Live data from Hacker News

LastPass: Security done wrong

palant.de

91–100 of 221 posts

Re: LastPass: Security done wrong

#91

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

I use bitwarden. It's open source and works in browser and on phone. I haven't done any auditing myself, so I guess it's a leap of faith in that regard, but it's working great thus far.

It can import from a lastpass file.

Even though it's open source, there is a hosted instance (so the experience is much like lastpass). There was a kickstarter a while back that failed though, so I'm unsure how it's funded.

Re: LastPass: Security done wrong

#92

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

I switched from Keepass to Enpass a while ago (enpass.io). It does use 3rd party cloud accounts for synchronization, but it's fully integrated into the apps.

Has android/ios/blackberry/windows mobile clients, desktop clients for mac/win/linux/chromebook (including portable versions), and browser addons. It's not a subscription service---the desktop versions are free, and the mobile versions cost a 1-time purchase to unlock all the features. I'm very happy with it.

Re: LastPass: Security done wrong

#94
post #50

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

Keepass imports from Lastpass [0]. Not that meets the rest of your requirements, but Keepass + KeepassHttp + PassIFox work beautifully for me. Autofills my logins and fully integrates with Firefoxes password manager so that you don't get conflicts between the browser and your password manager trying to save the same password. Also doesn't add the stupid CSS hacking that LastPass does to add their logo into the passwo…

Keepass has lots of red flags for me:

- No https on site

- Update file hosted via http (not https)

- Downloads via sourceforge which has injected adware in downloads before

- FAQ downplays lack of constant time comparison instead of using constant time comparisons and being extra safe

- You have to cobble together multiple apps from multiple developers to get a full working solution; means you have to trust lots of individual entities

That being said I can hardly defend staying on Lastpass anymore.

I just wish 1Pass was crossplatform so there was a clear universal winner!

Re: LastPass: Security done wrong

#95

I've been a LastPass user for a few years and I use the browser extension everyday. As an admin of several websites, the the extension has been a time saver. I thought I had no illusions about the inherent insecurity in using LastPass, but I guess I was wrong. I use Yubikey and disabled autofill long ago, but I was still vulnerable. Their response to these exploits is maddening. "Our investigation to date has not ind…

I've struggled with this too.

I love how I can share passwords with a team using LastPass (share just access, share ability to view, share ability to edit). For me... it's more about getting the team using the right tool than individuals. There are probably better individual solutions than LastPass, but I don't know of any that are better for teams. I know that having a tool that lets you share passwords is inherently risky... but I still think LastPass is less risky than people sharing via PostIt, or sharing via emails... or less risky than not sharing passwords in that "hit by a bus" scenario we always talk about.

I tried Enpass, 1Password, and KeePass for individual use... none of them were horrible (I liked 1Password the most). Enpass let you sync your vault with the storage option of your choice... so you could sort of do team passwords that way. Typically I don't want to share all my passwords, just a few... and like I would want to share different subsets with different people... so that "share your vault" option wasn't ideal for me.

Usability-wise, I love how LastPass fills in my credit card info and address on forms I tell it to. And how LastPass can automatically update passwords for many common sites. And gives me a report of passwords that are weak, old, and duplicate -- the "global rank" on LastPass is a game and I want to get a high score. Ha. (Full disclosure, I tried each casually for less than a week... there may have been things I missed.)

Been on LastPass for a long time, generally happy with them and haven't found anything that better fit my needs, but clearly these reports that they aren't taking security as seriously as they should be are troubling.

EDIT: Going to look at https://1password.com/teams/ in the next week or so. I don't think this option existed last time I looked at 1Password.

Re: LastPass: Security done wrong

#96
I am almost ready to file a lawsuit.

Context:

What I am after is a password manager that has the option to NOT store anything in the cloud at all. I want encrypted storage to be stored locally. No exposure outside my network. Inter-device synchronization done manually or automatically within the confines of said private network.

I would also like to store data beyond uid's and pwd's. For example: secret questions and their answers, account and pin numbers, company tax id's, bank account numbers, passport numbers, etc. In other words, data you might need handy that should be encrypted.

I've been using a program for a number of years. The program started exactly as I described above: Network only synchronization.

Over the years they have mutated the program to cloud based storage. And, over the years, they have done this without warning to users or seeking any kind of authorization.

Imagine if you are using software that only stores data locally and syncs over your network only to wake up one day to discover that the latest update uploaded all of your secret data to their cloud-based system WITHOUT your permission. And, to make things even worst, they progressively eliminated the network sync option.

The current version doesn't even ask, the minute you edit a record or create a new one it shoots it up to the cloud. Unbelievable.

Years ago I asked about this. I have an email from the support assuring me the data would never be stored on the cloud. Time to file a lawsuit?

Anyhow. Is there a tool fitting my description above? I don't care if it's free or paid. I simply want my data to never move outside my network unless I want it to.

Re: LastPass: Security done wrong

#97
I've been using LastPass for a few months and have loved it, but maybe I'll consider switching to 1Password.

However, can I just rant for a second about how these security assessments and blog posts fold out? The beginning of my career was spent thinking I was going to go into this field (one of my degrees is in Information Assurance) and the #1 thing that persuaded me to switch to building software instead was the attitude and approach of the security field.

If it's not 100% secure and we all agree that it's the 100% best way to do something, it's the end of the world and anyone using LastPass is an idiot who will have all of their passwords hacked and their life ruined. (Remember when the draft for client side storage was announced? You would have thought armageddon was upon us based on the reaction of the security industry.)

Big picture here -- most people re-use a short, simple password on all of their sites. Using a password manager, even one with a few things that it can and should improve, is a HUGE step in consumer behavior. Bickering amongst ourselves and boasting for crapping on someone's company is not the right approach to increasing our entire society's security stance.

Want to actually help?

1. Create more resources to help consumers pick, use, and adopt a password manager with super simple setup process. Even the current methods that all password managers use of generating, saving, and autofilling passwords are too complex and cumbersome for the average consumer. Heck, even MFA is seen as a huge waste of time and barrier to logging into people's accounts by the majority of people right now.

2. Create more resource to educate developers of these services, helping them to see what they should do and how they should do it, not bragging about your ability to tear down a service they spent hours slaving over. Get over yourself and actually help society. (https://www.owasp.org/index.php/OWASP_Guide_Project is a great example of this)

Looking for an example? Apple's iTouch. Yes -- it's not the most secure option. People leave their fingerprints all over the place and they can be lifted and used to unlock a phone. But look at the other option -- using no passcode, or a 4 digit passcode that's easy to guess or look over a shoulder. Is it the most secure option? No. Does it raise the level of security for our society as a whole by providing a realistic security barrier that the average consumer can use? Yes.

Re: LastPass: Security done wrong

#99

Sigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?

See the beauty of using program + cloud-provider is that all the cloud provider sees is an encrypted file. If one were to gain access to my Google Drive they would still have to crack an encrypted file which will take a while. I feel like with lastpass the attack vector is bigger with all the fancy features.

It's encrypted on the lastpass "cloud" too. The point of it being integrated is the user doesn't have to take action to download the encrypted DB; the software does it for you.

Re: LastPass: Security done wrong

#100
post #29

Earlier quoted context omitted.

I signed my family up for 1Password a month ago and love it so far. Here's the 1Password Security Design Whitepaper: https://1password.com/files/1Password%20for%20Teams%20White%...

1Password has no Linux support so it's not really a drop in replacement. Android autofill functionality is also significantly worse.

Not supported no, but you can use the 1password DB with other tools[0].

0: http://www.lucianofiandesio.com/1password-in-linux

Post reply on HN