6 ms·
I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it. So many better
by darrmit 9y ago
I can’t figure out why LastPass is still so popular. Ease of use since it’s completely browser based? They were early to market? I don’t get it.
So many better designed, more secure options out there. KeePass, Bitwarden, or 1Password to name a few.
- SubiculumCode 9y agoThat is a whole lot of opinion, but not much substance. What makes LastPass inferior to these other options?
- craftyguy 9y ago> What makes LastPass inferior to these other options? Well, for one, the very first sentence of the article here.
- strictnein 9y agoThe article whose "exploit" requires handing your unlocked phone to someone?
- SubiculumCode 9y agoAnd which just got revealed,and will probably be fixed.
- craftyguy 9y agoYou'd be surprised how many people (not on HN) use extremely weak (or no) unlocking mechanisms for their devices. It overlaps with the set of folks who would want to use LastPass because of how easy it is.
- saosebastiao 9y agoDo you know what is easier than using last pass for people who use weak unlocking mechanisms? Using the same password everywhere. I'd be surprised if there was any overlap at all where you claim.
- craftyguy 9y agoWell, I have several family members that fall in the "I use a pattern to unlock my phone or do not use anything to lock it, but store passwords in Last Pass" category. So I guess you're wrong.
- larvaetron 9y ago> (Edit #1, 7.30pm GMT): A lot of people are saying that this flaw requires physical access. However, as I pointed out above, you don’t need physical access, a maliciously installed application can easily access the activity and capture the code.)
- strictnein 9y agoSo you don't need physical access you just need to install a malicious application? Okay then. Why can one application even explore and access the views of another?
- elsif1 9y agoAccessibility APIs
- Someone1234 9y agoThe article that is literally not about Lastpass's password manager? Lastpass Authenticator is not their password manager. It is a Google Authenticator competitor...
- craftyguy 9y agoIf they have a history of shitty security practices (this app), then why should we fully trust other apps they make?
- Someone1234 9y agoYou're going to double down on completely misreading the article and misquoting as to why their Password Manager is insecure? Come on...
- craftyguy 9y agoHere, since you can't be bothered to do your own research before jumping to conclusions: https://www.theverge.com/2017/3/22/15023062/lastpass-security-flaw-passwords https://www.theverge.com/2017/3/22/15023062/lastpass-securit... https://www.pcworld.com/article/2936621/the-lastpass-security-breach-what-you-need-to-know-do-and-watch-out-for.html https://www.pcworld.com/article/2936621/the-lastpass-securit... https://labs.detectify.com/2016/07/27/how-i-made-lastpass-give-me-all-your-passwords/ https://labs.detectify.com/2016/07/27/how-i-made-lastpass-gi...
- Someone1234 9y agoNone of which has anything to do with this thread, your claims, or your erroneous claim that the article was about their password manager. Keep doubling down...
- darrmit 9y agoPerhaps I could have clarified better, but I was speaking to the various nasty security issues they’ve had mainly. I also find their apps to be ugly as sin, but that’s a personal preference.
- corobo 9y agoWhen your rival is KeePass you don't really need to do much in terms of UI/UX
- rbjorklin 9y agoFor me ease-of-use is a killer feature. Do any of the alternatives you suggested sync automatically between devices? Do they auto-fill?
- onewhonknocks 9y ago1Password does. It's great.
- cannonedhamster 9y agoI use 1Password at work. It's not very good and doesn't seem to work on linux, which I need for work. Add to that really clunky user management...it's just not that great usability wise. I've never been able to get it to autofill either. Lastpass on the other hand just works on all my devices. We were using Keepass before but syncing was such a massive PITA that my wife wouldn't use it. Now she at least uses Lastpass with a better password than what she was using before, but I suspect until we're robbed she's not going to see the value in security. Don't get me started on her and the 2FA grievances.
- MBCook 9y agoiCloud Keychain does, and it’s free, but obviously it’s limited to Macs and iOS devices.
- Someone1234 9y agoiCloud Keychain doesn't work with all apps or even all browsers, when it doesn't there's no trivial way of copying in a password, it isn't cross-platform, and you cannot import or export existing passwords. I consider the other products listed as actual competitors of Lastpass, I don't even rank iCloud Keychain that high, it lacks even basic features.
- MBCook 9y agoCopying a password isn’t that hard, you can get to it through keychain or the password section in iOS Settings. It’s definitely not cross platform, but that’s to be expected from an Apple product. Doesn’t support other browsers? I suppose, but for me and many other people that’s not an issue. It works fine in for many individuals I think they could consider it a competitor. It’s certainly not an answer for MOST people, but if you’re in the right group it works great.
- hedora 9y agoI think it is mostly inertia and cross-platform support. Before they were acquired, they seemed to care a lot more about security, instead of just security theater. They also have some nice crypto features: For instance, I forgot my master password, and they have a one time password reset protocol that lets them send you an unlock code that only works on previously logged in devices. Also, it has rock-solid offsite backup built in. Moving away has been on my TODO list for a long time.
- SubiculumCode 9y agoI certainly have worried about LastPass after their aquisitions, but have no concrete grievances, save the extension seems slower than it was previously. I like a number of features in LastPass. The auto fill, the auto password change feature, password sharing, etc.
- Someone1234 9y agoI have a concrete grievance since acquisition... They've started to dump crap into the Lastpass Vault. First it was adverts and then they modified the search bar to search the web rather than only your saved passwords/notes. Both attempts at gaining advertising/referral revenue and in my opinion at the cost of security. I've disabled the idiotic search and was paying for Lastpass Premium before so don't see the ads but it is the principle that the company now places minor revenue over what I consider security which I cannot stand. Plus I had issues with LogMeIn's business practices previously and moved to a competitor. Only to now have them follow me by buying Lastpass. I am in the early stages of looking at moving away from Lastpass (after four years).
- mbesto 9y agoI just moved away from LastPass due to the acquisition and migrated to 1P. I had two issues with the migration that were easily solvable by someone technically inclined. 1) Folders don't get migrated over to tags into 1P. You need to use this pearl script to do so. (google it) 2) Autofill is well umm different. It took some getting used to, but you now have to hit Cmd+\ to autofill intsead of using the mouse. It's more secure and it ends up being more "clean" I've noticed.
- misterbowfinger 9y agoit's a free version of 1Password
- busterarm 9y ago1Password more secure? Surely you're joking.
- MBCook 9y agoWhat makes you say that?
- busterarm 9y agoSee my other reply: https://news.ycombinator.com/item?id=16016274 https://news.ycombinator.com/item?id=16016274
- busterarm 9y agoSeems folks forget just how poor of a job they were doing only a year ago. SIK-2016-038: Subdomain Password Leakage in 1Password Internal Browser SIK-2016-039: Https downgrade to http URL by default in 1Password Internal Browser SIK-2016-040: Titles and URLs Not Encrypted in 1Password Database SIK-2016-041: Read Private Data From App Folder in 1Password Manager SIK-2016-042: Privacy Issue, Information Leaked to Vendor 1Password Manager The tradition with this company is not a serious (as in mission-critical serious) approach to security and the amount of FUD that they spread anytime they take real criticism from the community speaks volumes. They had more vulnerabilities disclosed last year than any of their competitors. Just because you like it doesn't mean that it's secure software.
- darrmit 9y agoWasn’t aware of these, but just solidifies my move away from 1PW.
- yegle 9y agoThe ability to fill password in Android app. The last time I checked there's no competitors doing this. I'm hoping the Autofill API in Android Oreo can bring more competition.
- xxkylexx 9y agoBitwarden supports autofill through accessibility services and through Oreo autofill.
- CaptSpify 9y agokeepassdroid lets you do that via copying data to the clipboard. Not a great solution, but it works
- yegle 9y agoEvery password manager allow you to copy/paste your password. This is NOT a solution.
- CaptSpify 9y agoInteresting, because it works for me. Now that may not be a solution that works for you, but it clearly is a solution.
- criley2 9y agoThe clipboard is insecure and can be accessed by any app that is running. It's not a secure solution, period end of story, to copy paste a password to a shared location on the device that all running processes can access. https://developer.android.com/guide/topics/text/copy-paste.html https://developer.android.com/guide/topics/text/copy-paste.h... I mean, there's the guide. I wouldn't put my passwords on the clipboard, personally.
- SAI_Peregrinus 9y agoKeepass2Android has a custom keyboard to auto-type usernames/passwords.
- nathanvanfleet 9y ago1. It's not easy to have all the integrations necessary to make this product 2. There ultimately doesn't appear to be that much money in it compared to other businesses 3. The least secure password manager is more willing to do the unsafe thing that is a killer feature that users want.
- chaostheory 9y agoThey're owned by Citrix so they have automatic credibility. In this case, the name is important too. It's easy to remember and it explains the product as well. The only alternative with a better name is 1password
- balladeer 9y agoKeePass is anything but user friendly or convenient - it involves a lot of tinkering and not a lot of people have time, patience, or even know-how for that. It has never been and I don't see that happening in near future. In comparison LastPass is "sign up once, use everywhere". 1Password royally ignored every other platform other than the fruit company ecosystem for a really long time. See, I am not speaking as a fanboy, I am not one. Just a satisfied user - I have really tried all other apps out there and for some reason or the other I kept coming back to LastPass. Bitwarden came close to make me switch. OSS, polished, and seemingly with a business model. After checking on Elementary Firefox, iOS, Android apps when I went find its Safari extension (that's where I do my personal browsing) - it didn't exist, it still doesn't and the Github issue is clear that they will not be working on that [0] anytime soon. Also, I read a reddit comment that there was only one full time developer and this was few weeks ago[1]. Now I know it's an open source project but I want to use a service that is really ready to be used for my password management. LastPass - it's not really entirely browser based, it's actually available everywhere - Windows, Linux, Mac, Chrome, Ff, Safari, IE, iOS, Android. You name it. And it has been on these various platforms since long. Sync, client side encryption, easy import from other apps, good extensions, decent support ticket TATs (even for free accounts), continuous development (however I must add that they have started to add bloat and useless gloss after the sale) - have really been consistent. This is what makes it a favourite option. So when you say "better designed" I assume you mean better security architecture designed and yes it is ease of use with acceptable security for the most. [0] https://github.com/bitwarden/browser/issues/17 https://github.com/bitwarden/browser/issues/17 [1] https://www.reddit.com/r/Bitwarden/comments/7htswv/how_many_people_are_involved_in_bitwarden/ https://www.reddit.com/r/Bitwarden/comments/7htswv/how_many_...
- WhitneyLand 9y agoI think you make some good points, I prefer the practical perspective. Lastpass seems to lack a fair amount of usability polish, but it’s all relative maybe no one is better. For example, why when adding new sites, it likes retain even super long useless query param strings that clutter the interface. Without going into detail, this is in no way technically necessary for most cases. Also, they already have the ability to pre-associate common login sites, yet won’t do it for many popular domains. For example, there are a few stack exchange sites with different domains but that use the same credentials. Why should I have to manually set this up for a site that’s not far from the top 100 in traffic on the planet? It’s been requested, they won’t do it. Pay a damn intern to pre-associate the top 500 domains at least when needed. There are many other practical examples. But again, maybe the bar just isn’t that high in this category of software. Edit: What didn’t you like about bitwardem? Haven’t had a chance to try it yet.
- sp332 9y agoIt doesn't have to be browser-based. If you'd rather have a stand-alone app there's one in the Microsoft Store.
- balladeer 9y agoKeePass is anything but user friendly or convenient - it involves a lot of tinkering and not a lot of people have time, patience, or even know-how for that. 1Password has ignored every other platform other than the fruit company ecosystem for a really long time now. Bitwarden comes close. OSS, polished, and seemingly with a business model. After checking on Firefox (on Linux), iOS, and Android apps when I wanted to install it on my Mac I found out its Safari extension doesn't exist and the Github issue is clear that they will not be working on that anytime soon [0]. Also, I read a reddit comment that there is only one full time developer and this was just few weeks ago[1]. Now I know it's an open source project but I want to use a service that is really ready to be used for my password management while I want to pay for it. LastPass is everywhere - Windows, Linux, Mac, Chrome, Ff, Safari, IE, iOS, Android. You name it. And it has been on these various platforms since long. Sync, client side encryption, easy import from other apps, good extensions, decent support ticket TATs (even for free accounts), continuous development (however I must add that they have started to add bloat and useless gloss after the sale) - have really been consistent. This is what makes it a favourite option. So when you say "better designed" I assume you mean better security architecture/design and yes the reason for its popularity is indeed ease of use with acceptable security for the most. I have really tried all other apps out there and for some reason or the other I keep coming back to LastPass. [0] https://github.com/bitwarden/browser/issues/17 https://github.com/bitwarden/browser/issues/17 [1] https://www.reddit.com/r/Bitwarden/comments/7htswv/how_many_people_are_involved_in_bitwarden/ https://www.reddit.com/r/Bitwarden/comments/7htswv/how_many_...