Live data from Hacker News

LastPass’ Authenticator app is not secure

medium.com

81–90 of 118 posts

Re: LastPass’ Authenticator app is not secure

#81
post #31

Earlier quoted context omitted.

For me ease-of-use is a killer feature. Do any of the alternatives you suggested sync automatically between devices? Do they auto-fill?

iCloud Keychain does, and it’s free, but obviously it’s limited to Macs and iOS devices.

iCloud Keychain doesn't work with all apps or even all browsers, when it doesn't there's no trivial way of copying in a password, it isn't cross-platform, and you cannot import or export existing passwords.

I consider the other products listed as actual competitors of Lastpass, I don't even rank iCloud Keychain that high, it lacks even basic features.

Re: LastPass’ Authenticator app is not secure

#82

Earlier quoted context omitted.

For me ease-of-use is a killer feature. Do any of the alternatives you suggested sync automatically between devices? Do they auto-fill?

1Password does. It's great.

I use 1Password at work. It's not very good and doesn't seem to work on linux, which I need for work. Add to that really clunky user management...it's just not that great usability wise. I've never been able to get it to autofill either. Lastpass on the other hand just works on all my devices. We were using Keepass before but syncing was such a massive PITA that my wife wouldn't use it. Now she at least uses Lastpass with a better password than what she was using before, but I suspect until we're robbed she's not going to see the value in security. Don't get me started on her and the 2FA grievances.

Re: LastPass’ Authenticator app is not secure

#83
post #47

Earlier quoted context omitted.

1.) Find exploit in forum software/server. 2.) Modify login.php to send form username/password to attackers server.

Except there is no forum login page, just a SAML redirect to their SSO login.

And that link can be changed.

Re: LastPass’ Authenticator app is not secure

#84

Earlier quoted context omitted.

This "problem" has precisely nothing to do with open source vs closed source. "Tell me the list of activities that are public" and "tell me the name of each activity as I launch it" are babies-first-app-analysis level and work equally well on open and closed source apps. Are we really concerned about an exploit that requires somebody to have unlocked access to your phone?

I'm not saying that's the problem, I'm just suggesting that you have to have a lot of faith in a company to trust it with all of your passwords, especially when there's only a handful of eyes on its source code. It's not for me, personally. And yes, because the scariest aspect of password managers is the fact that you have basically shifted the responsibility of "I use the same password everywhere" to a different par…

Prove that open source has more eyes than closed source. You can't because in reality it's most likely not true for the vast majority of software. Most software requires an incentive to look over the code and the skill to do it. The incentive to do it for closed source is money, open source is warm fuzzies or personal interest. I really love open-source software but code review is clearly not a benefit for the vast majority of people.

Re: LastPass’ Authenticator app is not secure

#86
post #59

Earlier quoted context omitted.

keepassdroid lets you do that via copying data to the clipboard. Not a great solution, but it works

Every password manager allow you to copy/paste your password. This is NOT a solution.

Interesting, because it works for me. Now that may not be a solution that works for you, but it clearly is a solution.

Re: LastPass’ Authenticator app is not secure

#87
I'm very confused about how bad this is, the article seems unclear. Does it allow malicious apps steal the OTA codes? Does it allow malicious apps to steal the keys used to generate the OTA codes? Does it allow a user to see the keys? Is it none of the above?

All I get from the article is that the user might be able to see the OTA codes in a roundabout way. If that's the entire problem, why is it a problem?

Re: LastPass’ Authenticator app is not secure

#88

Earlier quoted context omitted.

You can't keep varied, secure passwords in your head unless you barely use any services.

Most people don’t use many services where security is important. It’s not uncommon to have several hundred accounts with passwords, but I have maybe 10 that I really worry about being hacked/lost. For all the crap sites I can just use $singlepassword+$servicename as password. For the few sensitive ones I use strong passwords and 2FA. I do use a manager to keep those strong passwords - but even though I have it, I can…

When I started using a password manager I did something similar, but I told myself every site which used the "insecure" password was linked. So I'd ask myself "If someone hacked the least consequential site I've used this password on, they'd also have hacked this site, do I care?"

It was very rare that the extra 30 seconds to add a new entry password manager wasn't justified after asking myself that question.

I think it all comes down to ease. Yes, some secure passwords is better than none, but it's just soooo easy I'd just say go with the PM

Re: LastPass’ Authenticator app is not secure

#89
post #87

I'm very confused about how bad this is, the article seems unclear. Does it allow malicious apps steal the OTA codes? Does it allow malicious apps to steal the keys used to generate the OTA codes? Does it allow a user to see the keys? Is it none of the above? All I get from the article is that the user might be able to see the OTA codes in a roundabout way. If that's the entire problem, why is it a problem?

It is difficult to understand, but it seems like the app normally has some sort of PIN protection in order to open it. This is apparently a bypass method for that protection.

Maybe I am misunderstanding, but it really does not seem like much of a big deal, as someone would need to have your phone in hand as well as your lock screen passcode.

The title seems pretty dishonest, if my interpretation of this issue is correct.

Re: LastPass’ Authenticator app is not secure

#90

Earlier quoted context omitted.

You'd be surprised how many people (not on HN) use extremely weak (or no) unlocking mechanisms for their devices. It overlaps with the set of folks who would want to use LastPass because of how easy it is.

Do you know what is easier than using last pass for people who use weak unlocking mechanisms? Using the same password everywhere. I'd be surprised if there was any overlap at all where you claim.

Well, I have several family members that fall in the "I use a pattern to unlock my phone or do not use anything to lock it, but store passwords in Last Pass" category. So I guess you're wrong.
Post reply on HN