Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

241–250 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#241
post #43

LP has a history of problems, but my company forces us to use that crappy product. I've complained about it for years. I use keepassx for personal, 1password for work, and lastpass for anything that I need to share with coworkers. I always wondered who got the kickback from LP.

>LP has a history of problems, but my company forces us to use that crappy product. I've been using them the better part of a decade, I've never had an issue and find calling it a 'crappy product' to be shocking. What sort of issues have you had?

Before I switched to another password manager, LP has:

- constantly managed to lose newly generated passwords

- consistently failed to register new passwords with the Safari extension

- failed to autofill credentials on many websites

I had used LP for years, but these problems never went away despite these being a failure of core functionality. After I finally switched to an alternative password manager, I was pleasantly surprised at how well everything seemed to work in addition to a much nicer UI.

In LP's defense, it's great that they offer such an important service for free, but I'd really prefer my password manager to be of more higher quality.

Re: LastPass stores passwords so securely, not even its users can access them

#242
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

Bitwarden is also very good

Same here. very happy paying for customer as well

Re: LastPass stores passwords so securely, not even its users can access them

#243
post #7

So glad I switched to 1Password, haven't had an issue since. They provide an easy transfer of your passwords from LastPass, you can just follow their guide and be done in 5 minutes: https://support.1password.com/import-lastpass/

Bitwarden is also very good

Looks good, except I'm surprised by 'pay more to a third company to use MFA' in the enterprise offering. I'd expect MFA to be part of the enterprise offering and not require me to trust another company.

Re: LastPass stores passwords so securely, not even its users can access them

#244

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

Doesn't it worry you that Bitwarden is essentially maintained by one person [0]?

What if that person gets run over tomorrow and nobody knows the password for the AWS account. Imagine how long it'll take for somebody get around the huge code base on their own.

[0] https://github.com/bitwarden/server/graphs/contributors

Re: LastPass stores passwords so securely, not even its users can access them

#245

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

Doesn't it worry you that Bitwarden is essentially maintained by one person [0]? What if that person gets run over tomorrow and nobody knows the password for the AWS account. Imagine how long it'll take for somebody get around the huge code base on their own. [0] https://github.com/bitwarden/server/graphs/contributors

You could easily export your passwords if needed and leave bitwarden in that case.

Now I think there is a scenario where the maintainer gets bussed and bitwarden later goes down after some months resulting in lost passwords.

Re: LastPass stores passwords so securely, not even its users can access them

#246

Earlier quoted context omitted.

Switched from LastPass to BitWarden over the weekend. I have 1,200+ passwords, and the transition was seamless. I even set up BitWarden on one of my web servers so that I can control my data -- even that took less than 30 minutes, thanks to BitWardenRS docker container. The only thing I have yet to figure out for BitWarden is how to get a little icon to show up next to user/password fields in forms. I just have to ri…

Is there an exporter available for BitWarden then? I'm guessing your 1,200 password had a seamless transition because of some tooling the project provides? Is that correct? Cheers.

I suppose seamless may have been an oversell. I consider it seamless because BitWarden provides the import functionality for a variety of competitors' exports (XMLs, CSVs, etc), so all I had to do was export my LastPass passwords to my desktop and then import it into BitWarden via the web interface. HTH

Re: LastPass stores passwords so securely, not even its users can access them

#247

Earlier quoted context omitted.

Doesn't it worry you that Bitwarden is essentially maintained by one person [0]? What if that person gets run over tomorrow and nobody knows the password for the AWS account. Imagine how long it'll take for somebody get around the huge code base on their own. [0] https://github.com/bitwarden/server/graphs/contributors

You could easily export your passwords if needed and leave bitwarden in that case. Now I think there is a scenario where the maintainer gets bussed and bitwarden later goes down after some months resulting in lost passwords.

I keep an offline, encrypted backup of my Bitwarden data in a safe place. If something happens I can quickly spin up a bitwarden-rs instance, or go back to KeePass.

Re: LastPass stores passwords so securely, not even its users can access them

#248

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

Also check out this Bitwarden-compatible server written in Rust[0]. I've been using it for 2 years now and had exactly 0 problems with it.

[0] https://github.com/dani-garcia/bitwarden_rs

Re: LastPass stores passwords so securely, not even its users can access them

#249

Earlier quoted context omitted.

Switched from LastPass to BitWarden over the weekend. I have 1,200+ passwords, and the transition was seamless. I even set up BitWarden on one of my web servers so that I can control my data -- even that took less than 30 minutes, thanks to BitWardenRS docker container. The only thing I have yet to figure out for BitWarden is how to get a little icon to show up next to user/password fields in forms. I just have to ri…

Given you use Firefox, have you considered using the built in Sync service and companion Lockwise mobile app: https://hacks.mozilla.org/2018/11/firefox-sync-privacy/ I seriously considered Bitwarden not so long ago when I was looking for a password manager, and then realized I also need to maintain bookmarks across platforms and devices. Sadly Bitwarden doesn't offer that as a feature. I'm curious if there is a diffe…

I'm not the parent comment, but I did consider Lockwise but the inability to store anything else than passwords is a dealbreaker. I have some software license keys and their receipts stored securely, as well as some network accounts that are not web-based.

Re: LastPass stores passwords so securely, not even its users can access them

#250

Earlier quoted context omitted.

I hear "the cost of electricity" thrown out a lot for self running a small service. A Pi uses ~2W. At $0.11/kWh, running that constantly is ~$1.93 a year. Of course electricity rates vary, but I usually find the cost of electricity to be overblown when it comes to compute. Power can be very cheap. However, I imagine spending an hour of your time is more than that $10 budget.

Yes, my time is worth more than $10/hour. Also, I've never run a Pi for more than a few years without the SD card failing. Even when logging to a ram disk, something seems to fail eventually, and it is sometimes not found until the unit is rebooted.

You can make the Pi boot over USB, I do that with more important stuff with a SATA SSD attached over USB.

Of course, I have a backup of the important data as well.

Post reply on HN