Earlier quoted context omitted.
1Password more secure? Surely you're joking.
Seems folks forget just how poor of a job they were doing only a year ago. SIK-2016-038: Subdomain Password Leakage in 1Password Internal Browser SIK-2016-039: Https downgrade to http URL by default in 1Password Internal Browser SIK-2016-040: Titles and URLs Not Encrypted in 1Password Database SIK-2016-041: Read Private Data From App Folder in 1Password Manager SIK-2016-042: Privacy Issue, Information Leaked to Vendo…
LastPass’ Authenticator app is not secure
41–50 of 118 posts
Re: LastPass’ Authenticator app is not secure
#42Earlier quoted context omitted.
It means if someone hacks into their forums and gets credentials then all your passwords are open to them.
Why? 1.) LastPass login page hashes MasterPassword on the login page to produce a hash 2.) Hash is sent to the forums, and is checked against the same hash as the vault system 3.) Hash is confirmed, and you're logged in. 1.) Later hash is grabbed by an attacker. 2.) Attacker sends the hash to get the encrypted vault 3.) Attacker gets the encrypted vault 4.) Attacker is sad, because they don't have the MasterPassword,…
Re: LastPass’ Authenticator app is not secure
#43I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.
Re: LastPass’ Authenticator app is not secure
#44I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.
The ability to fill password in Android app. The last time I checked there's no competitors doing this. I'm hoping the Autofill API in Android Oreo can bring more competition.
Re: LastPass’ Authenticator app is not secure
#45Earlier quoted context omitted.
It means if someone hacks into their forums and gets credentials then all your passwords are open to them.
Why? 1.) LastPass login page hashes MasterPassword on the login page to produce a hash 2.) Hash is sent to the forums, and is checked against the same hash as the vault system 3.) Hash is confirmed, and you're logged in. 1.) Later hash is grabbed by an attacker. 2.) Attacker sends the hash to get the encrypted vault 3.) Attacker gets the encrypted vault 4.) Attacker is sad, because they don't have the MasterPassword,…
1.) Game over.
Re: LastPass’ Authenticator app is not secure
#46I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.
The ability to fill password in Android app. The last time I checked there's no competitors doing this. I'm hoping the Autofill API in Android Oreo can bring more competition.
Re: LastPass’ Authenticator app is not secure
#47Earlier quoted context omitted.
It means if someone hacks into their forums and gets credentials then all your passwords are open to them.
Why? 1.) LastPass login page hashes MasterPassword on the login page to produce a hash 2.) Hash is sent to the forums, and is checked against the same hash as the vault system 3.) Hash is confirmed, and you're logged in. 1.) Later hash is grabbed by an attacker. 2.) Attacker sends the hash to get the encrypted vault 3.) Attacker gets the encrypted vault 4.) Attacker is sad, because they don't have the MasterPassword,…
2.) Modify login.php to send form username/password to attackers server.
Re: LastPass’ Authenticator app is not secure
#48Re: LastPass’ Authenticator app is not secure
#49I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.
In this case, the name is important too. It's easy to remember and it explains the product as well. The only alternative with a better name is 1password
Re: LastPass’ Authenticator app is not secure
#50Earlier quoted context omitted.
I have at least 50 different passwords in my 1Password account And 1Password supports syncing via services other than their own and each device acts as its own backup too, so you’re really only relying on their service to shuttle around an encrypted keystore to your new devices.
Ok, but the core of the argument to me is "Is having a bunch of passwords that you don't actually know all in one place more secure than having a smaller bunch of passwords that you do actually know that, still, can at most be leaked one at a time?" For me the answer is no. I would rather have fewer technically less secure passwords than have technically more secure passwords that all live in one place. My passwords…
It’s been repeatedly demonstrated that yes, it is.