Live data from Hacker News

Evaluation of five password managers

medium.com

61–70 of 216 posts

Re: Evaluation of five password managers

#61

What did you find changed in lastpass after the logmein acquisition? We've been using lastpass since before the acquisition, and i can't say i've noticed any substantial changes (either positive or negative)

Same here, but I only use the personal version.

Re: Evaluation of five password managers

#62
post #35

I've been using masterpassword [1] which is stateless and requires no sync. I wonder what the HN crowd thinks of its features. Another option with the same paradigm is lesspass [2]. 1. https://masterpassword.app/ 2. https://lesspass.com/#/

There's a few issues with the master password derived password system, including: What if you need to change your password for a site to a different one? What if the site changes its URL?

There's a counter on Master Password, so if the password expires or you need to change it, you just +1 and it's new.

They also have settings depending on password requirements (no special characters, etc.).

I'm unsure what the URL really has to do with it, you could just generate a new password for the new URL and change it.

Re: Evaluation of five password managers

#63
post #8

> Mac OS, Windows, Linux, Android, and iOS ... full functionality can’t be dependent on an app which is only available on Mac OS and/or Windows. In other words, lack of full Linux support is a show-stopper for us. This ruled out 1Password... ...Huh? 1Password supports all of those platforms (including Linux) https://1password.com/downloads/linux/

Unfortunately, 1Password may find its engineers compromised by their government, by virtue of being Australian.

They have literally one support person in Australia.

Re: Evaluation of five password managers

#64

I'm surprised there was no mention of recent security audits. BitWarden just famously had one.

Many of these have had audits, not just this Bitwarden audit. There are some disquieting things in that audit, for what it's worth.

I don't understand how this information is actionable. It would be worth knowing whether something has _ever_ been audited (again: most of the major password managers have been), but just knowing an audit has been done isn't sufficient to know whether it's secure.

Re: Evaluation of five password managers

#65
post #52

In the end I've just been using the Unix pass password manager [1]. It's just cobbling together of GPG and git with shell scripts but it works like a normal git repository so you get all your synchronization, from that, your security from GPG which are all things I know and trust without introducing other components that I don't know / understand. [1] https://www.passwordstore.org/

I love this as well. It supports OTP and there is an awesome Android app for it called Password Store, and a browser extension called Browserpass.

Re: Evaluation of five password managers

#66
post #24

Earlier quoted context omitted.

I switched from LastPass to 1Password. It was a quick and simple export -> import process.

As a current LastPass user, what prompted you to switch?

Not the person you asked, but I also switched from LastPass to 1Password. The reasons were (1) 1Password's more integrated/more convenient 2FA support, and (2) AgileBits seems to care more about design.

Re: Evaluation of five password managers

#67

What did you find changed in lastpass after the logmein acquisition? We've been using lastpass since before the acquisition, and i can't say i've noticed any substantial changes (either positive or negative)

Not sure if its related to the acquisition, but if you're a firefox user the app has gotten very slow in past few years. I think the issue is related to the move to chrome extensions but really that shouldn't be an excuse. Lots of add-on have done this move and haven't had a problem.

Re: Evaluation of five password managers

#69
post #52

In the end I've just been using the Unix pass password manager [1]. It's just cobbling together of GPG and git with shell scripts but it works like a normal git repository so you get all your synchronization, from that, your security from GPG which are all things I know and trust without introducing other components that I don't know / understand. [1] https://www.passwordstore.org/

I love this as well. It supports OTP and there is an awesome Android app for it called Password Store, and a browser extension called Browserpass.

OTP as in Open Telephony Platform?

Edit: it turns out OTP is one time password, that's neat!

I'm only familiar with that through Erlang and consider it an architectural pattern for supervision trees, would you be willing to expound a teeny bit more on what you mean?

Re: Evaluation of five password managers

#70

I rarely see it mentioned, but when 1Password changed to a subscription model I switched to Enpass ( https://www.enpass.io ) and I've been very happy with it.

they don't make it very obvious, but note that 1password doesn't require a subscription. i use it with vaults shared and kept in sync via dropbox for example.

Same. I recently purchased an upgrade and consider it well worth the price, although I'm considering switching to the subscription model / family plan to make it easier to support my parents and in-laws. However my main concern is that you can't disable browser access when using ay of the subscription plans:

https://discussions.agilebits.com/discussion/80105/cant-disa...

Post reply on HN