15 ms·
LastPass: Security done wrong
- gtirloni 10y agoWhat to use instead that doesn't fall into the same situation and offers decent mobile/browser support?
- pseudobry 10y agoI signed my family up for 1Password a month ago and love it so far. Here's the 1Password Security Design Whitepaper: https://1password.com/files/1Password%20for%20Teams%20White%20Paper.pdf https://1password.com/files/1Password%20for%20Teams%20White%...
- izacus 10y ago1Password has no Linux support so it's not really a drop in replacement. Android autofill functionality is also significantly worse.
- ac29 10y agoAndroid O is getting an Autofill API [0], which should be very useful for apps like LastPass. [0]https://arstechnica.com/gadgets/2017/03/the-android-o-developer-preview-promises-better-battery-life-faster-apps/ https://arstechnica.com/gadgets/2017/03/the-android-o-develo...
- ek750 10y agoThat's too bad. I'm using LastPass because I need multi platform (Linux, iOS, macOS, etc) and multi browser support. And it has very useful features such as sharing and emergency access.
- zie 10y agoNot supported no, but you can use the 1password DB with other tools[0]. 0: http://www.lucianofiandesio.com/1password-in-linux http://www.lucianofiandesio.com/1password-in-linux
- dawnerd 10y agoI use their webapp but it's really frustrating to have to copy+paste all the time from a browser tab. Considering people have been asking for a linux client for a few years now, you'd think they'd find some time. Then again their windows app isn't really polished either.
- sayurichick 10y agohttps://enpass.io https://enpass.io
- Kalounji 10y agoI would say Keepass 2 and Keepass2Android.
- random28345 10y agoI second this. It's usable.
- Sealy 10y agoInterested to hear what the HN community thinks about 1Password
- pragone 10y agoI've taken it as a sign that 1Password must be a fairly good choice as I very, very rarely see it pop up on here.
- bluejekyll 10y agoThat could also indicate fewer people use it?
- roustem 10y ago1Password has over 15 million users across Mac, Windows, iOS and Android platforms.
- barkingcat 10y agoWrong metric to use. Just because nobody talks about it doesn't mean it's a "good" choice. It might be better for all you or I know, but using how many hacker news posts you see for something like this is not a good way to evaluate a product.
- monatron 10y agoI used 1Password for quite a long time but have since switched to LastPass mostly due to Linux compatibility and u2f integration
- mancerayder 10y agoCommentary / Opinions on how this compares to a KeePass+DropBox solution would be quite interesting to me. It seems password managers please some of the people some of the time, and unnerve many of the people all of the time.
- cmdrfred 10y agoI use KeePass+SFTP personally. Something like a password manager I won't trust to a cloud service.
- karood 10y agoI used it (1P) and it was super, but mac only - no Linux client. Just switched over to Enpass, and its very like 1Password, only they do provide a linux client. So far its great, very happy with it. * reply to comment above re 1Password
- CGamesPlay 10y ago1Password is different from LastPass; the article is about the latter.
- karood 10y agoYip, misreplyed to a comment asking about 1Password
- CGamesPlay 10y ago1Password is different from LastPass; the article is about the latter.
- dmd 10y agoThis is about Lastpass, not 1Password.
- dmix 10y agoI use `pass` on linux/mac, which creates a directory of .pgp encrypted plaintext files for each password for each website. https://www.passwordstore.org/ https://www.passwordstore.org/ I sync this directory to my mobile device using megasync (linux packages and Android app available). https://aur.archlinux.org/packages/megasync/ https://aur.archlinux.org/packages/megasync/ https://play.google.com/store/apps/details?id=mega.privacy.android.app https://play.google.com/store/apps/details?id=mega.privacy.a... Then I use `pass` on Android via the "Password Store" app (and the APG app to manage my PGP keys on mobile). https://play.google.com/store/apps/details?id=com.zeapo.pwdstore https://play.google.com/store/apps/details?id=com.zeapo.pwds... The whole UX is super easy. Basically just PGP, plaintext files, and copy/paste.
- deleted 10y ago
- jd007 10y agoI wonder if 1Password is equally susceptible or less so, due to the way that the extension works. Because 1Password has a native application, I believe the browser extensions merely communicate with the native application to retrieve passwords to fill when needed, instead of handling your whole decrypted vault.
- JoelTheSuperior 10y agoPrecisely this. The LastPass extension actually handles the decryption, whereas the 1Password one merely communicates with the app. 1Password should therefore be significantly more secure.
- mentat 10y agoIf it auths the application, which it didn't for quite some time. Tavis has found plenty of issues with 1Password and their team has been much more hostile and less responsive.
- jfindley 10y agoCan you please provide a source for this? The 1Password only bug I can find filed by tavis is [0], in which 1Password were very responsive and thankful of tavis' efforts. I note that can't find anything on twitter that even remotely supports your allegations either. 0: https://bugs.chromium.org/p/project-zero/issues/detail?id=888&can=1&q=1password https://bugs.chromium.org/p/project-zero/issues/detail?id=88...
- crestfallen 10y agoI'm super interested in this. After a super brief Google search, I was unable to find Tavis's results. Could you kindly direct me to them?
- tripzilch 10y ago> whereas the 1Password [extension] merely communicates with the app. wait. the communication goes what way?? You make it sound like the 1Password extension (that doesn't handle encryption, therefore is not authenticated) can request password and credential data from the 1Password app, like it's pulling data from it? How does the 1Password app know that whatever process is making that request is in fact made by that particular browser extension, prompted by user-action on the extension that is the same user as the one that unlocked the encrypted password vault in the app? And if it doesn't why are you storing your passwords in it :) Are we all clear on what a password manager is? Maybe we should start with a good definition, such as: A password manager is an application that manages an encrypted database, that when unlocked by the user, can be prompted by the user, to decrypt an entry from the database, and send one or more fields of that entry to a specified receiving application's input/login field(s). Communication only flows from the user prompting, to the password manager, to the receiving application. Not the other way around. Ok that's not a full definition yet, it also needs a bit about how to store the encrypted database, how not to sync it, not keeping any keys or plaintext in memory any longer than strictly necessary, etc etc. But it's good if we'd have a definition like that, something that is waterproof by definition.
- draw_down 10y agoI never liked it, but I won't pretend it's because I'm some security genius. Just found it very unpleasant to use
- johnjuuljensen 10y agohttp://keepass.info/ http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works great and can read from most cloud storage solutions. Don't know about iPhone. Edit: It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.
- el_benhameen 10y agoWould love to hear from someone who has an iPhone and uses Keepass or a derivative. That's my last barrier to using it.
- graedus 10y agoI do. I use the MiniKeePass app, which is free. You can export your KeePass database (.kdbx) from the Dropbox app to MiniKeePass.
- scott_karana 10y agoDitto. It doesn't make for a good _write_ experience, since you have to copy back to Dropbox manually, but I find that I almost exclusively _read_ passwords, so it's a non-issue for my use case.
- irrational 10y agoDoes this keep things auto synced up between all your devices? I'm constantly switching between different desktops, laptops, tablets, etc. and I'd love a replacement for LastPass that auto syncs just as well and also works on iOS.
- graedus 10y agoAs far as I know the system I described is manual only on iPhone. That is, if the database file gets updated on another device/computer, you have to manually re-import it from Dropbox to MiniKeePass to see the update there. On desktops/laptops, if you're pointing KeePass at a database file in a Dropbox-synced folder, then it's automatic.
- 4ad 10y agoI'm interested to hear what the HN community thinks about keeping passwords in iCloud-based Keychain (Safari) or whatever Google's alternative is called. I don't care about portability. Why would I want e.g. 1Password instead of simply using Apple Keychain. Thanks!
- dewey 10y ago1Password has a lot more features than the default Keychain, smarter autofill to begin with. If that's worth it to you that depends on which features of 1Password you'd use.
- madamelic 10y agoHere is how I think about it: It is a spectrum. You can have high accessibility / ease of use or you can have high security. You can't have both. By storing your info on a remote server, you are trusting they will protect your data. Maybe they will, maybe they won't. It is just a matter of finding a balance you feel comfortable with. Personally, I don't store my passwords on any cloud service, carry them on a thumb drive and don't use services that expose them to the browser. Could I lose a thumb drive? Sure. I rate the chances of someone picking it up and knowing how to exploit it as very low.
- el_benhameen 10y agoHow do you deal with passwords on your mobile device?
- madamelic 10y agoType them in by hand. It does mean I have to have a computer around with me though. I don't really use a lot of apps, I mostly have my bank apps and those stay logged in.
- saosebastiao 10y agoFrom a strict security standpoint, maybe all of this is true. But I see strong PR as a feature, not a bug...at least until password manager market penetration is closer to 100% than it is to 0%. Once you've adopted a password manager, you've limited the scope of potential abuse, and you've decreased the pain of recovering from abuse that does happen. Being forced to change passwords used to be a stressful problem for me, and now it is not. Before, I would procrastinate changing passwords after a breach, because I knew how hard it would be. With lastpass, I literally changed every password in my vault in less than a half hour. The PR matters because it's too easy to hear some bad news and give up on trying to be secure. If the PR prevents people from giving up, I'm all for it.
- mentat 10y agoThese are security critical pieces of software. Like, AV, if the password manager makes it easier to compromise your access in bulk, that's a very very bad thing. This doesn't need to be targeted, just throw some JS into an ad and pwn up 100s of 1000s of accounts. That's actually worse.
- saosebastiao 10y agoMy black hat method is much easier than that, and it doesn't even require a black hat skillset. 1) Download two datasets from different massive breaches. You can find plenty of them with plaintext passwords on any torrent tracker. 2) Correlate email and password combos across datasets. Don't worry, you'll find 10s of millions of people who don't use password managers and reuse passwords. 3) profit If you have reason to believe you're being targeted, any breach is a problem. But until my method no longer produces results, theres no reason to believe black hats will go through any additional effort to obtain the average person's creds.
- Blackthorn 10y agoSigh. I can't ignore the red flags anymore. Time to switch off. Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass. Don't suppose there's anything out there that can import the lastpass db?
- k_sh 10y agoDashlane does! Been using it for a year or so. Good experience. https://csdashlane.zendesk.com/hc/en-us/articles/202699141-How-to-Import-from-LastPass https://csdashlane.zendesk.com/hc/en-us/articles/202699141-H...
- Blackthorn 10y agoI will fully investigate Dashlane. I turned a lot of my non-technical friends onto password managers, and will need to update my recommendation for them with something that can both import the LastPass DB and be as convenient to use.
- smrq 10y agoI switched away from Dashlane after several years because their software has been getting progressively more unstable. Force-killing the Dashlane executable because the browser plugin has locked up got pretty old.
- cypherpunks01 10y agoI love Dashlane, it's pretty magical and a massive timesaver. I use it on OSX primarily but it syncs to my Android very well. There's an unfixed bug in the OSX client where it crashes rarely (every couple months for me) and I have to kill the process manually and restart, but it has very minor impact. Is there any security analysis or consensus on Dashlane security vs. other password managers?
- k_sh 10y agoI have this problem every couple weeks as well. Killing DashlaneMASService solves it.
- Orangeair 10y agoI would love to switch to a different password manager, but nothing else I've tried has quite managed to nail the usability aspect. Specifically, Lastpass's app fill functionality on Android is a huge benefit that I haven't seen in others. It also has a browser extension that works without a separate program running on your computer; I didn't even realize that was a plus until I started trying to use other apps that did that. I guess for now I'll just turn off all of the automatic features like this I can find.
- bigtunacan 10y agoUsability is great, but we're talking about our passwords. Security needs to be put ahead of usability in this case. If you can get both that's great, but poor usability beats having your banking and systems owned.
- baldfat 10y agoWhy would people put their bank and other important passwords like this in a password manager? I use lastpass for over 5 years and I memorize my lastpass and my bank account passwords.
- Bluestrike2 10y agoWhy wouldn't the average user? The entire idea is that you'll just have to remember two passwords: your computer account, and your password manager. At least for most users, the idea that some password shouldn't be stored just opens the door to bad practices and password reuse. For someone working on a password manager, I think the default assumption has to be that a screwup on your part will--literally--impact pretty much every aspect of a user's life. You can't assume that some passwords won't be stored.
- baldfat 10y agoWell my wife believes that reusing the same password with variations is more secure then a password manager. Most average users distrust a manager and won't use it.
- feeblewitz 10y agoI've been a LastPass user for a few years and I use the browser extension everyday. As an admin of several websites, the the extension has been a time saver. I thought I had no illusions about the inherent insecurity in using LastPass, but I guess I was wrong. I use Yubikey and disabled autofill long ago, but I was still vulnerable. Their response to these exploits is maddening. "Our investigation to date has not indicated that any sensitive user data was lost or compromised." This when they can't verify if passwords were compromised as LastPass servers weren't involved in this exploit. So I guess I need to switch to a different service. Any suggestions?
- Oculus 10y agoI'm a big fan of 1Password.
- dbg31415 10y agoI've struggled with this too. I love how I can share passwords with a team using LastPass (share just access, share ability to view, share ability to edit). For me... it's more about getting the team using the right tool than individuals. There are probably better individual solutions than LastPass, but I don't know of any that are better for teams. I know that having a tool that lets you share passwords is inherently risky... but I still think LastPass is less risky than people sharing via PostIt, or sharing via emails... or less risky than not sharing passwords in that "hit by a bus" scenario we always talk about. I tried Enpass, 1Password, and KeePass for individual use... none of them were horrible (I liked 1Password the most). Enpass let you sync your vault with the storage option of your choice... so you could sort of do team passwords that way. Typically I don't want to share all my passwords, just a few... and like I would want to share different subsets with different people... so that "share your vault" option wasn't ideal for me. Usability-wise, I love how LastPass fills in my credit card info and address on forms I tell it to. And how LastPass can automatically update passwords for many common sites. And gives me a report of passwords that are weak, old, and duplicate -- the "global rank" on LastPass is a game and I want to get a high score. Ha. (Full disclosure, I tried each casually for less than a week... there may have been things I missed.) Been on LastPass for a long time, generally happy with them and haven't found anything that better fit my needs, but clearly these reports that they aren't taking security as seriously as they should be are troubling. EDIT: Going to look at https://1password.com/teams/ https://1password.com/teams/ in the next week or so. I don't think this option existed last time I looked at 1Password.
- ja27 10y agoI've always been quite nervous that the LastPass two-factor authentication can be easily bypassed if your email account is compromised. On the 2FA screen there's a "If you lost your Google Authenticator device, click here to disable Google Authenticator authentication" link. No. I don't want that to be able to be disabled. I have one-time passwords for that.
- nickik 10y agoYou can configure quite a lot of stuff in the 2Fa settings. I have no such option for my 2Fa on Lastpass. Also, my E-Mail also has a 2Fa.
- twblalock 10y agoGiven how many sites will send password resets and one-time-use second factor codes to email, it's pretty much imperative to have two-factor auth on your email account these days.
- hyyypr 10y agoThe HN community seems to be giving a lot of praise for 1Password, Lastpass and Keepass occasionally. But rarely mention Dashlane, I'm curious as to why ?
- cube2222 10y agoIt's interface and usability is also ridiculous on windows, and it's the most expensive of all.
- hyyypr 10y agoCould you elaborate ?
- dublinben 10y agoDashlane isn't open source, nor is it available on Linux. That is going to prevent a lot of people from even considering it.
- deleted 10y ago[deleted]
- svenfaw 10y agoLastpass / 1Password are not open source either.
- dublinben 10y agoGreat reason to not recommend them either!
- doublerebel 10y agoThe Dashlane Windows app does work under Wine. Dashlane is the only password manager that looks normal enough to be used by the non-tech members of the company. I've found its sharing feature invaluable, I can get the whole team on it using 2FA and passwords don't get emailed around anymore!
- 10y ago
- mnm1 10y ago"Altogether it looks like LastPass is a lot better at PR than they are at security. Yes, that’s harsh but this is what I’ve seen so far." No, it's not harsh enough for a program that knows the right password, shows it to you, but then inputs the wrong one in the password field. Of course, compared to these security issues, such UI issues are almost irrelevant. With such a simple UI to program, you'd think they'd at least get that right or fix it. And if they don't, it's likely they have much bigger problems under the hood. Over and over. Unfortunately, all the reviews of Lastpass I read gave it 4-5 stars and it was often a recommended or editor's choice pick. Clearly, those reviewers and their publications are just a bunch of shit words to attract advertising (that includes pretty much every article on password managers I managed to read). This is a pretty important part of security. If it takes someone with expert skills in computers almost a year to find a good password manager program, not to mention days worth of work importing into and testing various solutions, what chance does your everyday computer user stand? The way things stand with password managers right now, I'm not sure we're advising ordinary computer users correctly in telling them to use one.
- r3bl 10y ago> If it takes someone with expert skills in computers almost a year to find a good password manager program, not to mention days worth of work importing into and testing various solutions, what chance does your everyday computer user stand? The reason why I hate these kinds of threads in IT communities is that we usually don't seem to talk about the issue(s) the article is referring to. Take this one for example. There's much more discussion about what works for who than the actual content of the article. And then I followed an article linked in the comment here about getting 1Password to run on Linux. And at the bottom of the article there was a link to the HackerNews thread about that article. And the situation is exactly the same. Out of 57 comments in that thread (https://news.ycombinator.com/item?id=9091691 https://news.ycombinator.com/item?id=9091691), only four are actually related to running 1Password on Linux, and none of them is actually related to someone actually trying the method from the article and sharing his/her experience. 53/57 comments are basically "I use X because of Y".
- OJFord 10y ago
- dahart 10y agoIt must be noted that the author of this article has a competing project, and in an article so deeply critical of LastPass, it seems like a disclaimer should be prominent. Wladimir does disclose this on the previous article: https://palant.de/2016/09/16/more-last-pass-security-vulnerabilities https://palant.de/2016/09/16/more-last-pass-security-vulnera... As a fairly happy LastPass user, I would certainly like to know what ongoing threats there are here, and what the real-world likelihood that I might be exposed to those threats. Would anyone care to summarize? The linked issues have been fixed, even in Firefox, and the claim that vulnerabilities still exist are unsourced. *EDIT: disclaimer has been added! My comment is now out of date.
- SubiculumCode 10y ago+1 Agree. Lastpass has great functionality imo, and I want a level headed analysis before I jump ship to a competitor. I do wonder though if the change in ownership last year has led to a decline in quality.
- Adaptive 10y agoFWIW I manage a couple Lastpass Enterprise installs and I haven't seen any indicators of a reduction in quality. Even @taviso had this (positive) follow up tweet: https://twitter.com/taviso/status/844574176165822465 https://twitter.com/taviso/status/844574176165822465
- SubiculumCode 10y agoyup. I checked my LastPass extension and it had updated and needed a browser restart.
- palant 10y agoFrankly, I cannot really understand him being positive about that. A vendor that rushes out a fix without verifying that they fixed the issue everywhere - that's not great at all. I definitely prefer vendors who take a few days to look at the issue properly. But then again, if LastPass did this they would have addressed the issues back in August last year at the latest and I would have nothing to write about.
- alexmat 10y agoI use passwords.google.com It works well with chromium on linux and on my android phone. It's free, has all the security of a google account including u2f, chromium integration is flawless on linux, and works well with chrome on Android.
- SubiculumCode 10y agoI just noted that my lastpass extension was updated by Firefox. Is this fixed?
- rebootthesystem 10y agoI am almost ready to file a lawsuit. Context: What I am after is a password manager that has the option to NOT store anything in the cloud at all. I want encrypted storage to be stored locally. No exposure outside my network. Inter-device synchronization done manually or automatically within the confines of said private network. I would also like to store data beyond uid's and pwd's. For example: secret questions and their answers, account and pin numbers, company tax id's, bank account numbers, passport numbers, etc. In other words, data you might need handy that should be encrypted. I've been using a program for a number of years. The program started exactly as I described above: Network only synchronization. Over the years they have mutated the program to cloud based storage. And, over the years, they have done this without warning to users or seeking any kind of authorization. Imagine if you are using software that only stores data locally and syncs over your network only to wake up one day to discover that the latest update uploaded all of your secret data to their cloud-based system WITHOUT your permission. And, to make things even worst, they progressively eliminated the network sync option. The current version doesn't even ask, the minute you edit a record or create a new one it shoots it up to the cloud. Unbelievable. Years ago I asked about this. I have an email from the support assuring me the data would never be stored on the cloud. Time to file a lawsuit? Anyhow. Is there a tool fitting my description above? I don't care if it's free or paid. I simply want my data to never move outside my network unless I want it to.
- et-al 10y agoThey don't make it obvious, but 1Password still offers a standalone version on Windows/macOS. And KeePassX allows you to manage your own synchronisation.
- jameskilton 10y agoHave you looked at https://1password.com/ https://1password.com/? And it looks like https://www.enpass.io/ https://www.enpass.io/ has similar capabilities, but I don't use it so I'm not sure exactly. 1Password keeps a local encrypted file. The "integrations" are 1Password knowing default locations to look to store the file in the right directory.
- mi100hael 10y ago
- miles_matthias 10y agoI've been using LastPass for a few months and have loved it, but maybe I'll consider switching to 1Password. <rant> However, can I just rant for a second about how these security assessments and blog posts fold out? The beginning of my career was spent thinking I was going to go into this field (one of my degrees is in Information Assurance) and the #1 thing that persuaded me to switch to building software instead was the attitude and approach of the security field. If it's not 100% secure and we all agree that it's the 100% best way to do something, it's the end of the world and anyone using LastPass is an idiot who will have all of their passwords hacked and their life ruined. (Remember when the draft for client side storage was announced? You would have thought armageddon was upon us based on the reaction of the security industry.) Big picture here -- most people re-use a short, simple password on all of their sites. Using a password manager, even one with a few things that it can and should improve, is a HUGE step in consumer behavior. Bickering amongst ourselves and boasting for crapping on someone's company is not the right approach to increasing our entire society's security stance. Want to actually help? 1. Create more resources to help consumers pick, use, and adopt a password manager with super simple setup process. Even the current methods that all password managers use of generating, saving, and autofilling passwords are too complex and cumbersome for the average consumer. Heck, even MFA is seen as a huge waste of time and barrier to logging into people's accounts by the majority of people right now. 2. Create more resource to educate developers of these services, helping them to see what they should do and how they should do it, not bragging about your ability to tear down a service they spent hours slaving over. Get over yourself and actually help society. (https://www.owasp.org/index.php/OWASP_Guide_Project https://www.owasp.org/index.php/OWASP_Guide_Project is a great example of this) Looking for an example? Apple's iTouch. Yes -- it's not the most secure option. People leave their fingerprints all over the place and they can be lifted and used to unlock a phone. But look at the other option -- using no passcode, or a 4 digit passcode that's easy to guess or look over a shoulder. Is it the most secure option? No. Does it raise the level of security for our society as a whole by providing a realistic security barrier that the average consumer can use? Yes. </rant>
- irrational 10y agoThank you for putting into words my exact thoughts. Though, I'm cynical enough to believe that people would rather moan about how much password managers suck (Why can't everyone just memorize a different 30 character string for each of their 200+ websites? Losers.) and not do anything productive to fix it. I wish I had the skills to do so.
- h1d 10y agoNot sure how people like online password managers. The consequence will be far worse than selling your online attitude to Google by using their online services in case of a security breach. It pretty much gives your online self up to hackers. With that said, I only use offline managers and this is only for Mac but Locko by Binarynights is clean and easy to use. The downside is that it's browser extension can't remember basic auth credentials but other than that I like it. I can also back up the encrypted database easily with a script. (Seems the link is gone from their site with the release of forklift3 but the page still exists. http://www.binarynights.com/locko/ http://www.binarynights.com/locko/ )
- touchofevil 10y agoDoes anyone use Keeper? How is it? I need a password manager that supports Linux so it seems that LastPass, Keeper, Enpass, and Keypass are the only options. https://keepersecurity.com/ https://keepersecurity.com/
- Kametrixom 10y agoI can recommend https://www.passwordstore.org/ https://www.passwordstore.org/
- deleted 10y ago[deleted]
- test6554 10y agoI literally just decided to jump into the world of password managers this past weekend. I went with LastPass
- indutny 10y agoHas anyone considered using DerivePass yet? (https://derivepass.com/ https://derivepass.com/) It doesn't store passwords anywhere at all, just the domain and login information, both of which are encrypted with your master password. (Disclaimer: I'm the author of it).
- aeleos 10y agoDoes anyone know of an extension based program, that doesn't rely on an application, that just uses a keepass file stored in the cloud? I really like the idea of KeeWeb, but I wish it could be part of an extension, with support for things like automatic detection and autofill.
- staticassertion 10y agoYeah, the two weak points pointed out have always been weak points. It's unfortunate, but disabling autofill has always been my recommendation. > Altogether it looks like LastPass is a lot better at PR than they are at security. Yes, that’s harsh but this is what I’ve seen so far. In particular, security vulnerabilities have been addressed punctually, only the exact scenario reported has been tested by the developers. This seems unfair. LastPass fixes the initial vulnerability punctually - we do not know what they will do in the future. Is it better for them to wait, come out with a defense in depth approach, and then patch? Seems silly. Of course, how long do we wait? Historically, I would argue, LastPass has down defense in depth fairly well - when their was a breach they were quick to not only address the vulnerabilities immediately but soon after they rolled out Content Security Policy and HSTS, two technologies that were rarely deployed in the wild at the time (and are still sadly too rare). My suggestion to LastPass users is to: 1) Enable 2FA 2) Up your PBKDF2 Rounds 3) Disable as many browser integration features as possible I don't recommend dropping LastPass and trying to roll your own key-sync store with KeyPass/Dropbox as some have done. I don't know of any other browser-based password manager that isn't equally weak to attacks based on browser-integration. Alternatively, don't use a browser-based solution. This is less convenient but you'll avoid by far the largest area of attack surface.
- proactivesvcs 10y agoWith KeePass, a Yubikey and Syncthing you have a pretty solid system which you can carry around with you, without having to trust any third party with any data (or service availability). Arguably you could even leave out the Yubikey and still get a great degree of security.