Live data from Hacker News

LastPass: Security done wrong

palant.de

41–50 of 221 posts

Re: LastPass: Security done wrong

#41
post #40

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

Dashlane does! Been using it for a year or so. Good experience. https://csdashlane.zendesk.com/hc/en-us/articles/202699141-H...

I will fully investigate Dashlane. I turned a lot of my non-technical friends onto password managers, and will need to update my recommendation for them with something that can both import the LastPass DB and be as convenient to use.

Re: LastPass: Security done wrong

#42
post #40

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

Dashlane does! Been using it for a year or so. Good experience. https://csdashlane.zendesk.com/hc/en-us/articles/202699141-H...

I switched away from Dashlane after several years because their software has been getting progressively more unstable. Force-killing the Dashlane executable because the browser plugin has locked up got pretty old.

Re: LastPass: Security done wrong

#43
post #36
post #17

I used it (1P) and it was super, but mac only - no Linux client. Just switched over to Enpass, and its very like 1Password, only they do provide a linux client. So far its great, very happy with it. * reply to comment above re 1Password

I use `pass` on linux/mac, which creates a directory of .pgp encrypted plaintext files for each password for each website. https://www.passwordstore.org/ I sync this directory to my mobile device using megasync (linux packages and Android app available). https://aur.archlinux.org/packages/megasync/ https://play.google.com/store/apps/details?id=mega.privacy.a... Then I use `pass` on Android via the "Password Store" ap…

[deleted]

Re: LastPass: Security done wrong

#44

From a strict security standpoint, maybe all of this is true. But I see strong PR as a feature, not a bug...at least until password manager market penetration is closer to 100% than it is to 0%. Once you've adopted a password manager, you've limited the scope of potential abuse, and you've decreased the pain of recovering from abuse that does happen . Being forced to change passwords used to be a stressful problem fo…

These are security critical pieces of software. Like, AV, if the password manager makes it easier to compromise your access in bulk, that's a very very bad thing. This doesn't need to be targeted, just throw some JS into an ad and pwn up 100s of 1000s of accounts. That's actually worse.

Re: LastPass: Security done wrong

#45

I would love to switch to a different password manager, but nothing else I've tried has quite managed to nail the usability aspect. Specifically, Lastpass's app fill functionality on Android is a huge benefit that I haven't seen in others. It also has a browser extension that works without a separate program running on your computer; I didn't even realize that was a plus until I started trying to use other apps that…

Usability is great, but we're talking about our passwords. Security needs to be put ahead of usability in this case.

If you can get both that's great, but poor usability beats having your banking and systems owned.

Re: LastPass: Security done wrong

#46
post #36
post #17

I used it (1P) and it was super, but mac only - no Linux client. Just switched over to Enpass, and its very like 1Password, only they do provide a linux client. So far its great, very happy with it. * reply to comment above re 1Password

I use `pass` on linux/mac, which creates a directory of .pgp encrypted plaintext files for each password for each website. https://www.passwordstore.org/ I sync this directory to my mobile device using megasync (linux packages and Android app available). https://aur.archlinux.org/packages/megasync/ https://play.google.com/store/apps/details?id=mega.privacy.a... Then I use `pass` on Android via the "Password Store" ap…

If you want to have some more features than default pass while keeping your third party apps there's also gopass (https://news.ycombinator.com/item?id=13551692) that was posted a while ago.

Re: LastPass: Security done wrong

#48
post #19

I wonder if 1Password is equally susceptible or less so, due to the way that the extension works. Because 1Password has a native application, I believe the browser extensions merely communicate with the native application to retrieve passwords to fill when needed, instead of handling your whole decrypted vault.

Precisely this. The LastPass extension actually handles the decryption, whereas the 1Password one merely communicates with the app. 1Password should therefore be significantly more secure.

If it auths the application, which it didn't for quite some time. Tavis has found plenty of issues with 1Password and their team has been much more hostile and less responsive.

Re: LastPass: Security done wrong

#49
I've been a LastPass user for a few years and I use the browser extension everyday. As an admin of several websites, the the extension has been a time saver.

I thought I had no illusions about the inherent insecurity in using LastPass, but I guess I was wrong. I use Yubikey and disabled autofill long ago, but I was still vulnerable. Their response to these exploits is maddening. "Our investigation to date has not indicated that any sensitive user data was lost or compromised." This when they can't verify if passwords were compromised as LastPass servers weren't involved in this exploit.

So I guess I need to switch to a different service. Any suggestions?

Re: LastPass: Security done wrong

#50

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

Keepass imports from Lastpass [0]. Not that meets the rest of your requirements, but Keepass + KeepassHttp + PassIFox work beautifully for me.

Autofills my logins and fully integrates with Firefoxes password manager so that you don't get conflicts between the browser and your password manager trying to save the same password. Also doesn't add the stupid CSS hacking that LastPass does to add their logo into the password fields breaking various site's styles.

  [0]: http://keepass.info/help/base/importexport.html
Post reply on HN