Live data from Hacker News

LastPass: Security done wrong

palant.de

191–200 of 221 posts

Re: LastPass: Security done wrong

#191
post #182

http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.

https://www.enpass.io/ is better, does the same, you sync the wallet across your machines and devices, also has browser integration. https://www.enpass.io/security/

Looks nice but no sharing options

Re: LastPass: Security done wrong

#192
post #90

Earlier quoted context omitted.

passwordstore.org is good if you're a nerd. It's built on standard linux tools: pwgen, gnupg, git. QTPass is a QT based multi-platform desktop gui version. That helps if you're not in the mood to be a nerd today. Android Password Store is the mobile version and integrates with Android chrome/chromium. Thanks to gnupg, pass also works in conjunction with smartcards like Yubikeys. Open Keychain on android allows you to…

Does using PGP make it any safer than, say, simple password-based SHA-512 encryption?

How do you encrypt using a hash function?...

Re: LastPass: Security done wrong

#193

Earlier quoted context omitted.

Here is how I think about it: It is a spectrum. You can have high accessibility / ease of use or you can have high security. You can't have both. By storing your info on a remote server, you are trusting they will protect your data. Maybe they will, maybe they won't. It is just a matter of finding a balance you feel comfortable with. Personally, I don't store my passwords on any cloud service, carry them on a thumb d…

How do you deal with passwords on your mobile device?

Type them in by hand.

It does mean I have to have a computer around with me though. I don't really use a lot of apps, I mostly have my bank apps and those stay logged in.

Re: LastPass: Security done wrong

#194

I would love to switch to a different password manager, but nothing else I've tried has quite managed to nail the usability aspect. Specifically, Lastpass's app fill functionality on Android is a huge benefit that I haven't seen in others. It also has a browser extension that works without a separate program running on your computer; I didn't even realize that was a plus until I started trying to use other apps that…

Usability is great, but we're talking about our passwords. Security needs to be put ahead of usability in this case. If you can get both that's great, but poor usability beats having your banking and systems owned.

It's still more secure than not using a password manager. And I've found that whenever I'm in a situation where I can't use lastpass for whatever reason, I just fall back to using a password I've used many times before. Anything else I would just immediately forget.

Re: LastPass: Security done wrong

#195
post #114

Earlier quoted context omitted.

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

Here's another question to ask: "Is everyone really going to open a separate application, unlock the vault every time they want to use it (due to timeout), Ctrl+F for the URL, and then Ctrl+C out the username and password every time they want to visit a site? Also, is everyone going to create a correlated entry every time they make a new account?" Good security is hard in practice because people are always going to d…

I actually do that (gpg-encrypted file with an org-mode table with usernames and passwords, easily accessed from within Emacs). It's not as much of a hassle as it sounds, really.

Re: LastPass: Security done wrong

#196
post #153
post #124

Earlier quoted context omitted.

> If it takes someone with expert skills in computers almost a year to find a good password manager program, not to mention days worth of work importing into and testing various solutions, what chance does your everyday computer user stand? The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to. Take this one for example. The…

> The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to. The reason why I hate these kinds of threads in IT communities is that they always devolve into criticism of what other people want to talk about.

I recommend we adopt a /meta.. tag to identify posts that are just about posting.

Re: LastPass: Security done wrong

#197

http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.

I would like to know this as well. I tried setting up keePass on iOS, but was never able to get it to work so it seamlessly kept things in sync between all my devices (two desktop computers, three laptops, two tablets and an iphone). I then tried LastPass and so far it was worked flawlessly for me across all devices. Now I read this and I'm not sure what to do. Prior to LastPass I used the same six character password for everything. Now many of my passwords are 30+ characters long. That seems more secure, but if someone can just grab my passwords while I'm browsing then maybe it's time to go back to the same 6 character password that I can remember.

Re: LastPass: Security done wrong

#198

Earlier quoted context omitted.

Would love to hear from someone who has an iPhone and uses Keepass or a derivative. That's my last barrier to using it.

I do. I use the MiniKeePass app, which is free. You can export your KeePass database (.kdbx) from the Dropbox app to MiniKeePass.

Does this keep things auto synced up between all your devices? I'm constantly switching between different desktops, laptops, tablets, etc. and I'd love a replacement for LastPass that auto syncs just as well and also works on iOS.

Re: LastPass: Security done wrong

#199
post #114

Earlier quoted context omitted.

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

Here's another question to ask: "Is everyone really going to open a separate application, unlock the vault every time they want to use it (due to timeout), Ctrl+F for the URL, and then Ctrl+C out the username and password every time they want to visit a site? Also, is everyone going to create a correlated entry every time they make a new account?" Good security is hard in practice because people are always going to d…

Point is: this can be done right. I develop Easy Passwords myself, with the same/better convenience factor and without offering a huge attack surface. It's not about LastPass making mistakes, rather about them not learning from them and thus necessarily repeating them. If you still want to believe that LastPast is hardened now - well, if it makes you happier...

Re: LastPass: Security done wrong

#200
post #58

Earlier quoted context omitted.

Usability is great, but we're talking about our passwords. Security needs to be put ahead of usability in this case. If you can get both that's great, but poor usability beats having your banking and systems owned.

Why would people put their bank and other important passwords like this in a password manager? I use lastpass for over 5 years and I memorize my lastpass and my bank account passwords.

Uh, because otherwise my bank account password would be the equivalent of 1234abcd. That's what my password basically way prior to using a password manager. Now my bank password is the maximum length allowed and is what is basically a random mix of upper lower case letters, numbers, special characters.

After reading this I'm seriously considering dropping my password manager and going back to something I can remember and type in in a reasonable amount of time like 1234abcd.

Post reply on HN