I wonder if 1Password is equally susceptible or less so, due to the way that the extension works. Because 1Password has a native application, I believe the browser extensions merely communicate with the native application to retrieve passwords to fill when needed, instead of handling your whole decrypted vault.
LastPass: Security done wrong
31–40 of 221 posts
Re: LastPass: Security done wrong
#32Once you've adopted a password manager, you've limited the scope of potential abuse, and you've decreased the pain of recovering from abuse that does happen. Being forced to change passwords used to be a stressful problem for me, and now it is not. Before, I would procrastinate changing passwords after a breach, because I knew how hard it would be. With lastpass, I literally changed every password in my vault in less than a half hour.
The PR matters because it's too easy to hear some bad news and give up on trying to be secure. If the PR prevents people from giving up, I'm all for it.
Re: LastPass: Security done wrong
#33Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass.
Don't suppose there's anything out there that can import the lastpass db?
Re: LastPass: Security done wrong
#34I'm interested to hear what the HN community thinks about keeping passwords in iCloud-based Keychain (Safari) or whatever Google's alternative is called. I don't care about portability. Why would I want e.g. 1Password instead of simply using Apple Keychain. Thanks!
Re: LastPass: Security done wrong
#35Interested to hear what the HN community thinks about 1Password
I used 1Password for quite a long time but have since switched to LastPass mostly due to Linux compatibility and u2f integration
Re: LastPass: Security done wrong
#36I used it (1P) and it was super, but mac only - no Linux client. Just switched over to Enpass, and its very like 1Password, only they do provide a linux client. So far its great, very happy with it. * reply to comment above re 1Password
https://www.passwordstore.org/
I sync this directory to my mobile device using megasync (linux packages and Android app available).
https://aur.archlinux.org/packages/megasync/
https://play.google.com/store/apps/details?id=mega.privacy.a...
Then I use `pass` on Android via the "Password Store" app (and the APG app to manage my PGP keys on mobile).
https://play.google.com/store/apps/details?id=com.zeapo.pwds...
The whole UX is super easy. Basically just PGP, plaintext files, and copy/paste.
Re: LastPass: Security done wrong
#37Interested to hear what the HN community thinks about 1Password
I've taken it as a sign that 1Password must be a fairly good choice as I very, very rarely see it pop up on here.
Re: LastPass: Security done wrong
#38I guess for now I'll just turn off all of the automatic features like this I can find.
Re: LastPass: Security done wrong
#39I'm interested to hear what the HN community thinks about keeping passwords in iCloud-based Keychain (Safari) or whatever Google's alternative is called. I don't care about portability. Why would I want e.g. 1Password instead of simply using Apple Keychain. Thanks!
You can have high accessibility / ease of use or you can have high security. You can't have both.
By storing your info on a remote server, you are trusting they will protect your data. Maybe they will, maybe they won't.
It is just a matter of finding a balance you feel comfortable with. Personally, I don't store my passwords on any cloud service, carry them on a thumb drive and don't use services that expose them to the browser. Could I lose a thumb drive? Sure. I rate the chances of someone picking it up and knowing how to exploit it as very low.
Re: LastPass: Security done wrong
#40Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?
https://csdashlane.zendesk.com/hc/en-us/articles/202699141-H...