Live data from Hacker News

LastPass requesting password reset after facing unknown anomaly

blog.lastpass.com

41–50 of 66 posts

Re: LastPass requesting password reset after facing unknown anomaly

#41

That's the final straw for me. Just exported my login details, emptied out my lastpass vault and uninstalled the addon. Will stick to storing my login details in a Dropbox distributed GnuPG protected flat file. Less convenient, but at least I'm not reliant on a third party.

You still rely on Dropbox.

Re: LastPass requesting password reset after facing unknown anomaly

#42

That's the final straw for me. Just exported my login details, emptied out my lastpass vault and uninstalled the addon. Will stick to storing my login details in a Dropbox distributed GnuPG protected flat file. Less convenient, but at least I'm not reliant on a third party.

You still rely on Dropbox.

As for not getting his passwords compromised: no, not more than a vpn user relies on internet to keep his data secret.

As for getting access to his data anytime: Yes, except if he has a backup.

Re: LastPass requesting password reset after facing unknown anomaly

#43
post #25

Interesting, it isn't prompting me to do any such thing. Anyway, since many are mentioning 1Password - I used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows. Also, since I use tw…

I used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows. I find that Keepass, with the database saved on my Dropbox folder, works well. No browser integration needed - Keepass regi…

Seconded.

Just wanted to add that it's possible to configure any auto-typing (the default is ${USER}TAB${PASS}), which means sites having all sorts of other info are easy to work with as well.

I actually wrote a blog post about using Keepass with various tricks: http://www.loopycode.com/solving-sign-up-anxiety/

Re: LastPass requesting password reset after facing unknown anomaly

#45

That's the final straw for me. Just exported my login details, emptied out my lastpass vault and uninstalled the addon. Will stick to storing my login details in a Dropbox distributed GnuPG protected flat file. Less convenient, but at least I'm not reliant on a third party.

You still rely on Dropbox.

In what way do I rely on Dropbox for securing or accessing my login details?

My passwords are encrypted and accessible at all times, even if Dropbox is down or I lack Internet access...

Re: LastPass requesting password reset after facing unknown anomaly

#46
post #42

Earlier quoted context omitted.

You still rely on Dropbox.

As for not getting his passwords compromised: no, not more than a vpn user relies on internet to keep his data secret. As for getting access to his data anytime: Yes, except if he has a backup.

I don't understand why you think I wont be able to access my data anytime? Dropbox synchronises the files so you have a local copy on each of your Dropbox hosts. So if Dropbox is offline, or you get disconnected from the Internet, you can still access them...

Worse case scenario is something causes the file to get deleted and that propagates to all of the other hosts and deletes their local copies. But yes, I have backups so that isn't a problem.

Re: LastPass requesting password reset after facing unknown anomaly

#47
post #25

Interesting, it isn't prompting me to do any such thing. Anyway, since many are mentioning 1Password - I used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows. Also, since I use tw…

I used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows. I find that Keepass, with the database saved on my Dropbox folder, works well. No browser integration needed - Keepass regi…

[deleted]

Re: LastPass requesting password reset after facing unknown anomaly

#48

So I just started using 1password and was thinking of lastpass. I'm still trying to figure out which is better. Anyone have any comments?

I would say use SHA1_Pass and never store, synchronize or forget a password again. I'm biased though, I wrote it and use it daily. It's entirely free, cross-platform (GPL licensed) and you can get the source code from github.

Edit: Also, SHA1_Pass does not rely on websites or anything remote from your device to operate. It just requires you (the user) and your brain ;) That's the biggest reason I wrote it.

Re: LastPass requesting password reset after facing unknown anomaly

#49
i'm surprised by the reactions here. maybe i am misunderstanding the blog post, or maybe others are?

as far as i can see they are being extremely paranoid. they seem to be monitoring (and following up on!) traffic flow, which is itself pretty impressive, are flagging this even though they have no other error signs, and have done a good enough job in their implementation that can say, without any more details, that the only risk is via brute force cracking.

i use keepassx locally, but my take on this is that they are way better than average. this kind of report would make me use a company, not switch from them.

Re: LastPass requesting password reset after facing unknown anomaly

#50
post #9

Suddenly, I'm glad I switched to 1Password.

Yeah 1Password is pretty awful when you consider the amount of features you get with LastPass like multi-factor authentication. 1Password relies on Dropbox. Your passwords are all stored on your computer. Granted they're in an encrypted format, but if you have a jerk for a room mate they could copy your encrypted files, key log your vault password, and have access to all your passwords. On the other hand, if you get…

But you can control the risk of exposure to keyloggers. You have zero control over risks to LastPass's infrastructure - which, as this blog post mentions, is a much juicier target than your passwords on their own.
Post reply on HN