Live data from Hacker News

LastPass: Security done wrong

palant.de

31–40 of 221 posts

Re: LastPass: Security done wrong

#31
post #19

I wonder if 1Password is equally susceptible or less so, due to the way that the extension works. Because 1Password has a native application, I believe the browser extensions merely communicate with the native application to retrieve passwords to fill when needed, instead of handling your whole decrypted vault.

Precisely this. The LastPass extension actually handles the decryption, whereas the 1Password one merely communicates with the app. 1Password should therefore be significantly more secure.

Re: LastPass: Security done wrong

#32
From a strict security standpoint, maybe all of this is true. But I see strong PR as a feature, not a bug...at least until password manager market penetration is closer to 100% than it is to 0%.

Once you've adopted a password manager, you've limited the scope of potential abuse, and you've decreased the pain of recovering from abuse that does happen. Being forced to change passwords used to be a stressful problem for me, and now it is not. Before, I would procrastinate changing passwords after a breach, because I knew how hard it would be. With lastpass, I literally changed every password in my vault in less than a half hour.

The PR matters because it's too easy to hear some bad news and give up on trying to be secure. If the PR prevents people from giving up, I'm all for it.

Re: LastPass: Security done wrong

#33
Sigh. I can't ignore the red flags anymore. Time to switch off.

Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass.

Don't suppose there's anything out there that can import the lastpass db?

Re: LastPass: Security done wrong

#34
post #25

I'm interested to hear what the HN community thinks about keeping passwords in iCloud-based Keychain (Safari) or whatever Google's alternative is called. I don't care about portability. Why would I want e.g. 1Password instead of simply using Apple Keychain. Thanks!

1Password has a lot more features than the default Keychain, smarter autofill to begin with. If that's worth it to you that depends on which features of 1Password you'd use.

Re: LastPass: Security done wrong

#35
post #5
post #3

Interested to hear what the HN community thinks about 1Password

I used 1Password for quite a long time but have since switched to LastPass mostly due to Linux compatibility and u2f integration

I used it (1P) and it was super, but mac only - no Linux client. Just switched over to Enpass, and its very like 1Password, only they do provide a linux client. So far its great, very happy with it.

Re: LastPass: Security done wrong

#36
post #17

I used it (1P) and it was super, but mac only - no Linux client. Just switched over to Enpass, and its very like 1Password, only they do provide a linux client. So far its great, very happy with it. * reply to comment above re 1Password

I use `pass` on linux/mac, which creates a directory of .pgp encrypted plaintext files for each password for each website.

https://www.passwordstore.org/

I sync this directory to my mobile device using megasync (linux packages and Android app available).

https://aur.archlinux.org/packages/megasync/

https://play.google.com/store/apps/details?id=mega.privacy.a...

Then I use `pass` on Android via the "Password Store" app (and the APG app to manage my PGP keys on mobile).

https://play.google.com/store/apps/details?id=com.zeapo.pwds...

The whole UX is super easy. Basically just PGP, plaintext files, and copy/paste.

Re: LastPass: Security done wrong

#37
post #4
post #3

Interested to hear what the HN community thinks about 1Password

I've taken it as a sign that 1Password must be a fairly good choice as I very, very rarely see it pop up on here.

Wrong metric to use. Just because nobody talks about it doesn't mean it's a "good" choice. It might be better for all you or I know, but using how many hacker news posts you see for something like this is not a good way to evaluate a product.

Re: LastPass: Security done wrong

#38
I would love to switch to a different password manager, but nothing else I've tried has quite managed to nail the usability aspect. Specifically, Lastpass's app fill functionality on Android is a huge benefit that I haven't seen in others. It also has a browser extension that works without a separate program running on your computer; I didn't even realize that was a plus until I started trying to use other apps that did that.

I guess for now I'll just turn off all of the automatic features like this I can find.

Re: LastPass: Security done wrong

#39
post #25

I'm interested to hear what the HN community thinks about keeping passwords in iCloud-based Keychain (Safari) or whatever Google's alternative is called. I don't care about portability. Why would I want e.g. 1Password instead of simply using Apple Keychain. Thanks!

Here is how I think about it: It is a spectrum.

You can have high accessibility / ease of use or you can have high security. You can't have both.

By storing your info on a remote server, you are trusting they will protect your data. Maybe they will, maybe they won't.

It is just a matter of finding a balance you feel comfortable with. Personally, I don't store my passwords on any cloud service, carry them on a thumb drive and don't use services that expose them to the browser. Could I lose a thumb drive? Sure. I rate the chances of someone picking it up and knowing how to exploit it as very low.

Re: LastPass: Security done wrong

#40

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

Dashlane does! Been using it for a year or so. Good experience.

https://csdashlane.zendesk.com/hc/en-us/articles/202699141-H...

Post reply on HN