Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

241–246 of 246 posts

Re: LastPass notifies users of yet another data breach

#241

Earlier quoted context omitted.

Password managers are entirely a UX problem waiting to be solved better. Every time I hit a UX bug with my password manager, I mutter that I could do fix that, and then know that mine would also be worse in so many ways just to reach parity. What I wish is there was a public bug tracker of UX issues/optimizations that I, and the rest of the world, could log ideas to. Password managers are such a good idea but they al…

Can you give me an example of a UX problem that you attribute to the password manager? That'd help me understand. I often hit problems with 1Password's autofill on particular websites, but by and large I blame the website. Few examples: * one website expects me to type the PIN then a Symantec VIP OTP token into a single field called "password". That's a (possibly deliberately) password manager-hostile design. I final…

Thanks for the feedback. It's certainly a challenge to make 1Password work on every website that exists, and even more so to keep it working over time, especially with old items that people created years ago which no longer match the site. We do have a whole "filling and saving" team dedicated to the problem, and we do follow up when users report issues with sites.

I'd love to look into the Quick Access placement. It is supposed to appear on all spaces and sets an NSWindow property to do so. Is there anything particular that you think triggers it (multi-monitor, full screen apps, etc)?

Re: LastPass notifies users of yet another data breach

#242

Earlier quoted context omitted.

Can you give me an example of a UX problem that you attribute to the password manager? That'd help me understand. I often hit problems with 1Password's autofill on particular websites, but by and large I blame the website. Few examples: * one website expects me to type the PIN then a Symantec VIP OTP token into a single field called "password". That's a (possibly deliberately) password manager-hostile design. I final…

These are tiny paper cuts that add up to pain, like the ones you mentioned that affect me/a tiny portion of the user base so they aren't worth fixing. Is the justification I'm sure that's being made. For example, if site auto detection that you're submitting a form fails that you laboriously have to add field elements in and if the editor is on a different workspace on mac you have to go to the application space/desk…

(I'm Mitch from 1Password.) I do appreciate reading about these kinds of paper cuts and always follow up on them when I see them. We are going to address the item title issue next week, so thank you for that one.

It's true that sometimes very small/simple issues that affect some portiion of people can go for a long time. I'd like to find a better way of identifying these and getting to them quicker than just crawling through HN posts. If you have any thoughts or at least issues you'd like us to look into, always open to hear more.

Re: LastPass notifies users of yet another data breach

#243

Earlier quoted context omitted.

Can you give me an example of a UX problem that you attribute to the password manager? That'd help me understand. I often hit problems with 1Password's autofill on particular websites, but by and large I blame the website. Few examples: * one website expects me to type the PIN then a Symantec VIP OTP token into a single field called "password". That's a (possibly deliberately) password manager-hostile design. I final…

Thanks for the feedback. It's certainly a challenge to make 1Password work on every website that exists, and even more so to keep it working over time, especially with old items that people created years ago which no longer match the site. We do have a whole "filling and saving" team dedicated to the problem, and we do follow up when users report issues with sites. I'd love to look into the Quick Access placement. It…

> I'd love to look into the Quick Access placement. It is supposed to appear on all spaces and sets an NSWindow property to do so. Is there anything particular that you think triggers it (multi-monitor, full screen apps, etc)?

Thanks! I haven't seen it in a while, so maybe it's been fixed by either a 1Password or macOS update or is specific to a setting I since changed. But I'll keep my eyes out for if it happens again. I do have a multi-monitor setup.

I do see right now that if I'm on a full-screen app, 1Password's quick access window doesn't show up; if I move to the next space over I see it for a moment and then it disappears. In contrast, Spotlight search will actually pop up directly over my full-screen app, though knowing Apple they could be using some private API for this behavior.

Re: LastPass notifies users of yet another data breach

#245
post #175

Did lastpass also pull the dumbass 'no local vaults' move that 1password made? One of the nice things about a 'bring your own vault syncing' is that breaches like this don't have to mean a goddamned thing to you.

Not for this data, but in the past, yes - there is persistent pressure to do that for any maker of password managers, be it independent, in-browser or in-OS. (Source: I was a cofounder of a company that made a password manager as part of our product).

I mean it's a better forcing function to keep your customers constantly upgrading and tied to your platform. You can't just make good tools anymore, now you make mediocre tools that are sticky through dark patterns.

Re: LastPass notifies users of yet another data breach

#246
post #153

Earlier quoted context omitted.

But the phone number you have is not 100% in your control. I had AT&T flub something and I lost my number and they assigned me a new one (I was chanting my plan just after they did some merging with someone). Granted its unlikely but I would still use defense in depth and not have password reset be my only login method.

Thats totally fair and really scary since so many services think 2fa means texting or calling a phone number (my bank for example)

It's also why I always opt for 2FA that's within my control: a security key, TOTP, or an email address on a domain I own. That last one is the weakest, since I own the domain as long the registrar says I do but it's better than a corporation I can't get support from if my email account is locked for any reason.
Post reply on HN