3 ms·
My reason for not using LastPass is because it is proprietary. In fact, there has been an XSS attack on them in the past which was somewhat successful. I use Ke
by TheEskimo 15y ago
My reason for not using LastPass is because it is proprietary. In fact, there has been an XSS attack on them in the past which was somewhat successful. I use KeePassX because it allows me to avoid laying trust on any proprietary entity. At present if LastPass were to have another security flaw (and hey, security flaws on web-facing servers are all too common) you'd be out of luck. With KeePassX security is local. The worst case for me is someone stealing my database and trying to bruteforce the password (hah, like that'll happen). This requires them to have physical access to my computer. Anyone can take a guess at your password because it's a web based service.
- illumin8 15y agoKeePassX is still vulnerable to a keylogger on your local machine. LastPass with 2-factor auth should be more secure than KeePassX, however, your point about it being proprietary is well taken. I also think LastPass has a very good reputation for full disclosure - when the salted hashes of master passwords were compromised in 2010 it was very refreshing to see the CEO come forward and give immediate full disclosure to the public about the implications, and why you should change your master password. I also find it refreshing that if you have a strong master password, even someone compromising their entire database should not give you reason to worry - it would be similar to someone getting a copy of your KeePassX database - it's still encrypted with high-grade encryption.