Live data from Hacker News

LastPass’ Authenticator app is not secure

medium.com

51–60 of 118 posts

Re: LastPass’ Authenticator app is not secure

#51

The code, tech, and mindset behind LastPass is a joke. They started just after the “dark ages” of security but don’t seem to have upgraded their mental model of security since. I’ll share with you the moment I discovered something that made me cancel my schedule for the day, research alternatives, write a LastPass to 1Password converter [0], and cancel my LastPass account and subscription. Are you ready? You log in t…

Electronic password managers never made sense to me. While you can do more to secure a single target, it is a more valuable target and one mistake costs you all your passwords. For me a physical password journal is best. While it does make you vulnerable to physical attackers, the cost invest to target someone physically is so much higher that if I have to deal with that threat level I'm already a goner. Just have to hide it from the kids.

Re: LastPass’ Authenticator app is not secure

#52
post #3

I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.

KeePass is anything but user friendly or convenient - it involves a lot of tinkering and not a lot of people have time, patience, or even know-how for that. It has never been and I don't see that happening in near future. In comparison LastPass is "sign up once, use everywhere".

1Password royally ignored every other platform other than the fruit company ecosystem for a really long time.

See, I am not speaking as a fanboy, I am not one. Just a satisfied user - I have really tried all other apps out there and for some reason or the other I kept coming back to LastPass.

Bitwarden came close to make me switch. OSS, polished, and seemingly with a business model. After checking on Elementary Firefox, iOS, Android apps when I went find its Safari extension (that's where I do my personal browsing) - it didn't exist, it still doesn't and the Github issue is clear that they will not be working on that [0] anytime soon. Also, I read a reddit comment that there was only one full time developer and this was few weeks ago[1]. Now I know it's an open source project but I want to use a service that is really ready to be used for my password management.

LastPass - it's not really entirely browser based, it's actually available everywhere - Windows, Linux, Mac, Chrome, Ff, Safari, IE, iOS, Android. You name it. And it has been on these various platforms since long. Sync, client side encryption, easy import from other apps, good extensions, decent support ticket TATs (even for free accounts), continuous development (however I must add that they have started to add bloat and useless gloss after the sale) - have really been consistent. This is what makes it a favourite option.

So when you say "better designed" I assume you mean better security architecture designed and yes it is ease of use with acceptable security for the most.

[0] https://github.com/bitwarden/browser/issues/17

[1] https://www.reddit.com/r/Bitwarden/comments/7htswv/how_many_...

Re: LastPass’ Authenticator app is not secure

#53

Wow, color me surprised. Software developers aren't perfect, and closed source software with less eyes on it tends to be even less perfect. I will never trust my passwords all being in one place other than my brain.

This "problem" has precisely nothing to do with open source vs closed source. "Tell me the list of activities that are public" and "tell me the name of each activity as I launch it" are babies-first-app-analysis level and work equally well on open and closed source apps.

Are we really concerned about an exploit that requires somebody to have unlocked access to your phone?

Re: LastPass’ Authenticator app is not secure

#54

Earlier quoted context omitted.

You can't keep varied, secure passwords in your head unless you barely use any services.

You're right, but that doesn't mean he's better off with a password manager. No method of storage is perfectly secure. Password managers have their attack vectors, your brain has others.

The attack vectors against password managers tend to be more rare and more difficult to exploit.

Re: LastPass’ Authenticator app is not secure

#55

Earlier quoted context omitted.

Ok, but the core of the argument to me is "Is having a bunch of passwords that you don't actually know all in one place more secure than having a smaller bunch of passwords that you do actually know that, still, can at most be leaked one at a time?" For me the answer is no. I would rather have fewer technically less secure passwords than have technically more secure passwords that all live in one place. My passwords…

>Is having a bunch of passwords that you don't actually know all in one place more secure than having a smaller bunch of passwords that you do actually know that, still, can at most be leaked one at a time? It’s been repeatedly demonstrated that yes, it is.

>It's been repeatedly demonstrated

Meaning you have consulted a sea of research that has compared the risk posed by password managers to keeping a mental catalogue of long, not-random-but-pretty-good character strings, using 2fa, and exercising proper security habits?

I don't think you could ever come to an objective conclusion, since the 99%-user doesn't have a near-autistic obsession with security like most of us.

Re: LastPass’ Authenticator app is not secure

#56

Earlier quoted context omitted.

I have at least 50 different passwords in my 1Password account And 1Password supports syncing via services other than their own and each device acts as its own backup too, so you’re really only relying on their service to shuttle around an encrypted keystore to your new devices.

Ok, but the core of the argument to me is "Is having a bunch of passwords that you don't actually know all in one place more secure than having a smaller bunch of passwords that you do actually know that, still, can at most be leaked one at a time?" For me the answer is no. I would rather have fewer technically less secure passwords than have technically more secure passwords that all live in one place. My passwords…

The answer is yes. For the large majority of users, the only thing that matters is that you never reuse your passwords. Since human beings cannot feasibly remember unique passwords for each service, password managers win.

Re: LastPass’ Authenticator app is not secure

#57
post #22

Earlier quoted context omitted.

>You log in to their support forums and online community with the same password you decrypt your vault with. what's the issue with that? maybe they have some SSO system

They issue is that your vault key must never be available to their system, otherwise when they get hacked with the most trivial XSS now your vault is pwned. Password vaults are a hugely valuable target, worth potentially thousands of dollars on the black market, you absolutely should not be using a service that has the ability or can acquire the ability to decrypt your vault. You're better off with a plaintext file i…

Just to clarify this, because it took me a second, the point (if I understand you) is that your password is available to them at the point when you log in to their support forums. Particularly bad, because it's a site that hosts a ton of user content.

It's also really dumb, because the whole point of the product is to make it easy to not reuse passwords. They could have even had the signup process automatically create those accounts for you and insert the passwords into your vault, and it would have been just as easy for the user.

Re: LastPass’ Authenticator app is not secure

#58

The code, tech, and mindset behind LastPass is a joke. They started just after the “dark ages” of security but don’t seem to have upgraded their mental model of security since. I’ll share with you the moment I discovered something that made me cancel my schedule for the day, research alternatives, write a LastPass to 1Password converter [0], and cancel my LastPass account and subscription. Are you ready? You log in t…

My biggest gripe/concern with LastPass Enterprise (we use it) is that sharing/access control _never_ works properly. Every time we bring someone on and try to share folders or credentials with them, we end up needing a multi-hour support ticket to get everything resolved correctly. This shouldn't happen. It raises big alarms for me.

Do they ask you to confirm your master password over the phone so they can check on their end and see if they can reproduce the issue?

Re: LastPass’ Authenticator app is not secure

#59
post #19

Earlier quoted context omitted.

The ability to fill password in Android app. The last time I checked there's no competitors doing this. I'm hoping the Autofill API in Android Oreo can bring more competition.

keepassdroid lets you do that via copying data to the clipboard. Not a great solution, but it works

Every password manager allow you to copy/paste your password. This is NOT a solution.

Re: LastPass’ Authenticator app is not secure

#60
post #46
post #19

Earlier quoted context omitted.

The ability to fill password in Android app. The last time I checked there's no competitors doing this. I'm hoping the Autofill API in Android Oreo can bring more competition.

1password registers a specific keyboard... but I'm not a big fan of that method. It's a terrible keyboard tbh.

I was actually surprised that 1password never implemented in-app password fill using accessibility API.
Post reply on HN