Live data from Hacker News

LogMeIn acquires Lastpass

blog.lastpass.com

211–220 of 443 posts

Re: LogMeIn acquires Lastpass

#211
post #154

Earlier quoted context omitted.

> "They however do control access to the account. This means there's a point where they get all sorts of data on me, and while I personally don't mind, I must admit I felt a bit safer when I thought it was a smaller, purpose-built company managing things." I've never really understood the appeal of account-based password managers. It was a startup and it needed a business model, sure, so from the company's perspectiv…

Agreed. Logically, something like KeepassX ( https://www.keepassx.org/ ) is the most logical, secure choice. I think a lot of people pick Lastpass and such for the convenience of browser integration, but I don't think that's necessarily impossible with keepassx - just so happens that nobody is really working on it (which is a shame).

There's actually rather good browser integration for KeePass now, I just switched a few weeks ago from LastPass.

Check out http://keepass.info/plugins.html (I use PassIFox and ChromeIPass via KeePassHttp)

Re: LogMeIn acquires Lastpass

#212

Huh. Gotta admit, I'm rather distressed by this, but I'm trying to think through it logically. * They still don't have access to my raw passwords. Everything's already encrypted before it gets to them, and they don't have the key. They just store the encrypted data. * They however do control access to the account. This means there's a point where they get all sorts of data on me, and while I personally don't mind, I…

This isn't quite a reason to jump ship for me yet, but I'll certainly be duplicating work to other services(which so far, I've found to be quite inferior). Did you try 1Password (which works with Dropbox, Wifi sync, etc.)? Not affiliated with them, just a happy customer.

I actually did an evaluation of password storage services recently and chose LastPass over 1Password for a couple reasons:

1. 1Password is SUPER expensive for what it is. You really pay for the fact that it looks nice and integrates well with mac.

2. It has no enterprise level features (This is for my organization) such as user management, access logging and fine grained roles and sharing.

1Password might be good for an individual or a small team, but it's too simple for anything beyond that.

Re: LogMeIn acquires Lastpass

#214

I'd really love for some objective person to weigh in about why all the negative reaction to this. Is LogMeIn a terrible company? I have not used either LogMeIn or LastPass.

IMO not all that LogMeIn is a good/bad company, it's that LastPass was sold. Their (your) data is being moved from one company to another.

It's certainly possible that LogMeIn stays hands-off and LastPass continues all operations exactly as they did before, but then why would LastPass sell?

LogMeIn paid $x money for LastPass, and they intend to make $x + $y money for it, by doing things that LastPass was either unable or unwilling to do (otherwise, LastPass wouldn't have sold).

Usually this means that LogMeIn is going to try to "extract more value" from the customer.

Re: LogMeIn acquires Lastpass

#216

Earlier quoted context omitted.

This is true, but my first reaction was as a LastPass customer not as an observer of the company. I also agree with colinplamondon's comment "The thing I liked about LastPass was that it seemed like the highly geeky, less startupy approach to password managers, more likely to be run for the long-term, less likely to be at risk of an acquisition." So the thought of them seeking an exit never crossed my mind.

makes the point that this startup culture with a focus on exits and maker founders and VCs rich is often not beneficial to our customers

And I think at some point the customers are going to figure out that the startup merry-go-round is and never was intended for their benefit. Over time it's going to get harder for new startups to attract customers because people will realize that flashy new product offerings aren't likely to stick around (in a form that we actually want) for long.

Re: LogMeIn acquires Lastpass

#217
post #98

Earlier quoted context omitted.

You should be using VeraCrypt ( https://veracrypt.codeplex.com/ ) rather than TrueCrypt. The authors of TrueCrypt even said to stop using it when they stopped maintaining it.

Yeah, I should. But Arch doesn't provide packages for it yet and there's no realistic attack vector against my usage of TrueCrypt, so meh. It's good enough until Arch starts shipping packages.

You can use Linux's own cryptsetup to mount TrueCrypt volumes. No TrueCrypt needed. There's documentation on the ArchWiki. https://wiki.archlinux.org/index.php/TrueCrypt

Re: LogMeIn acquires Lastpass

#218
post #110

https://passopolis.com/ - I'm using this (formerly known as Mitro) Open source

I see a bunch of lame commits like changing logos and names and no actual work on mitro -- not sure how encouraging that is, since you've already jumped at changing the name and making a company around it.

Perhaps the original app was feature complete and not a lot of work needed to be done on it? It's based on a third party password management service that open sourced its code before shuttering, so this would naturally be step one in relaunching something based on that code.

Re: LogMeIn acquires Lastpass

#220
post #154

Huh. Gotta admit, I'm rather distressed by this, but I'm trying to think through it logically. * They still don't have access to my raw passwords. Everything's already encrypted before it gets to them, and they don't have the key. They just store the encrypted data. * They however do control access to the account. This means there's a point where they get all sorts of data on me, and while I personally don't mind, I…

> "They however do control access to the account. This means there's a point where they get all sorts of data on me, and while I personally don't mind, I must admit I felt a bit safer when I thought it was a smaller, purpose-built company managing things." I've never really understood the appeal of account-based password managers. It was a startup and it needed a business model, sure, so from the company's perspectiv…

But if an attacker steals your Keepass file and acquires your password you won't notice.

Lastpass can detect logins from new IP adresses and throttle requests, send warning mails etc.

But sure, once their servers are cracked and their plugin is infected with master-password-stealing code it's all game over.

Post reply on HN