening. "Our investigation to date has not ind…