Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

241–250 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#241

Earlier quoted context omitted.

It’s basically what modern ddos protection does - the WASM computational calculation is a digital dew can.

Wait, so you're telling me that Cloudflare interstitial is running some PoW check on my client? I always thought that was just a way to let the user know they're being rate limited on Cloudflare's end.

Not sure if cloudflares does it but disable WASM/JavaScript and you’ll find some that do.

Re: The situation at LastPass may be worse than they are letting on

#242

Is there any reason to use these cloud based solutions when open source alternatives like KeepassXC is available?

Is there any reason to give someone else your password to store when you can just remember it or write it down somewhere safe?

Yes. Humans can't remember a sufficient number of sufficiently-complex passwords.

Re: The situation at LastPass may be worse than they are letting on

#243
post #96
post #44

Earlier quoted context omitted.

PigSty's Razor

I suggest "the LastPass Law"

They’re not worthy of having any law named for them, even a negative one. Really wish there was a Software Hall of Shame where they can go rest in infamy.

Re: The situation at LastPass may be worse than they are letting on

#244
post #160

Best to just use pass ( https://www.passwordstore.org/ ) with your own gpg key rather than rely on any 3rd party service. Then set up a git repository on a (free) google cloud instance, (or even use github/gitlab), and you're set to sync your passwords to all your devices.

This is less secure than using keepassxc, 1password, or another application with a 1st party well maintained browser extension. With keepassxc, 1password, or even chrome's password manager, if a phisher links you to "gmail.scammersite.info", even if it looks exactly like the real gmail login page, browser-integration will not fill in the password field. With pass, the default flow is to copy the password to your clip…

There is a really good browser extension for pass, called BrowserPass. It has auto fill with phishing protection. There is also a good Android app, called Android Password Store, which does the same for all of my apps. Both use GPG keys stored on my Yubikey.

Re: The situation at LastPass may be worse than they are letting on

#245
post #61

Earlier quoted context omitted.

It all depends on how the data are encrypted. With a sensible design capturing the encrypted storage will only reveal the number of encrypted records, rough estimates on their size, and time stamps.

Ideally it would be an opaque blob with no information about the number of records or their size, just the total size and maybe a last modified or accessed time.

Password managers typically offer to store images like document scans. Without per record encryption one needs to send the whole encrypted blob on each modification.

Re: The situation at LastPass may be worse than they are letting on

#247
post #125

Earlier quoted context omitted.

They still require that your vault be hosted by them though. Terrible policy.

*for some. For those of us that have been using it for long enough, we can still use the "classic" version stuck at v7, but it means being able to self host. no monthly SaaS fees.

From what I can tell, v7 is Intel-only. That means when Apple sunsets Rosetta 2, it’s not going to work anymore. I’ll need to switch to something else before then, but hate Electron, and all the other options seem to use it (and now 1Password does, too).

Re: The situation at LastPass may be worse than they are letting on

#248

So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…

Quite obviously there isn't anything and the handle indicating a crypto hack it's as non-credible as anything can be but some folks on HN still fall for the crypto hype.

This is your regular reminder that all crypto is scam , this is a simple mathematical fact.

Re: The situation at LastPass may be worse than they are letting on

#249

Is there a site or something where you can put in all the devices you own (e.g., iPhone, Mac laptop, tablet, chromebook, etc) and what features you want (e.g., adding a password on one device syncs it automatically to all other devices, offline useage, auto fill of browser form fields, auto saves now username/passwords, etc.) and it will tell you what password manager best meets your needs?

https://en.m.wikipedia.org/wiki/List_of_password_managers As far as I can tell BitWarden and Google are the two good ones. I use BitWarden. My reasoning is anything new and experimental is scary, I want something with tons of users that's well established. If the community isn't all over it, it's probably not reviewed enough. Open source makes stuff a little more trustworthy, but by itself isn't enough. I also don't…

What do you mean by Google? I looked at the Wikipedia article, but didn’t see Google listed.

Re: The situation at LastPass may be worse than they are letting on

#250

So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…

> why is this tweet on HN

Is a meme

Post reply on HN