Live data from Hacker News

LastPass: Security done wrong

palant.de

201–210 of 221 posts

Re: LastPass: Security done wrong

#201
post #114
post #79

It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

> I use pass[1], and I recommend it if you can stand copying and pasting.

Try browserpass. It uses pass internally. https://github.com/dannyvankooten/browserpass

Re: LastPass: Security done wrong

#202

I've been using LastPass for a few months and have loved it, but maybe I'll consider switching to 1Password. However, can I just rant for a second about how these security assessments and blog posts fold out? The beginning of my career was spent thinking I was going to go into this field (one of my degrees is in Information Assurance) and the #1 thing that persuaded me to switch to building software instead was the a…

Thank you for putting into words my exact thoughts. Though, I'm cynical enough to believe that people would rather moan about how much password managers suck (Why can't everyone just memorize a different 30 character string for each of their 200+ websites? Losers.) and not do anything productive to fix it. I wish I had the skills to do so.

Re: LastPass: Security done wrong

#203
post #57
post #3

Interested to hear what the HN community thinks about 1Password

Initially hesitated to switch to 1Password since some of our team used Linux but eventually we all switched to Mac so that went away. Much happier with 1Password since we switched from Lastpass. Consistent UI, proper OS integration, multiple separate vaults, not to mention the security story seems better (I've seen several LP vulnerabilities of concern but not yet seen a 1PW one that worried me).

How well does it work on iOS? Does it auto sync between all devices like LastPass does?

Re: LastPass: Security done wrong

#204
post #3

Interested to hear what the HN community thinks about 1Password

I really like it. Much nicer to use than Lastpass in my opinion.

How much time have you spent using both? Have you ever used KeyPass? I see people recommending it and I wonder if you have any experience with it.

Re: LastPass: Security done wrong

#205
post #4

Earlier quoted context omitted.

I've taken it as a sign that 1Password must be a fairly good choice as I very, very rarely see it pop up on here.

That could also indicate fewer people use it?

1Password has over 15 million users across Mac, Windows, iOS and Android platforms.

Re: LastPass: Security done wrong

#206

Earlier quoted context omitted.

I do. I use the MiniKeePass app, which is free. You can export your KeePass database (.kdbx) from the Dropbox app to MiniKeePass.

Does this keep things auto synced up between all your devices? I'm constantly switching between different desktops, laptops, tablets, etc. and I'd love a replacement for LastPass that auto syncs just as well and also works on iOS.

As far as I know the system I described is manual only on iPhone. That is, if the database file gets updated on another device/computer, you have to manually re-import it from Dropbox to MiniKeePass to see the update there.

On desktops/laptops, if you're pointing KeePass at a database file in a Dropbox-synced folder, then it's automatic.

Re: LastPass: Security done wrong

#207
post #58

Earlier quoted context omitted.

Why would people put their bank and other important passwords like this in a password manager? I use lastpass for over 5 years and I memorize my lastpass and my bank account passwords.

Why wouldn't the average user? The entire idea is that you'll just have to remember two passwords: your computer account, and your password manager. At least for most users, the idea that some password shouldn't be stored just opens the door to bad practices and password reuse. For someone working on a password manager, I think the default assumption has to be that a screwup on your part will--literally--impact prett…

Well my wife believes that reusing the same password with variations is more secure then a password manager. Most average users distrust a manager and won't use it.

Re: LastPass: Security done wrong

#208
post #3

Interested to hear what the HN community thinks about 1Password

no linux support and shit android support means it's a hard pass for me.

Can you be more detailed about "shit android support"? I'm currently trying it out and didn't seem so bad, similar to how I currently use LastPass in Android in general. Apparently I need an extra click to actually copy a password there, but I also saw they have an integrated keyboard (https://support.1password.com/android-keyboard/), which I haven't looked at yet.

Re: LastPass: Security done wrong

#209
post #114
post #79

It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likeli…

Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing s…

That's a good point. Might be a good workaround to sort of "sandbox" the password manager from your active web browser. Have a second browser with the plugin installed that you use only to copy the password to your clipboard and then paste into the password field. I can usually remember by username for 99% of websites.

Re: LastPass: Security done wrong

#210
post #40

Earlier quoted context omitted.

Dashlane does! Been using it for a year or so. Good experience. https://csdashlane.zendesk.com/hc/en-us/articles/202699141-H...

I love Dashlane, it's pretty magical and a massive timesaver. I use it on OSX primarily but it syncs to my Android very well. There's an unfixed bug in the OSX client where it crashes rarely (every couple months for me) and I have to kill the process manually and restart, but it has very minor impact. Is there any security analysis or consensus on Dashlane security vs. other password managers?

I have this problem every couple weeks as well. Killing DashlaneMASService solves it.
Post reply on HN