Live data from Hacker News

LastPass’ Authenticator app is not secure

medium.com

91–100 of 118 posts

Re: LastPass’ Authenticator app is not secure

#91

So the moral of the story is don't let people install applications on your Android device? And the bigger moral is: don't hand someone your unlocked Android device and let them play with it for an extended period of time?

You are correct. Not sure why you were downvoted.

Re: LastPass’ Authenticator app is not secure

#93
post #59

Earlier quoted context omitted.

Every password manager allow you to copy/paste your password. This is NOT a solution.

Interesting, because it works for me. Now that may not be a solution that works for you, but it clearly is a solution.

The clipboard is insecure and can be accessed by any app that is running.

It's not a secure solution, period end of story, to copy paste a password to a shared location on the device that all running processes can access.

https://developer.android.com/guide/topics/text/copy-paste.h...

I mean, there's the guide. I wouldn't put my passwords on the clipboard, personally.

Re: LastPass’ Authenticator app is not secure

#94
post #19

Earlier quoted context omitted.

The ability to fill password in Android app. The last time I checked there's no competitors doing this. I'm hoping the Autofill API in Android Oreo can bring more competition.

Dashlane does that.

Been with it since beta and have never had an issue with it, it's the one I always recommend.

Re: LastPass’ Authenticator app is not secure

#95

Earlier quoted context omitted.

> What makes LastPass inferior to these other options? Well, for one, the very first sentence of the article here.

The article whose "exploit" requires handing your unlocked phone to someone?

> (Edit #1, 7.30pm GMT): A lot of people are saying that this flaw requires physical access. However, as I pointed out above, you don’t need physical access, a maliciously installed application can easily access the activity and capture the code.)

Re: LastPass’ Authenticator app is not secure

#96
post #8
post #3

I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.

I think it is mostly inertia and cross-platform support. Before they were acquired, they seemed to care a lot more about security, instead of just security theater. They also have some nice crypto features: For instance, I forgot my master password, and they have a one time password reset protocol that lets them send you an unlock code that only works on previously logged in devices. Also, it has rock-solid offsite b…

I just moved away from LastPass due to the acquisition and migrated to 1P. I had two issues with the migration that were easily solvable by someone technically inclined.

1) Folders don't get migrated over to tags into 1P. You need to use this pearl script to do so. (google it)

2) Autofill is well umm different. It took some getting used to, but you now have to hit Cmd+\ to autofill intsead of using the mouse. It's more secure and it ends up being more "clean" I've noticed.

Re: LastPass’ Authenticator app is not secure

#97
post #59

Earlier quoted context omitted.

keepassdroid lets you do that via copying data to the clipboard. Not a great solution, but it works

Every password manager allow you to copy/paste your password. This is NOT a solution.

Keepass2Android has a custom keyboard to auto-type usernames/passwords.

Re: LastPass’ Authenticator app is not secure

#98

The code, tech, and mindset behind LastPass is a joke. They started just after the “dark ages” of security but don’t seem to have upgraded their mental model of security since. I’ll share with you the moment I discovered something that made me cancel my schedule for the day, research alternatives, write a LastPass to 1Password converter [0], and cancel my LastPass account and subscription. Are you ready? You log in t…

Electronic password managers never made sense to me. While you can do more to secure a single target, it is a more valuable target and one mistake costs you all your passwords. For me a physical password journal is best. While it does make you vulnerable to physical attackers, the cost invest to target someone physically is so much higher that if I have to deal with that threat level I'm already a goner. Just have to…

My approach for anything remotely sensitive, or that could be used to gain access to other accounts, is to generate a LastPass password and to memorize a handful of short "salts" that I add to each sensitive password manually + using 2FA wherever it's available.

Obviously there's no 100% secure approach, but at least this makes me sleep better knowing that if LastPass were comprimized, my stored gmail, bank, paypal, work, etc. passwords wouldn't work.

Re: LastPass’ Authenticator app is not secure

#99
post #29

Earlier quoted context omitted.

That is a whole lot of opinion, but not much substance. What makes LastPass inferior to these other options?

Perhaps I could have clarified better, but I was speaking to the various nasty security issues they’ve had mainly. I also find their apps to be ugly as sin, but that’s a personal preference.

When your rival is KeePass you don't really need to do much in terms of UI/UX

Re: LastPass’ Authenticator app is not secure

#100
post #47

Earlier quoted context omitted.

1.) Find exploit in forum software/server. 2.) Modify login.php to send form username/password to attackers server.

Except there is no forum login page, just a SAML redirect to their SSO login.

Modify login page to have a login form
Post reply on HN