Live data from Hacker News

LastPass: Security done wrong

palant.de

61–70 of 221 posts

Re: LastPass: Security done wrong

#61

http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.

https://keeweb.info/ is also very nice. It has a very convenient Dropbox (& co) integration.

Re: LastPass: Security done wrong

#62
I've always been quite nervous that the LastPass two-factor authentication can be easily bypassed if your email account is compromised. On the 2FA screen there's a "If you lost your Google Authenticator device, click here to disable Google Authenticator authentication" link. No. I don't want that to be able to be disabled. I have one-time passwords for that.

Re: LastPass: Security done wrong

#63

I would love to switch to a different password manager, but nothing else I've tried has quite managed to nail the usability aspect. Specifically, Lastpass's app fill functionality on Android is a huge benefit that I haven't seen in others. It also has a browser extension that works without a separate program running on your computer; I didn't even realize that was a plus until I started trying to use other apps that…

I hope the new Auto Fill API [0] in Android O will make it a lot easier for other apps to add this feature.

[0] https://developer.android.com/preview/features/autofill.html

Re: LastPass: Security done wrong

#64
post #25

I'm interested to hear what the HN community thinks about keeping passwords in iCloud-based Keychain (Safari) or whatever Google's alternative is called. I don't care about portability. Why would I want e.g. 1Password instead of simply using Apple Keychain. Thanks!

Here is how I think about it: It is a spectrum. You can have high accessibility / ease of use or you can have high security. You can't have both. By storing your info on a remote server, you are trusting they will protect your data. Maybe they will, maybe they won't. It is just a matter of finding a balance you feel comfortable with. Personally, I don't store my passwords on any cloud service, carry them on a thumb d…

How do you deal with passwords on your mobile device?

Re: LastPass: Security done wrong

#66
post #56

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

If you're open to a paid option, 1Password for Teams/Families a good one. You can transfer from LastPass via CSV ( https://support.1password.com/import-lastpass/ ).

I recently switched to 1pass, it's much better

Re: LastPass: Security done wrong

#67
post #56

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

If you're open to a paid option, 1Password for Teams/Families a good one. You can transfer from LastPass via CSV ( https://support.1password.com/import-lastpass/ ).

I felt like they weren't above board previously with pricing. It wasn't fraud but IIRC prices got a big jump that was timed to be in combination with some kind of defacto mandatory upgrade. It had a bait and switch feel to it and at the time the family price across multiple devices seemed too high.

Re: LastPass: Security done wrong

#68
post #65

The HN community seems to be giving a lot of praise for 1Password, Lastpass and Keepass occasionally. But rarely mention Dashlane, I'm curious as to why ?

Dashlane isn't open source, nor is it available on Linux. That is going to prevent a lot of people from even considering it.

Re: LastPass: Security done wrong

#69
post #50

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

Keepass imports from Lastpass [0]. Not that meets the rest of your requirements, but Keepass + KeepassHttp + PassIFox work beautifully for me. Autofills my logins and fully integrates with Firefoxes password manager so that you don't get conflicts between the browser and your password manager trying to save the same password. Also doesn't add the stupid CSS hacking that LastPass does to add their logo into the passwo…

Sounds interesting, but requires a password program, a 3rd party plugin for the program, and a browser plugin... and yet another app to do cloud sync like Dropbox.

Sounds like a huge pain compared to LastPass, as well as increasing attack surface.

Re: LastPass: Security done wrong

#70
post #56

Earlier quoted context omitted.

If you're open to a paid option, 1Password for Teams/Families a good one. You can transfer from LastPass via CSV ( https://support.1password.com/import-lastpass/ ).

I felt like they weren't above board previously with pricing. It wasn't fraud but IIRC prices got a big jump that was timed to be in combination with some kind of defacto mandatory upgrade. It had a bait and switch feel to it and at the time the family price across multiple devices seemed too high.

I'm still on 4.* which was a 1 time fee. I never felt like I was forced to upgrade.
Post reply on HN