Live data from Hacker News

LastPass: Security done wrong

palant.de

171–180 of 221 posts

Re: LastPass: Security done wrong

#171
post #114
post #79

It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

Here's another question to ask: "Is everyone really going to open a separate application, unlock the vault every time they want to use it (due to timeout), Ctrl+F for the URL, and then Ctrl+C out the username and password every time they want to visit a site? Also, is everyone going to create a correlated entry every time they make a new account?"

Good security is hard in practice because people are always going to default to the most convenient/simple way to accomplish their goal, and at this point, most of our security measures require someone to expend extra energy. That means it's going to be very hard to get people to do it.

We have decades of experience with this just with regard to one layer of passwords. Adding an extra layer, like a password vault, is not going to make things better.

While it absolutely true that there is more risk involved in using a third-party extension to manage a password vault than not, the actual net effect is likely better security, because if you make things too hard, people are just going to say "Fuck those annoying nerds, we're going to make every password 123456", or whatever the next-simplest answer that the system will permit is.

As for LastPass making mistakes, that's true, but the benefit you get by using a well-known product like LastPass is that Project Zero has hardened it. That's not the case for most other password vault extensions, especially those made as shims for external vaults like KeePass.

Re: LastPass: Security done wrong

#172
post #50

Earlier quoted context omitted.

Keepass imports from Lastpass [0]. Not that meets the rest of your requirements, but Keepass + KeepassHttp + PassIFox work beautifully for me. Autofills my logins and fully integrates with Firefoxes password manager so that you don't get conflicts between the browser and your password manager trying to save the same password. Also doesn't add the stupid CSS hacking that LastPass does to add their logo into the passwo…

Keepass has lots of red flags for me: - No https on site - Update file hosted via http (not https) - Downloads via sourceforge which has injected adware in downloads before - FAQ downplays lack of constant time comparison instead of using constant time comparisons and being extra safe - You have to cobble together multiple apps from multiple developers to get a full working solution; means you have to trust lots of i…

- No https, agree, its a very old site, but it's not sensitive material that you're submitting. You can check the integrity of the download [0]

- Sourceforge, again not ideal but again it has very old beginnings from when Sourceforge was as respected as Github is. You can't blame the developer for the environment changing. Perhaps they're just a stickler for loyalty. I've never had any crapware with Keepass

- FAQ - I could't find your reference in the FAQ page [1]

- You have one app + plugin with a browser extension from two developers, hardly a mishmash. You know directly who those two developers are. You've no idea who was working on LastPass. I'd say it was more in the bazaar philosophy vs the LastPass cathedral.

  [0]: http://keepass.info/integrity.html
  [1]: http://keepass.info/help/base/faq_tech.html

Re: LastPass: Security done wrong

#173
post #77

"Altogether it looks like LastPass is a lot better at PR than they are at security. Yes, that’s harsh but this is what I’ve seen so far." No, it's not harsh enough for a program that knows the right password, shows it to you, but then inputs the wrong one in the password field. Of course, compared to these security issues, such UI issues are almost irrelevant. With such a simple UI to program, you'd think they'd at l…

Is there a better alternative? Certainly not reusing passwords and if you aren't reusing passwords you'll have to manage them all somehow. I can't see a better solution.

I'm "slightly" biased but to me Easy Passwords is a better solution (see https://palant.de/2016/04/19/easy-passwords). In fact, I programed it myself :)

Syncing data between different computers is still work in progress. Then again, with it being a password generator this is less of an issue than with password safes. As long as your master password is the same you can simply create a password with the same name on another computer and it will work.

Re: LastPass: Security done wrong

#174
post #35
post #5

Earlier quoted context omitted.

I used 1Password for quite a long time but have since switched to LastPass mostly due to Linux compatibility and u2f integration

I used it (1P) and it was super, but mac only - no Linux client. Just switched over to Enpass, and its very like 1Password, only they do provide a linux client. So far its great, very happy with it.

How is enpass's (cryptographic) design and security compared to 1Password?

Re: LastPass: Security done wrong

#175
post #56

Earlier quoted context omitted.

If you're open to a paid option, 1Password for Teams/Families a good one. You can transfer from LastPass via CSV ( https://support.1password.com/import-lastpass/ ).

Are you using 1Password's cloud sync or the older Dropbox/iCloud/other method? (Really curious about all 1Password users in this thread) I've read a lot of reviews but many predate 1Password's cloud option.

Been using 1P since version 4 or so and syncing with Dropbox. It works really well and I'm quite satisfied with how quickly they resolve issues (especially security related ones)

Re: LastPass: Security done wrong

#176
post #69
post #50

Earlier quoted context omitted.

Keepass imports from Lastpass [0]. Not that meets the rest of your requirements, but Keepass + KeepassHttp + PassIFox work beautifully for me. Autofills my logins and fully integrates with Firefoxes password manager so that you don't get conflicts between the browser and your password manager trying to save the same password. Also doesn't add the stupid CSS hacking that LastPass does to add their logo into the passwo…

Sounds interesting, but requires a password program, a 3rd party plugin for the program, and a browser plugin... and yet another app to do cloud sync like Dropbox. Sounds like a huge pain compared to LastPass, as well as increasing attack surface.

LastPass is a Cloud password program + browser plugin

So the extra layer is the plugin that is written by the same developer as the browser plugin. Which is a drop in plugin.

It's all open source so it's much easier for people to check the vulnerabilities. It's also easier to raise issues and other people to help fix them.

Separately Keepass is an offline database, so you have total control over access to it. The overhead of course is using something like Dropbox, plus probably Boxcryptor to ensure it's encrypted before it gets to Dropbox.

I've commented elsewhere here - it's similar to the Keepass bazaar vs the LastPass cathedral. Keepass might look uglier, but I trust it more.

Re: LastPass: Security done wrong

#177

Earlier quoted context omitted.

Putting one's keyfile in the cloud just seems to me to be asking for it. You're essentially trusting a 3rd party with the keys to your kingdom.

* Compared to completely cloud-based password manager like LastPass and 1Password, it's no worse. * The database in encrypted with your master password. * You can optionally also encrypt it with static "Key File" that are on all your devices but not in Dropbox.

1Password seems to put saving to their cloud front and center but you can still choose to not save your passwords on their servers and use your own methods. My 1Password vaults are encrypted with my master password and synced between devices using Dropbox, I think there's also an option for directly syncing between smartphones and computers.

Re: LastPass: Security done wrong

#178
post #50

Earlier quoted context omitted.

Keepass imports from Lastpass [0]. Not that meets the rest of your requirements, but Keepass + KeepassHttp + PassIFox work beautifully for me. Autofills my logins and fully integrates with Firefoxes password manager so that you don't get conflicts between the browser and your password manager trying to save the same password. Also doesn't add the stupid CSS hacking that LastPass does to add their logo into the passwo…

Keepass has lots of red flags for me: - No https on site - Update file hosted via http (not https) - Downloads via sourceforge which has injected adware in downloads before - FAQ downplays lack of constant time comparison instead of using constant time comparisons and being extra safe - You have to cobble together multiple apps from multiple developers to get a full working solution; means you have to trust lots of i…

You can download the file via https [0], this is what the Chocolatey package does [1]

  [0]: https://sourceforge.net/projects/keepass/files/KeePass%202.x/2.35/KeePass-2.35-Setup.exe
  [1]: https://chocolatey.org/packages/keepass

Re: LastPass: Security done wrong

#179
post #56

Earlier quoted context omitted.

If you're open to a paid option, 1Password for Teams/Families a good one. You can transfer from LastPass via CSV ( https://support.1password.com/import-lastpass/ ).

I felt like they weren't above board previously with pricing. It wasn't fraud but IIRC prices got a big jump that was timed to be in combination with some kind of defacto mandatory upgrade. It had a bait and switch feel to it and at the time the family price across multiple devices seemed too high.

I bought 1Password for Mac and 1Password for iOS in 2013, have paid nothing since and use the current versions. I don't save passwords to their cloud (I use Dropbox, including sharing a vault with my spouse), maybe I would have to start paying a subscription for that.

Re: LastPass: Security done wrong

#180
post #65

The HN community seems to be giving a lot of praise for 1Password, Lastpass and Keepass occasionally. But rarely mention Dashlane, I'm curious as to why ?

Dashlane isn't open source, nor is it available on Linux. That is going to prevent a lot of people from even considering it.

The Dashlane Windows app does work under Wine.

Dashlane is the only password manager that looks normal enough to be used by the non-tech members of the company. I've found its sharing feature invaluable, I can get the whole team on it using 2FA and passwords don't get emailed around anymore!

Post reply on HN