Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

271–280 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#271
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

> safe and secure with end-to-end encryption for all Vault data, including website URLs end-to-end encryption means something like https, it's a communication quality between trusted parties https://www.ibm.com/topics/end-to-end-encryption

Unless I misunderstood you, the article directly contradicts your point:

> Password managers [...] In this case, however, the user is on both endpoints and is the only person with a key.

Re: The situation at LastPass may be worse than they are letting on

#272
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

And Bitwarden can be self-hosted for those that are weary about using SaaS password managers.

Nitpick: "weary" == "tired", "wary" == cautious

Re: The situation at LastPass may be worse than they are letting on

#273

Earlier quoted context omitted.

I see a lot of people mentioning bitwarden around here; is their actually a technical reason to believe they are better than Lastpass or any of their competition (have they like open sourced all their stuff?). There’s very little room for failure and learning in the online password safe field, so I generally assume these companies are in one of two states: * has unknown bugs waiting to be revealed * out of business

> is their actually a technical reason to believe they are better than Lastpass or any of their competition (have they like open sourced all their stuff?). You can see their server and client code here: https://github.com/bitwarden I choose to use their clients unmodified, along with an instance of the server formerly known as "bitwarden_rs" running in my basement as the sync backend. https://github.com/dani-garcia/v…

> You can see their server and client code here: https://github.com/bitwarden

But in the case of the mobile apps, downloaded from their respective platform's app store, how can you guarantee the code you see on github is the exact same code you're running on your device?

Admittedly this supply-chain-verification is an issue for all mobile app store apps but seems particularly important with something like a password manager.

Re: The situation at LastPass may be worse than they are letting on

#275
post #270
post #265

Earlier quoted context omitted.

> someone who has some idea what they're talking about "I suspected someone used a 0day on me" is not exactly inspiring confidence

Why not? I have a security background. I see nothing wrong with that statement. Although what he actually said was: "Initially I imagined I was targeted by a 0day or rootkit" which actually does not make sense, because it implies he thinks those two things are fungible. He's obviously not a security expert, but he's also obviously not totally technically incompetent.

It's quite unlikely someone would risk burning a viable 0day without either going wide (and then we would've heard from a few more people) or going after a well outlined target that would be guaranteed to be worth more than the 0day itself.

Re: The situation at LastPass may be worse than they are letting on

#276

So is there any way to verify what this person is saying? I mean, from the way LastPass is evolving it doesn't seem unlikely to me -- but why is this tweet on HN? Is there any supporting evidence aside from an anecdote, does this Twitter account have a strong reputation of being credible, etc.? Without context, I just don't understand why this anecdotal thread should be considered credible. Disclaimer: I use FOSS pas…

This. Why would we be critical of LastPass being secretive and/or wrong and then take a tweet at face value?

From one of the tweets:

> I did not download anything. My machines are clean, and I have physical 2fa on everything. None of the links or contracts I interacted with were malicious. Nobody else had physical access to my PC.

Yeah sure. Sounds like my aunt when she messed up her PC and loudly claims "but I didn't do anything!" Surefire sign that she did. Turns out it's true, every time.

Re: The situation at LastPass may be worse than they are letting on

#277
post #270
post #265

Earlier quoted context omitted.

> someone who has some idea what they're talking about "I suspected someone used a 0day on me" is not exactly inspiring confidence

Why not? I have a security background. I see nothing wrong with that statement. Although what he actually said was: "Initially I imagined I was targeted by a 0day or rootkit" which actually does not make sense, because it implies he thinks those two things are fungible. He's obviously not a security expert, but he's also obviously not totally technically incompetent.

[deleted]

Re: The situation at LastPass may be worse than they are letting on

#278

I've been using LastPass for years. Looks like I'm going to have to export everything from my LP vault and import it into Bitwarden. Any downsides to Bitwarden that anyone knows of? I'm asking more about convenience, i.e. how well the browser extensions and Android app work and less about security.

> Any downsides to Bitwarden that anyone knows of?

UI\UX is bad. I tried switching to it from 1P, but went back after four months because I'd rather pay more than suffer daily.

Re: The situation at LastPass may be worse than they are letting on

#280
A few years ago, I made the decision to delete my LastPass account. At the time, I wasn't sure if it was the right move, but in light of the recent data leak, I couldn't be happier with my decision. If you're in the market for a new password manager, I highly recommend giving Bitwarden a try. It's open-source and has a strong focus on security and privacy.
Post reply on HN