Even the LastPass will be stolen, deal with it (2015) [pdf]
1–10 of 23 posts
Re: Even the LastPass will be stolen, deal with it (2015) [pdf]
#2 "If you ever wanted to dump someone's entire LastPass vault, this is where you start :D"
The author was referring to the linked presentation slides.Re: Even the LastPass will be stolen, deal with it (2015) [pdf]
#3Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.
Re: Even the LastPass will be stolen, deal with it (2015) [pdf]
#4Does anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.
Re: Even the LastPass will be stolen, deal with it (2015) [pdf]
#5Does anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.
Re: Even the LastPass will be stolen, deal with it (2015) [pdf]
#6Does anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.
I moved from lastpass to bitwarden about 2 years ago, then to self hosting vaultwarden about 6 months ago. Bitwarden wasn't as feature-full as lastpass at the time, but I liked it a lot. My father was using lastpass in the meantime and I saw it devolve into an unpleasant mess UX wise and these days, ignoring the elephant of the hack, am confident bitwarden is a much better experience overall compared to lastpass.
I now mostly use 1Password but I also host a VaultWarden instance. I haven't yet moved to it fully because even though 1P is also devolving and I don't like having my passwords db on a 3rd party server, I still find BW's clients clunky especially the browser integration.
My question was specifically about the kinds of issues in the OP though. I poked around my Firefox profiles and haven't found much but I don't really know what I'm looking for.
Re: Even the LastPass will be stolen, deal with it (2015) [pdf]
#7Does anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.
For me, 1password continues to work and improve on its features in a good way with biometric unlock support (Windows Hello, iOS/MacOS biometric unlock) and the SSH Agent is nice, so I use it and was paying the yearly subscription for it before my work started to give me a license for free. While it's my choice, I can see why most don't like 1password 8's subscription-only and cloud-only model (you effectively have to…
My question is related to the OP though, I'm not looking for UX/UI or feature comparisons.
Re: Even the LastPass will be stolen, deal with it (2015) [pdf]
#8Aside: I never really understood distributing just slides from a talk. Any good talk most of the information isn’t in the slides.
Re: Even the LastPass will be stolen, deal with it (2015) [pdf]
#9Does anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.
The one good thing about LastPass was basically how easy it was to set up. Everything else was a bit of a mess. 1Password was tricky to set up, and they took a bit longer to launch a cloud service.
One thing that bothers me about 1Password is that they only let you set up one security key, which is very impractical for people like me. OTOH, this is not unusual, and I assume part of it is to keep bad actors from adding more security keys to your account or something like that. Still not great when you can lose access to everything if you lose your key.
Re: Even the LastPass will be stolen, deal with it (2015) [pdf]
#10Does anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.
Although personally, I use OneDrive to sync it across devices