4 ms·
I do, I've been a heavy user of both for 4+ years, but I'm not a security expert of any kind. LastPass has been exploited a few times in ways that could have g
by reconbot 10y ago
I do, I've been a heavy user of both for 4+ years, but I'm not a security expert of any kind.
LastPass has been exploited a few times in ways that could have given up passwords. Their UX and server infrastructure seems to be a mess of php scripts, that itself doesn't have to be insecure but is a code smell. Their commercial support looks unmaintained. Both platforms support "cloud" based syncing but since 1Password's is pretty new I can't speak to it.
1Password does local encryption outside of the browser, LastPass will encrypt locally in the browser.
1Password can leverage other file transports to sync passwords, iCloud, DropBox, or any shared directory. LastPass does it all with their servers.
LastPass's web interface if compromised can have you give away the password to all your passwords. 1Password has a much smaller risk of this and would probably have to include a malicious software update.
1Password Families/Teams exists and I'm not familiar with it but it probably has a similar attack vector to LastPass's web interfaces.
You know, they both offer end to end encryption with similar attacks. Overall these companies are big targets and I'd rather keep my passwords offline or synced via side channels in a standalone app like 1Password.
PS I'd be amiss if I didn't mention dashlane https://www.dashlane.com/ https://www.dashlane.com/ I hear good things and it's passed review at a few companies who know their stuff, but that's all I know.
- milkytron 10y agoAfter reading this I deleted my lastpass account and came across this message upon trying to log in. http://imgur.com/a/SFpWw http://imgur.com/a/SFpWw One of the first things I learned about security was not to tell the user which credential was incorrect. Disclaimer: I'm not a security expert.
- emodendroket 10y agoI mean, honestly, it's not a crazy trade-off to let people see the username, especially if you have a registration page that's going to tell people "sorry, that name is already registered."
- jerf 10y agoThe debate that the smart people have on that one still seems to go back and forth. I can find people I respect who have both opinions. My only contribution is that I suspect that in practice almost every site leaks this info if you try hard enough, via some form of timing attack. You can get off-the-shelf "constant time string comparison" algorithms, but it's impractical to write anything much larger in a constant-time fashion, certainly nothing as complicated as a full authentication flow, especially in the light of the complexity of the systems we program on nowadays, with so many layers of caching to exploit for timing, etc. I've leaned in the direction of going for the user-friendly approach in my code, though I've only come around to that recently.
- dengerzone 10y agoKeepass is good, try to use that.
- welly 10y agoI've been using Dashlane for the past 12 months. It is excellent. Integrates well with OSX, Chrome, Firefox and Android, haven't heard of any security issues/break-ins or them handing out everyone's password data to anyone who shouldn't have them. I'm sticking with Dashlane for the foreseeable future. There's certain things that would be "nice to have" such as an API so a command line utility could be built but I'll deal with it.
- arthurfm 10y ago> I hear good things and it's passed review at a few companies who know their stuff Tavis Ormandy found some really bad vulnerabilities in Dashlane (and 1Password). [1] [2] [3] [4] [1] https://bugs.chromium.org/p/project-zero/issues/detail?id=890 https://bugs.chromium.org/p/project-zero/issues/detail?id=89... [2] https://twitter.com/taviso/status/769391927892598784 https://twitter.com/taviso/status/769391927892598784 [3] https://twitter.com/taviso/status/763801055725359104 https://twitter.com/taviso/status/763801055725359104 [4] https://twitter.com/taviso/status/773218040758448128 https://twitter.com/taviso/status/773218040758448128
- tptacek 10y agoSo far as I know, he only found a vulnerability in the Windows version of 1Password, which is now fixed. I don't know anything about Windows 1Password, but for macOS, I strongly recommend 1Password over any of the alternatives.