LastPass’ Authenticator app is not secure
21–30 of 118 posts
Re: LastPass’ Authenticator app is not secure
#22The code, tech, and mindset behind LastPass is a joke. They started just after the “dark ages” of security but don’t seem to have upgraded their mental model of security since. I’ll share with you the moment I discovered something that made me cancel my schedule for the day, research alternatives, write a LastPass to 1Password converter [0], and cancel my LastPass account and subscription. Are you ready? You log in t…
what's the issue with that? maybe they have some SSO system
Re: LastPass’ Authenticator app is not secure
#23Earlier quoted context omitted.
You can't keep varied, secure passwords in your head unless you barely use any services.
Somewhat true. I use abbreviations of several different long sentences with random characters added in random positions. To me this is far more secure than trusting a single authoritative source with 10 different random character strings that I have no real ownership of, and can all easily be stolen (or lost) at once.
And 1Password supports syncing via services other than their own and each device acts as its own backup too, so you’re really only relying on their service to shuttle around an encrypted keystore to your new devices.
Re: LastPass’ Authenticator app is not secure
#24Earlier quoted context omitted.
That is a whole lot of opinion, but not much substance. What makes LastPass inferior to these other options?
> What makes LastPass inferior to these other options? Well, for one, the very first sentence of the article here.
Re: LastPass’ Authenticator app is not secure
#25I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.
The ability to fill password in Android app. The last time I checked there's no competitors doing this. I'm hoping the Autofill API in Android Oreo can bring more competition.
Re: LastPass’ Authenticator app is not secure
#26Earlier quoted context omitted.
Somewhat true. I use abbreviations of several different long sentences with random characters added in random positions. To me this is far more secure than trusting a single authoritative source with 10 different random character strings that I have no real ownership of, and can all easily be stolen (or lost) at once.
I have at least 50 different passwords in my 1Password account And 1Password supports syncing via services other than their own and each device acts as its own backup too, so you’re really only relying on their service to shuttle around an encrypted keystore to your new devices.
For me the answer is no. I would rather have fewer technically less secure passwords than have technically more secure passwords that all live in one place. My passwords live "nowhere". There is no database breach, or peek over the shoulder that could ever compromise my entire wellbeing.
I also use 2fa wherever possible.
Re: LastPass’ Authenticator app is not secure
#27Wow, color me surprised. Software developers aren't perfect, and closed source software with less eyes on it tends to be even less perfect. I will never trust my passwords all being in one place other than my brain.
You can't keep varied, secure passwords in your head unless you barely use any services.
Re: LastPass’ Authenticator app is not secure
#28The code, tech, and mindset behind LastPass is a joke. They started just after the “dark ages” of security but don’t seem to have upgraded their mental model of security since. I’ll share with you the moment I discovered something that made me cancel my schedule for the day, research alternatives, write a LastPass to 1Password converter [0], and cancel my LastPass account and subscription. Are you ready? You log in t…
>You log in to their support forums and online community with the same password you decrypt your vault with. what's the issue with that? maybe they have some SSO system
Re: LastPass’ Authenticator app is not secure
#29I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.
That is a whole lot of opinion, but not much substance. What makes LastPass inferior to these other options?
I also find their apps to be ugly as sin, but that’s a personal preference.
Re: LastPass’ Authenticator app is not secure
#30The code, tech, and mindset behind LastPass is a joke. They started just after the “dark ages” of security but don’t seem to have upgraded their mental model of security since. I’ll share with you the moment I discovered something that made me cancel my schedule for the day, research alternatives, write a LastPass to 1Password converter [0], and cancel my LastPass account and subscription. Are you ready? You log in t…
>You log in to their support forums and online community with the same password you decrypt your vault with. what's the issue with that? maybe they have some SSO system