Live data from Hacker News

LastPass bug leaks credentials from previous site

zdnet.com

91–100 of 196 posts

Re: LastPass bug leaks credentials from previous site

#91
post #38

Earlier quoted context omitted.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

Anything that isn't context aware (i.e. knows which website you're on so can provide the relevant information) is doomed to failure right out the gate. I'd prefer people are using any password manager than go for perfection and then quit completely because it was a terrible UX. KeePass may be more secure against certain specific attacks, but it is largely irrelevant if people are going to contrast it against using no…

>> Anything that isn't context aware (i.e. knows which website you're on so can provide the relevant information) is doomed to failure right out the gate.

Sorry, not doomed to fail.

I'm not gonna use a password manager that is "context aware" and has the capability to auto-fill for sensitive sites - that's just my threat model. I'm okay with context aware storing of less critical passwords.

Re: LastPass bug leaks credentials from previous site

#92
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

I can also vouch for how much better BitWarden is. I was a LP customer for a long time. BitWarden reminds me of LP from 5 years ago, when it was fast and clean.

Re: LastPass bug leaks credentials from previous site

#93
post #4

I am seriously considering alternatives to LastPass. Since they moved to a dedicated app instead of just a plugin on Mac, it is borderline unusable for me. Almost never actually fills in my passwords (often have to click copy password), often thinks I am on a different website than I am, or just gives me an empty white box when I click the LastPass button.

Try BitWarden. It's what LP used to be before the bloat and is open source.

Re: LastPass bug leaks credentials from previous site

#94
post #62
post #38

Earlier quoted context omitted.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

> KeePass and similar are a better way to go, if slightly more labor intensive. Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion.

I store the keepass file in a cloud sync service. The file is encrypted.

The keepass application can perform "auto-type" which works for all sensible applications and websites that have username/password input fields and a log-in button.

Recently, more and more websites split the log-in into two screens, first email and then password. This completely breaks auto-type and is horrible in every way. Please don't do it.

Re: LastPass bug leaks credentials from previous site

#95
post #60
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

Love to hear more about why BitWarden is a safer choice than Lastpass if anyone cares to chime in. Thanks.

lastpass' privacy policy is very privacy hostile. They're now aggressively offering a free product with the ability to monitor (and sell) all browsing behavior tied to you as an individual (thanks to LogMeIn).

>How We Use the Information We Collect and Receive

>LogMeIn may access (which may include, with your consent, limited viewing or listening) and use the data we collect as necessary (a) to provide and maintain the Services; (b) to address and respond to service, security, and customer support issues; (c) to detect, prevent, or otherwise address fraud, security, unlawful, or technical issues; (d) as required by law; (e) to fulfill our contracts; (f) to improve and enhance the Services; (g) to provide analysis or valuable information back to our Customers and users. [1]

(e) is a very broad and loosely defined category. A contract can include Anything and this ambigious statement enables LogMeIn to inturn do anything with data they collect from all their services (including Lastpass).

In the new firefox updates, Lastpass won't let you open/run the extension until you provide it the abiltiy to monitor all browsing behavior (whereas on chrome I have it restricted to monitor sites when the extension is clicked/activated)... I will not be renewing my premium service and am looking to migrate away to another service.

[1] https://www.logmeininc.com/legal/privacy

Re: LastPass bug leaks credentials from previous site

#96
post #38
post #5

Switched to BitWarden a few months ago from years of using LastPass. Zero regrets... it is in every way better for my use case. Switching wasn't hard either. Even gave BW my money, it is worth supporting them.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

yep, keepass is my preferred password manager. i have the database in a dropbox folder to handle syncing between my desktop and android phone.

Re: LastPass bug leaks credentials from previous site

#97
post #62
post #38

Earlier quoted context omitted.

I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.

> KeePass and similar are a better way to go, if slightly more labor intensive. Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion.

I use dropbox to keep my db sync'd between my desktop and android phone.

Re: LastPass bug leaks credentials from previous site

#99
post #63

Earlier quoted context omitted.

What is your phishing protection? Making sure you read the URL?

Just add the original URL into the specified field and copy paste it each time you need to access said website. KeePass is the best at what it does and stays local as any password manager should do. If you need more security & portability encrypt the DB with VeraCrypt, sync with whatever service you trust.

Just a note that URL is the one field in Keepass where you may not need to copy/paste. As long as your default browser setting is set to the browser you want to use for the URL double-clicking on the URL in Keepass opens it in said browser.

Re: LastPass bug leaks credentials from previous site

#100
post #39

I quit LastPass when they were acquired by LogmeIn and doubled their prices to $24 a year, and their constant issues with autofill (atleast for websites in my country). I switched to Bitwarden and haven't faced an issue since.

Even worse, before it was just 12$ and now it is 24$ before taxes so you end up paying 29,52$. A 246% increase.

People are really complaining about this, but honestly the features I get from the product absolutely justify paying $2/month. I'd probably pay $3-4 before it wouldn't become worth it for me
Post reply on HN