Live data from Hacker News

LastPass’ Authenticator app is not secure

medium.com

41–50 of 118 posts

Re: LastPass’ Authenticator app is not secure

#41

Earlier quoted context omitted.

1Password more secure? Surely you're joking.

Seems folks forget just how poor of a job they were doing only a year ago. SIK-2016-038: Subdomain Password Leakage in 1Password Internal Browser SIK-2016-039: Https downgrade to http URL by default in 1Password Internal Browser SIK-2016-040: Titles and URLs Not Encrypted in 1Password Database SIK-2016-041: Read Private Data From App Folder in 1Password Manager SIK-2016-042: Privacy Issue, Information Leaked to Vendo…

Wasn’t aware of these, but just solidifies my move away from 1PW.

Re: LastPass’ Authenticator app is not secure

#42
post #36
post #28

Earlier quoted context omitted.

It means if someone hacks into their forums and gets credentials then all your passwords are open to them.

Why? 1.) LastPass login page hashes MasterPassword on the login page to produce a hash 2.) Hash is sent to the forums, and is checked against the same hash as the vault system 3.) Hash is confirmed, and you're logged in. 1.) Later hash is grabbed by an attacker. 2.) Attacker sends the hash to get the encrypted vault 3.) Attacker gets the encrypted vault 4.) Attacker is sad, because they don't have the MasterPassword,…

[deleted]

Re: LastPass’ Authenticator app is not secure

#43
post #3

I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.

1. It's not easy to have all the integrations necessary to make this product 2. There ultimately doesn't appear to be that much money in it compared to other businesses 3. The least secure password manager is more willing to do the unsafe thing that is a killer feature that users want.

Re: LastPass’ Authenticator app is not secure

#44
post #19
post #3

I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.

The ability to fill password in Android app. The last time I checked there's no competitors doing this. I'm hoping the Autofill API in Android Oreo can bring more competition.

Dashlane does that.

Re: LastPass’ Authenticator app is not secure

#45
post #36
post #28

Earlier quoted context omitted.

It means if someone hacks into their forums and gets credentials then all your passwords are open to them.

Why? 1.) LastPass login page hashes MasterPassword on the login page to produce a hash 2.) Hash is sent to the forums, and is checked against the same hash as the vault system 3.) Hash is confirmed, and you're logged in. 1.) Later hash is grabbed by an attacker. 2.) Attacker sends the hash to get the encrypted vault 3.) Attacker gets the encrypted vault 4.) Attacker is sad, because they don't have the MasterPassword,…

0.) LastPass login page is hacked with a skimmer.

1.) Game over.

Re: LastPass’ Authenticator app is not secure

#46
post #19
post #3

I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.

The ability to fill password in Android app. The last time I checked there's no competitors doing this. I'm hoping the Autofill API in Android Oreo can bring more competition.

1password registers a specific keyboard... but I'm not a big fan of that method. It's a terrible keyboard tbh.

Re: LastPass’ Authenticator app is not secure

#47
post #36
post #28

Earlier quoted context omitted.

It means if someone hacks into their forums and gets credentials then all your passwords are open to them.

Why? 1.) LastPass login page hashes MasterPassword on the login page to produce a hash 2.) Hash is sent to the forums, and is checked against the same hash as the vault system 3.) Hash is confirmed, and you're logged in. 1.) Later hash is grabbed by an attacker. 2.) Attacker sends the hash to get the encrypted vault 3.) Attacker gets the encrypted vault 4.) Attacker is sad, because they don't have the MasterPassword,…

1.) Find exploit in forum software/server.

2.) Modify login.php to send form username/password to attackers server.

Re: LastPass’ Authenticator app is not secure

#48

Earlier quoted context omitted.

> What makes LastPass inferior to these other options? Well, for one, the very first sentence of the article here.

The article whose "exploit" requires handing your unlocked phone to someone?

And which just got revealed,and will probably be fixed.

Re: LastPass’ Authenticator app is not secure

#49
post #3

I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.

They're owned by Citrix so they have automatic credibility.

In this case, the name is important too. It's easy to remember and it explains the product as well. The only alternative with a better name is 1password

Re: LastPass’ Authenticator app is not secure

#50

Earlier quoted context omitted.

I have at least 50 different passwords in my 1Password account And 1Password supports syncing via services other than their own and each device acts as its own backup too, so you’re really only relying on their service to shuttle around an encrypted keystore to your new devices.

Ok, but the core of the argument to me is "Is having a bunch of passwords that you don't actually know all in one place more secure than having a smaller bunch of passwords that you do actually know that, still, can at most be leaked one at a time?" For me the answer is no. I would rather have fewer technically less secure passwords than have technically more secure passwords that all live in one place. My passwords…

>Is having a bunch of passwords that you don't actually know all in one place more secure than having a smaller bunch of passwords that you do actually know that, still, can at most be leaked one at a time?

It’s been repeatedly demonstrated that yes, it is.

Post reply on HN