Live data from Hacker News

LastPass: Security done wrong

palant.de

51–60 of 221 posts

Re: LastPass: Security done wrong

#51

I've been a LastPass user for a few years and I use the browser extension everyday. As an admin of several websites, the the extension has been a time saver. I thought I had no illusions about the inherent insecurity in using LastPass, but I guess I was wrong. I use Yubikey and disabled autofill long ago, but I was still vulnerable. Their response to these exploits is maddening. "Our investigation to date has not ind…

I'm a big fan of 1Password.

Re: LastPass: Security done wrong

#52

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

Check out 1Password.

Re: LastPass: Security done wrong

#54

http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.

Would love to hear from someone who has an iPhone and uses Keepass or a derivative. That's my last barrier to using it.

Re: LastPass: Security done wrong

#55

http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.

You can also add in KeepassHttp + PassIFox. But I wonder if these might have similar vulnerabilities as they too would be handling decrypted passwords.

Re: LastPass: Security done wrong

#56

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

If you're open to a paid option, 1Password for Teams/Families a good one. You can transfer from LastPass via CSV (https://support.1password.com/import-lastpass/).

Re: LastPass: Security done wrong

#57
post #3

Interested to hear what the HN community thinks about 1Password

Initially hesitated to switch to 1Password since some of our team used Linux but eventually we all switched to Mac so that went away.

Much happier with 1Password since we switched from Lastpass. Consistent UI, proper OS integration, multiple separate vaults, not to mention the security story seems better (I've seen several LP vulnerabilities of concern but not yet seen a 1PW one that worried me).

Re: LastPass: Security done wrong

#58

I would love to switch to a different password manager, but nothing else I've tried has quite managed to nail the usability aspect. Specifically, Lastpass's app fill functionality on Android is a huge benefit that I haven't seen in others. It also has a browser extension that works without a separate program running on your computer; I didn't even realize that was a plus until I started trying to use other apps that…

Usability is great, but we're talking about our passwords. Security needs to be put ahead of usability in this case. If you can get both that's great, but poor usability beats having your banking and systems owned.

Why would people put their bank and other important passwords like this in a password manager?

I use lastpass for over 5 years and I memorize my lastpass and my bank account passwords.

Re: LastPass: Security done wrong

#59
post #17

I used it (1P) and it was super, but mac only - no Linux client. Just switched over to Enpass, and its very like 1Password, only they do provide a linux client. So far its great, very happy with it. * reply to comment above re 1Password

"* reply to comment above re 1Password"

Why are you copy and pasting it again in the same thread?

Re: LastPass: Security done wrong

#60
post #50

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

Keepass imports from Lastpass [0]. Not that meets the rest of your requirements, but Keepass + KeepassHttp + PassIFox work beautifully for me. Autofills my logins and fully integrates with Firefoxes password manager so that you don't get conflicts between the browser and your password manager trying to save the same password. Also doesn't add the stupid CSS hacking that LastPass does to add their logo into the passwo…

Clickable: http://keepass.info/help/base/importexport.html
Post reply on HN