5 ms·
Doesn't LastPass encourage you to install their browser plugin though? https://www.dropbox.com/s/pzmdqex81tsicyk/Screenshot%202015-09-14%2016.45.31.png?dl=0 ht
by conover 11y ago
Doesn't LastPass encourage you to install their browser plugin though?
https://www.dropbox.com/s/pzmdqex81tsicyk/Screenshot%202015-09-14%2016.45.31.png?dl=0 https://www.dropbox.com/s/pzmdqex81tsicyk/Screenshot%202015-...
- viraptor 11y agoThat's a different functionality. You can use the plugin and not save the master password. The plugin is more secure than the webapp anyway. You do the decryption/search completely on your machine.
- jsudhams 11y ago> "The plugin is more secure than the webapp anyway" Can you explain how this is correct? Because i use only webclient thinking that the plugins may be more vulnerable because other plugins may read what lp plug in does.
- viraptor 11y agoTo use the webapp you have to send the master password over the network. So if that connection is captured in some way, your account is hacked. But extensions actually save the encrypted store locally - you can even access them offline (password is still required).
- ejcx 11y agoThis is not correct. The extension and the webapp authenticate the same way, and neither send the master password over the network. Criticism to using the webapp is generally JS crypto being broken. Code delivered every time coupled with the browser not being good place for crypto (any code can eat any other code..). Extensions, being a separate program that lives mostly apart from the web pages your browser visits is slightly a more trustworthy environment
- pweissbrod 11y agoInteresting to hear lastpass actually employs javascript cryptography in their design. I would be interested in hearing the rationale behind this design decision considering the obvious risks that are being taken.
- viraptor 11y agoOops, you're right. I was thinking of the mobile app, not browser extension. Brainfart :(
- ejcx 11y agoThe mobile app does not authenticate by sending plaintext password to the server either.
- GeorgeOrr 11y agoI'm not sure how that relates to the point being made. The insecurity comes from someone already having physical control of your machine, and if you had alowed saving of your master password (which Lastpass and anyone sane encourages against).
- sp332 11y agoAnd this is the popup that plugin gives you when you click the button to save the master password: http://i.imgur.com/s0FgRhI.jpg http://i.imgur.com/s0FgRhI.jpg
- geofft 11y agoSadly (?), it may be reasonable for password managers to not even offer that option because of technically-invalid PR fiascos like this one -- people are just going to stop using password managers otherwise.
- mef 11y agoYeah, 1password doesn't let you save the master password.
- giovannibajo1 11y agoAn user moving to LastPass (or any password manager) is exponentially safer than before, even if they choose to save the master password on their local computer. If there's a subset of users who would drop LastPass if the password couldn't be saved, that would be a shame, as they're much better off this way.
- fletchowns 11y agoYeah but if you give the user the choice between convenience and security, they're almost always gonna chose convenience.
- azinman2 11y agoThat's actually quite poor ux design. Alerts confirming things happen all the time and so users have been trained to click yes to make things work. I'd suspect only 20% might actually read that sentence and even less will understand what it means and why. Instead that login screen should change and have large, clear text and iconography that violates expectations and thus forces users to read. Having buttons that explain like "make less secure" makes it more likely to be understood than "yes" "no."
- dwild 11y ago