That's not very smart considering that a lot of people won't be able to lockin to their email to verify their emails because they don't have access to the login details of their email because they haven't verified it. And why the hell didn't they use scrybt in the first place? For a company so paranoid, that seems to border on neglect.
LastPass make it pretty clear that your main email address is a point of recovery for your account. The two passwords I know are my LastPass master pass and my email password.
LastPass requesting password reset after facing unknown anomaly
51–60 of 66 posts
Re: LastPass requesting password reset after facing unknown anomaly
#52That's the final straw for me. Just exported my login details, emptied out my lastpass vault and uninstalled the addon. Will stick to storing my login details in a Dropbox distributed GnuPG protected flat file. Less convenient, but at least I'm not reliant on a third party.
Re: LastPass requesting password reset after facing unknown anomaly
#53Interesting, it isn't prompting me to do any such thing. Anyway, since many are mentioning 1Password - I used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows. Also, since I use tw…
I used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows. I find that Keepass, with the database saved on my Dropbox folder, works well. No browser integration needed - Keepass regi…
Edit: Some more negatives to password storage. Must protect stored password file. May be required to log access to stored password file for compliance reasons. Stored password files may become corrupt and stop working.
Re: LastPass requesting password reset after facing unknown anomaly
#54Earlier quoted context omitted.
I used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows. I find that Keepass, with the database saved on my Dropbox folder, works well. No browser integration needed - Keepass regi…
In my mind, that's the primary design flaw with traditional password managers. Why should end users store passwords? It introduces so many issues. Must have proper encryption. Must deal with synchronization. Must have master password. The list could go on and on. Passwords should be generated (locally on your device) when needed, and never stored in any way. Edit: Some more negatives to password storage. Must protect…
Re: LastPass requesting password reset after facing unknown anomaly
#55Earlier quoted context omitted.
In my mind, that's the primary design flaw with traditional password managers. Why should end users store passwords? It introduces so many issues. Must have proper encryption. Must deal with synchronization. Must have master password. The list could go on and on. Passwords should be generated (locally on your device) when needed, and never stored in any way. Edit: Some more negatives to password storage. Must protect…
I don't think I understand this - if the password isn't stored, do you expect the user to memorize all the various passwords?
I tried to make traditional password managers work for a number of years, before realizing that the traditional approach (password storage, master password) is fundamentally flawed and introduces more problems than it solves.
Re: LastPass requesting password reset after facing unknown anomaly
#56Re: LastPass requesting password reset after facing unknown anomaly
#57Wow, Lastpass won't let me login to my account now, and doesn't throw any error message whatsoever. When I try to change my password it says I can't because I don't have their browser plugin. Wacky, this is quite frustrating
Someone brought up the same issue in the comments on that post. Here's the solution given, two options: 1) Login in 'offline mode' then reconnect your cable/wireless connection and go to gmail... This is the preferred method. 2) Download Pocket, and have it find your local offline copy from the drop down of files and login there.
Re: LastPass requesting password reset after facing unknown anomaly
#58That's not very smart considering that a lot of people won't be able to lockin to their email to verify their emails because they don't have access to the login details of their email because they haven't verified it. And why the hell didn't they use scrybt in the first place? For a company so paranoid, that seems to border on neglect.
And that, right there, highlights why all of my passwords aren't kept with their (or any) service - for many, it just introduced a single point of failure. Imagine being locked out of every website you have an account on, just like that. Nope. I'll make strong passwords on my own and encrypt my own copies, thanks.
This is simply not a feasible solution for the general public. LastPass has demonstrated that they are 1. paranoid as hell and 2. that the only real vulnerability in this situation is that if you have a dictionary password, it may be able to be brute forced, if the worst case scenario happened. They even outlined steps that they are taking to fix this problem.
LastPass is an incredibly smart security solution for the majority of people. Telling us that they are taking steps to protect their users because of an event that they haven't even verified was a compromise is better than you discovering that your bank password was stolen because you forgot to update your firewall.
Re: LastPass requesting password reset after facing unknown anomaly
#59Earlier quoted context omitted.
I don't think I understand this - if the password isn't stored, do you expect the user to memorize all the various passwords?
End users don't need to memorize any passwords. They don't know them and they do not care what the passwords are (nor should they). They only need to know how to generate them when needed. Read about SHA1_Pass and try it out. I use it (and wrote it) to deal with hundreds of passwords that change frequently. I tried to make traditional password managers work for a number of years, before realizing that the traditional…
Additionally, some accounts have restrictions on usable characters or password length. The FAQ for SHA1_Pass says "try base64 half-encoding, its only 14 characters, and if that's too long maybe you shouldn't be using that website". Well I'm sorry but some BANKS do not allow passwords that long. You and I both know it's idiotic, but some banks have a small maximum password length, and some of them even restrict you to alphanumeric characters only.
I applaud SHA1_pass for trying to be innovative, you don't know what works unless you try it, but it looks like the result is a failure to me... too much complexity generated around the goal of trying to make passwords easy to remember, yet hashed to be secure. Just generate a random password with Keepass, whatever length and character sets you want, and store it.
What's the big deal? Yes, there's a chance that Keepass didn't do their encryption properly and your master password will be crackable, and someone will hack into your dropbox account and then have all your passwords. But with SHA1_pass there's also a chance someone will guess or socially engineer your passphrase, and since all your site words are "facebook" for facebook etc etc they too have full access to all your accounts.
Re: LastPass requesting password reset after facing unknown anomaly
#60So I just started using 1password and was thinking of lastpass. I'm still trying to figure out which is better. Anyone have any comments?
You can read up http://www.passpack.com/en/faq/