Live data from Hacker News

LastPass: Security done wrong

palant.de

71–80 of 221 posts

Re: LastPass: Security done wrong

#71
post #44

From a strict security standpoint, maybe all of this is true. But I see strong PR as a feature, not a bug...at least until password manager market penetration is closer to 100% than it is to 0%. Once you've adopted a password manager, you've limited the scope of potential abuse, and you've decreased the pain of recovering from abuse that does happen . Being forced to change passwords used to be a stressful problem fo…

These are security critical pieces of software. Like, AV, if the password manager makes it easier to compromise your access in bulk, that's a very very bad thing. This doesn't need to be targeted, just throw some JS into an ad and pwn up 100s of 1000s of accounts. That's actually worse.

My black hat method is much easier than that, and it doesn't even require a black hat skillset.

1) Download two datasets from different massive breaches. You can find plenty of them with plaintext passwords on any torrent tracker.

2) Correlate email and password combos across datasets. Don't worry, you'll find 10s of millions of people who don't use password managers and reuse passwords.

3) profit

If you have reason to believe you're being targeted, any breach is a problem. But until my method no longer produces results, theres no reason to believe black hats will go through any additional effort to obtain the average person's creds.

Re: LastPass: Security done wrong

#72
post #48

Earlier quoted context omitted.

Precisely this. The LastPass extension actually handles the decryption, whereas the 1Password one merely communicates with the app. 1Password should therefore be significantly more secure.

If it auths the application, which it didn't for quite some time. Tavis has found plenty of issues with 1Password and their team has been much more hostile and less responsive.

I'm super interested in this. After a super brief Google search, I was unable to find Tavis's results. Could you kindly direct me to them?

Re: LastPass: Security done wrong

#73
post #29

Earlier quoted context omitted.

I signed my family up for 1Password a month ago and love it so far. Here's the 1Password Security Design Whitepaper: https://1password.com/files/1Password%20for%20Teams%20White%...

1Password has no Linux support so it's not really a drop in replacement. Android autofill functionality is also significantly worse.

Android O is getting an Autofill API [0], which should be very useful for apps like LastPass.

[0]https://arstechnica.com/gadgets/2017/03/the-android-o-develo...

Re: LastPass: Security done wrong

#74
post #65

The HN community seems to be giving a lot of praise for 1Password, Lastpass and Keepass occasionally. But rarely mention Dashlane, I'm curious as to why ?

Dashlane isn't open source, nor is it available on Linux. That is going to prevent a lot of people from even considering it.

[deleted]

Re: LastPass: Security done wrong

#75
post #48

Earlier quoted context omitted.

Precisely this. The LastPass extension actually handles the decryption, whereas the 1Password one merely communicates with the app. 1Password should therefore be significantly more secure.

If it auths the application, which it didn't for quite some time. Tavis has found plenty of issues with 1Password and their team has been much more hostile and less responsive.

Can you please provide a source for this? The 1Password only bug I can find filed by tavis is [0], in which 1Password were very responsive and thankful of tavis' efforts.

I note that can't find anything on twitter that even remotely supports your allegations either.

0: https://bugs.chromium.org/p/project-zero/issues/detail?id=88...

Re: LastPass: Security done wrong

#76
post #65

The HN community seems to be giving a lot of praise for 1Password, Lastpass and Keepass occasionally. But rarely mention Dashlane, I'm curious as to why ?

It's interface and usability is also ridiculous on windows, and it's the most expensive of all.

Re: LastPass: Security done wrong

#77
"Altogether it looks like LastPass is a lot better at PR than they are at security. Yes, that’s harsh but this is what I’ve seen so far."

No, it's not harsh enough for a program that knows the right password, shows it to you, but then inputs the wrong one in the password field. Of course, compared to these security issues, such UI issues are almost irrelevant. With such a simple UI to program, you'd think they'd at least get that right or fix it. And if they don't, it's likely they have much bigger problems under the hood. Over and over.

Unfortunately, all the reviews of Lastpass I read gave it 4-5 stars and it was often a recommended or editor's choice pick. Clearly, those reviewers and their publications are just a bunch of shit words to attract advertising (that includes pretty much every article on password managers I managed to read). This is a pretty important part of security. If it takes someone with expert skills in computers almost a year to find a good password manager program, not to mention days worth of work importing into and testing various solutions, what chance does your everyday computer user stand?

The way things stand with password managers right now, I'm not sure we're advising ordinary computer users correctly in telling them to use one.

Re: LastPass: Security done wrong

#78
post #65

The HN community seems to be giving a lot of praise for 1Password, Lastpass and Keepass occasionally. But rarely mention Dashlane, I'm curious as to why ?

It's interface and usability is also ridiculous on windows, and it's the most expensive of all.

Could you elaborate ?

Re: LastPass: Security done wrong

#79
It must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnera...

As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likelihood that I might be exposed to those threats. Would anyone care to summarize? The linked issues have been fixed, even in Firefox, and the claim that vulnerabilities still exist are unsourced.

*EDIT: disclaimer has been added! My comment is now out of date.

Re: LastPass: Security done wrong

#80
post #3

Interested to hear what the HN community thinks about 1Password

I'm a long time lastpass user, it does enough for me. Different strong password for every website I use except but never store email, banking or hosting accounts. On another note the cheapest premium 1password is three times the cost of premium lastpass.

Thinking about it I'm really only using it for convenience, security/strong passwords is in second place.

Post reply on HN