5 ms·
Interesting, it isn't prompting me to do any such thing. Anyway, since many are mentioning 1Password - I used that for a couple years and switched to lastpass,
by pstack 15y ago
Interesting, it isn't prompting me to do any such thing.
Anyway, since many are mentioning 1Password - I used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows.
Also, since I use two-factor authentication, I wonder if that's the reason they have not asked me to change my password?
- mike-cardwell 15y agoIn the comments it states: "We're only forcing the issue right now you when we see you come from an IP you haven't used in the past few weeks (if you disable logging logins this might mean immediately)." It hit me straight away even though I'm using a static IP, because I disabled the logging of logins after this happened: https://grepular.com/LastPass_Vulnerability_Exposes_Account_Details https://grepular.com/LastPass_Vulnerability_Exposes_Account_...
- pstack 15y agoThanks. I had seen someone else asking in the comments on that page about two form authentication with regard to this, but hadn't seen any further comments about who this may or may not affect at the time I read it. Of course, I went ahead and changed it anyway, since it was getting to be about time.
- brown9-2 15y agoI used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows. I find that Keepass, with the database saved on my Dropbox folder, works well. No browser integration needed - Keepass registers an OS hotkey (at least on Windows) for ctrl+shift+A which will autotype ${USER}TAB${PASS} in the currently focused field, using the title of the browser window as the entry to look for in the pw database. Great for a free solution.
- edanm 15y agoSeconded. Just wanted to add that it's possible to configure any auto-typing (the default is ${USER}TAB${PASS}), which means sites having all sorts of other info are easy to work with as well. I actually wrote a blog post about using Keepass with various tricks: http://www.loopycode.com/solving-sign-up-anxiety/ http://www.loopycode.com/solving-sign-up-anxiety/
- deleted 15y ago[deleted]
- 16s 15y agoIn my mind, that's the primary design flaw with traditional password managers. Why should end users store passwords? It introduces so many issues. Must have proper encryption. Must deal with synchronization. Must have master password. The list could go on and on. Passwords should be generated (locally on your device) when needed, and never stored in any way. Edit: Some more negatives to password storage. Must protect stored password file. May be required to log access to stored password file for compliance reasons. Stored password files may become corrupt and stop working.
- brown9-2 15y agoI don't think I understand this - if the password isn't stored, do you expect the user to memorize all the various passwords?
- 16s 15y agoEnd users don't need to memorize any passwords. They don't know them and they do not care what the passwords are (nor should they). They only need to know how to generate them when needed. Read about SHA1_Pass and try it out. I use it (and wrote it) to deal with hundreds of passwords that change frequently. I tried to make traditional password managers work for a number of years, before realizing that the traditional approach (password storage, master password) is fundamentally flawed and introduces more problems than it solves.