http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.
https://www.enpass.io/ is better, does the same, you sync the wallet across your machines and devices, also has browser integration. https://www.enpass.io/security/
LastPass: Security done wrong
191–200 of 221 posts
Re: LastPass: Security done wrong
#192Earlier quoted context omitted.
passwordstore.org is good if you're a nerd. It's built on standard linux tools: pwgen, gnupg, git. QTPass is a QT based multi-platform desktop gui version. That helps if you're not in the mood to be a nerd today. Android Password Store is the mobile version and integrates with Android chrome/chromium. Thanks to gnupg, pass also works in conjunction with smartcards like Yubikeys. Open Keychain on android allows you to…
Does using PGP make it any safer than, say, simple password-based SHA-512 encryption?
Re: LastPass: Security done wrong
#193Earlier quoted context omitted.
Here is how I think about it: It is a spectrum. You can have high accessibility / ease of use or you can have high security. You can't have both. By storing your info on a remote server, you are trusting they will protect your data. Maybe they will, maybe they won't. It is just a matter of finding a balance you feel comfortable with. Personally, I don't store my passwords on any cloud service, carry them on a thumb d…
How do you deal with passwords on your mobile device?
It does mean I have to have a computer around with me though. I don't really use a lot of apps, I mostly have my bank apps and those stay logged in.
Re: LastPass: Security done wrong
#194I would love to switch to a different password manager, but nothing else I've tried has quite managed to nail the usability aspect. Specifically, Lastpass's app fill functionality on Android is a huge benefit that I haven't seen in others. It also has a browser extension that works without a separate program running on your computer; I didn't even realize that was a plus until I started trying to use other apps that…
Usability is great, but we're talking about our passwords. Security needs to be put ahead of usability in this case. If you can get both that's great, but poor usability beats having your banking and systems owned.
Re: LastPass: Security done wrong
#195Earlier quoted context omitted.
Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…
Here's another question to ask: "Is everyone really going to open a separate application, unlock the vault every time they want to use it (due to timeout), Ctrl+F for the URL, and then Ctrl+C out the username and password every time they want to visit a site? Also, is everyone going to create a correlated entry every time they make a new account?" Good security is hard in practice because people are always going to d…
Re: LastPass: Security done wrong
#196Earlier quoted context omitted.
> If it takes someone with expert skills in computers almost a year to find a good password manager program, not to mention days worth of work importing into and testing various solutions, what chance does your everyday computer user stand? The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to. Take this one for example. The…
> The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to. The reason why I hate these kinds of threads in IT communities is that they always devolve into criticism of what other people want to talk about.
Re: LastPass: Security done wrong
#197http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.
Re: LastPass: Security done wrong
#198Earlier quoted context omitted.
Would love to hear from someone who has an iPhone and uses Keepass or a derivative. That's my last barrier to using it.
I do. I use the MiniKeePass app, which is free. You can export your KeePass database (.kdbx) from the Dropbox app to MiniKeePass.
Re: LastPass: Security done wrong
#199Earlier quoted context omitted.
Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…
Here's another question to ask: "Is everyone really going to open a separate application, unlock the vault every time they want to use it (due to timeout), Ctrl+F for the URL, and then Ctrl+C out the username and password every time they want to visit a site? Also, is everyone going to create a correlated entry every time they make a new account?" Good security is hard in practice because people are always going to d…
Re: LastPass: Security done wrong
#200Earlier quoted context omitted.
Usability is great, but we're talking about our passwords. Security needs to be put ahead of usability in this case. If you can get both that's great, but poor usability beats having your banking and systems owned.
Why would people put their bank and other important passwords like this in a password manager? I use lastpass for over 5 years and I memorize my lastpass and my bank account passwords.
After reading this I'm seriously considering dropping my password manager and going back to something I can remember and type in in a reasonable amount of time like 1234abcd.