Earlier quoted context omitted.
copying and pasting seems to be a vulnerability..especially if you get distracted for a moment, or haven't had your coffee and paste it into your search bar.
While I don't use pass, KeePassXC and KeePassDroid clear the clipboard shortly after use.
LastPass: Security done wrong
181–190 of 221 posts
Re: LastPass: Security done wrong
#182http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.
Re: LastPass: Security done wrong
#183Earlier quoted context omitted.
I used it (1P) and it was super, but mac only - no Linux client. Just switched over to Enpass, and its very like 1Password, only they do provide a linux client. So far its great, very happy with it.
How is enpass's (cryptographic) design and security compared to 1Password?
Re: LastPass: Security done wrong
#184http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.
Putting one's keyfile in the cloud just seems to me to be asking for it. You're essentially trusting a 3rd party with the keys to your kingdom.
Re: LastPass: Security done wrong
#185Earlier quoted context omitted.
Usability is great, but we're talking about our passwords. Security needs to be put ahead of usability in this case. If you can get both that's great, but poor usability beats having your banking and systems owned.
Why would people put their bank and other important passwords like this in a password manager? I use lastpass for over 5 years and I memorize my lastpass and my bank account passwords.
On top of that, chances are that a bank login saved in a password database, which has 2FA and other sensible precautions, is probably kept safer for any one individual than the bank's systems themselves, what with the huge legacy cruft they suffer from. No-one would be able to walk into my computer, or call it, with some faked documents and social engineer themselves into my password database.
Re: LastPass: Security done wrong
#186Re: LastPass: Security done wrong
#187Earlier quoted context omitted.
Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…
Here's another question to ask: "Is everyone really going to open a separate application, unlock the vault every time they want to use it (due to timeout), Ctrl+F for the URL, and then Ctrl+C out the username and password every time they want to visit a site? Also, is everyone going to create a correlated entry every time they make a new account?" Good security is hard in practice because people are always going to d…
This is not how pass or KeePass work. I recommend you try them out and see if they're really that hard to use (hint: they're not).
If you really like browser integration, I also sometimes recommend using the built-in Chrome or Firefox password managers with good master passwords. They're actually easier to use than LastPass and its insecure ilk.
Re: LastPass: Security done wrong
#188Earlier quoted context omitted.
copying and pasting seems to be a vulnerability..especially if you get distracted for a moment, or haven't had your coffee and paste it into your search bar.
While I don't use pass, KeePassXC and KeePassDroid clear the clipboard shortly after use.
Re: LastPass: Security done wrong
#189Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?
Padlock does: https://padlock.io/howto/lastpass/
Disclaimer: I'm the developer
Re: LastPass: Security done wrong
#190Earlier quoted context omitted.
Here's another question to ask: "Is everyone really going to open a separate application, unlock the vault every time they want to use it (due to timeout), Ctrl+F for the URL, and then Ctrl+C out the username and password every time they want to visit a site? Also, is everyone going to create a correlated entry every time they make a new account?" Good security is hard in practice because people are always going to d…
> "Is everyone really going to open a separate application, unlock the vault every time they want to use it (due to timeout), Ctrl+F for the URL, and then Ctrl+C out the username and password every time they want to visit a site? Also, is everyone going to create a correlated entry every time they make a new account?" This is not how pass or KeePass work. I recommend you try them out and see if they're really that ha…
I do actually also use Chrome's built-in password manager so that I don't have to copy and paste as much.