Earlier quoted context omitted.
Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.
Most people don't read open source and instead trust that the experts will catch any issues....
I Lost All Faith in LastPass
21–30 of 322 posts
Re: I Lost All Faith in LastPass
#22Luckily I've been off of it long enough that I suspect most of my regularly used accounts are different anyways, but I'm still going through the process now of methodically rotating all of them (I may change some of the email addresses as well).
----
I think a lot of people even casually knew LastPass wasn't at the same quality level as other solutions, but inertia is powerful. Sometimes you need something glaring to be the final straw that breaks the camel's back.
It's been long overdue; I moved off of Gmail as well a while ago but haven't gone through and systematically changed all of my account email addresses; there are still a few older services I have that send emails over. The new year is a good opportunity to clean that stuff up.
Re: I Lost All Faith in LastPass
#23After reading this, I acted on a decision I was on the fence about. I already have moved to Bitwarden and like it a lot better, but this post prompted me to go into LastPass and actively delete my account. The next thing to do will be to start changing passwords. As with most of us, that's a project of serious scope that I do not look forward to.
I've spent the better part of the past three days doing just this. Get some good music and some good coffee, and it can actually be pretty cathartic. I enjoyed the hygiene exercise much more than I thought I would.
Re: I Lost All Faith in LastPass
#24How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…
1password has a document on their security arch: https://1passwordstatic.com/files/security/1password-white-p... . This alone lends credence to their claims. To this date there has been no major breaches despite being a large target (albeit smaller than LP). Moreover, the fact that your vault is both password protected and locked behind a secret key is about as good as you can get in terms of commercially offered sec…
Re: I Lost All Faith in LastPass
#25How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…
1password has a document on their security arch: https://1passwordstatic.com/files/security/1password-white-p... . This alone lends credence to their claims. To this date there has been no major breaches despite being a large target (albeit smaller than LP). Moreover, the fact that your vault is both password protected and locked behind a secret key is about as good as you can get in terms of commercially offered sec…
And
> But after careful evaluation I've gone to them and people much more experienced in security have also moved to them as well.
Do you not see your contradiction?
Re: I Lost All Faith in LastPass
#26Re: I Lost All Faith in LastPass
#27Earlier quoted context omitted.
Thank you for the link. > It's also been built by people who are respected in the security industry. This means almost nothing. It is an appeal to authority. Experts can still miss things. Yes, it is better than experts saying a product stinks, but still is not trustworthy without open source. Maybe I'm making my own fallacy here, I'm just trying out a position.
Most people don't read open source and instead trust that the experts will catch any issues....
But it must be smaller than the number of bugs that exist in code read by a smaller group.
Re: I Lost All Faith in LastPass
#28How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…
Re: I Lost All Faith in LastPass
#29Earlier quoted context omitted.
There is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.
Still doesn't explain why it's all not at least source-available. I'm not going to complain if they don't use open-source licenses such as MIT or (A)GPL, but straight up not making the source code publicly readable at all is a big strike against it.
Re: I Lost All Faith in LastPass
#30How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…
There is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.
I've been very reluctant to use their cloud solution as I trust Dropbox more for security. So I still fight 1password to keep the vault stored in Dropbox.
I figure there are maybe 4 organizations who are active enough to prevent a full download of all their user's data. Google, Dropbox, Amazon, and Facebook. (Maybe Apple, but they seem lethargic.)
Because they store all the passwords to all of our services they are a huge target.