21 ms·
I used to just let Chrome remember everything, but then jumped on the LastPass bandwagon after Heartbleed last year. I've been happy with it. The mobile app wo
by spinchange 11y ago
I used to just let Chrome remember everything, but then jumped on the LastPass bandwagon after Heartbleed last year.
I've been happy with it. The mobile app works well and it is very convenient. I just can't help but to have this nagging feeling since all their salts were exposed, I am really no (or not very much) "safer" than if I let Chrome remember them. If someone gets on my machine and knows what they're doing it is probably all over anyway, right? (And no, I dont let LastPass remember master PW, and I do use a system-level password so you cant easily see them in chrome://settings/passwords unless you have that to...) So the question is who do you trust more to protect the credentials that are synced to the cloud: Google or Lastpass? I don't know the best answer, all things considered (local and on the network). I would guess Google is a much harder target than LastPass.
- hallman76 11y agoI trust LastPass for 3 reasons: 1) LastPass has a history of taking ownership of vulnerabilities and taking appropriate measures. They do this publicly and provide a level of detail that demonstrates their expertise[1]. 2) They're working under the same constraints as Google with the same caliber of engineering strength. 3) Most importantly, their business depends on delivering a secure product. It's in their best interest to continue providing a secure product. [1] https://blog.lastpass.com/2015/06/lastpass-security-notice.html/ https://blog.lastpass.com/2015/06/lastpass-security-notice.h...
- spinchange 11y agoIt isn't that I don't trust LastPass the company. It is that I'm no longer sure if the entire model of the product/service offers enough additional (or comparable) security over what Chrome offers, wrt to the syncing of encrypted credentials to the cloud. If your're only considering vulnerabilities that pertain to that, I would think native Chrome has an inherent security advantage over a Chrome plugin. I am happy to be wrong about this, though. Edit/Addition: While I give them props for the full disclosure about the salts being exposed, we don't have any evidence that this has ever happened to Google, so setting everything else aside, we already know for certain LastPass has been exploited in a way we don't have any evidence that Google has. That's not intended to be a slight on LastPass or praise for Google, just that, "it is what it is."