So in response to this story I decided to delete my (premium) account with them. After confirming multiple times (good thing), I was shown this error: https://i.imgur.com/4dpn6d5.png How does error handling like this even make it to production? I got an email as well confirming my account deletion and I can no longer log in. But all in all this clearly does increase my trust in Lastpass's security competence.
LastPass stores passwords so securely, not even its users can access them
261–266 of 266 posts
Re: LastPass stores passwords so securely, not even its users can access them
#262Not actually related to the article, but the headline makes me think of the "Muddy Puddle Test" for crypto, which goes like this: 1) Drop your device(s) into a muddy puddle (destroying them). 2) Slip in said puddle so you hit your head. On waking up you're absolutely fine, but are entirely incapable of remembering your passwords or encryption keys. 3) Can you get your cloud data back? If you can, then it's not actual…
What about biometrics?
Re: LastPass stores passwords so securely, not even its users can access them
#263Earlier quoted context omitted.
Hi, I work for AgileBits, makers of 1Password. I can't comment on the defensive part, but text can often be harder to parse in conversation so perhaps it was that? I generally find our support team to be pretty understanding but I am sorry if our support team didn't properly handle your concerns and feedback. Feature parity is a tricky one. The Mac (and since it's shared code in a lot of ways, the iOS app) have been…
Kyle, for what it's worth as a counterpoint, I've grumbled a couple of times about bugs and the 1P team has not come across as defensive at all to me. Particularly after the nonsense support LastPass gives, it was a pleasant experience, even if my grumbles hold true. It's not a perfect product by any means but still light years better than LastPass in usability.
We can't be the tool for everyone and we're always the first to recognize bugs exist. Unfortunately we also aren't able to fix them all just like I'm sure most people around here have backlogged bugs in the applications they work on. But we do try to prioritize based on severity and how many people are impacted.
I do appreciate the kind words though. We're not perfect, never will be, but we can sure try our best and I think that's all anyone really wants out of themselves.
If you ever run into issues feel free to reach out as well. Happy to help however I can!
Kyle
1Password Security Team
Re: LastPass stores passwords so securely, not even its users can access them
#264Earlier quoted context omitted.
For Firefox there is https://addons.mozilla.org/en-US/firefox/addon/passff/ which I'm quite happy with. When combined with a yubikey set to decrypt only on touch this setup has a very low attack surface compared to other browser password managers.
This used to be my approach, but it prevented grepping through my password store (you have to touch the yubikey to decrypt each password separately) I since switched to a separate on-device key for "low value" passwords and keep the interesting stuff (e-mail pwds) under the yubikey protected key (which does requires touch). Did you find a better solution?
Apparently there is a new "cached" option for the touch settings "Touch is cached for 15s after use (valid from 4.3)." Which would work for your use case but also neglect some/most? of the security advantages.
Re: LastPass stores passwords so securely, not even its users can access them
#265I'm shocked to see a post of such low quality on hacker news. It reads like an instagram post or twitter replies. I'm not familiar with "theregister.co.uk" but I honestly think it's the lowest quality article I've ever seen on this website
> I'm not familiar with "theregister.co.uk" Then you're not qualified to be discussing software or the tech industry, frankly.
Re: LastPass stores passwords so securely, not even its users can access them
#266I'm shocked to see a post of such low quality on hacker news. It reads like an instagram post or twitter replies. I'm not familiar with "theregister.co.uk" but I honestly think it's the lowest quality article I've ever seen on this website
> I'm not familiar with "theregister.co.uk" Then you're not qualified to be discussing software or the tech industry, frankly.