8 ms·
Since your master password is stored in another password manager, would it be accurate to say you copy/paste it into LastPass? If so, something running on your
by RKearney 5y ago
Since your master password is stored in another password manager, would it be accurate to say you copy/paste it into LastPass? If so, something running on your machine could be scraping your clipboard.
This of course assumes that it wasn’t really you from an IP that was just misidentified as being from Brazil.
For what it’s worth, I stopped using LastPass after they sold out to LogMeIn and would recommend others stop using it as well.
- gregsadetsky 5y agoYes, I do copy/paste from my local password manager. A clipboard scraper is a possibility, yes. I hadn't logged into that LastPass account for years, so it's definitely not me who attempted to login earlier. Re: LastPass, is there another cloud-based tool that's generally considered as more trustworthy? Bitwarden? Thanks
- coderintherye 5y agoBitwarden is great, highly recommend, it's open-source which adds to its trustworthiness and has a good track record of respecting users.
- nyolfen 5y ago+1, you can host your own server as well https://github.com/dani-garcia/vaultwarden https://github.com/dani-garcia/vaultwarden
- hda111 5y agoUnofficial server so you probably should avoid the web application (or build it yourself from official sources). In theory it could contain malicious code that leaks your password.
- sofixa 5y agoThere's an official self-host open source version as well ( the one you linked is unofficial), but it's rather heavy ( multiple .NET services, MS SQL) and not adapted for small scales.
- senectus1 5y agoI'm in this party too. bitwarden for yourself, friends and family...
- rich_sasha 5y agoI use 1Password, seems alright security wise, won’t definitely say one way or the other, but you could DYOR on it.
- mateuszf 5y agoBitwarden is fantastic
- 40four 5y agoPersonally I just stick to local Keepass database files. I’ve never ventured into the cloud based services. If you are really worried about it, do you really need to use a cloud based password service? Sure, managing the KeePass files by hand is certainly more cumbersome, but to me it’s worth it for the security/ peace of mind gains. I have never put my DB or key files in the cloud. And when I need to sync them up over all my devices, I gather all the DB files and use the handy ‘merge’ functionality to get them into the same state.
- tomsmeding 5y agoTIL about the merge functionality! You can also use Syncthing to synchronise the databases between your devices; if you don't have public IPs for your devices, this essentially means that you can only synchronise when two devices are on the same network -- but this might not be a problem for you.
- newaccount74 5y agoSyncthing works great even behind a NAT, not sure how it works but it just works for me (might depend on your NAT though)
- tomsmeding 5y agoI've had zero success with nat hole punching in the past, on multiple networks. Maybe I'm just unlucky. :)
- newaccount74 5y agoSome routers have UPnP disabled by default, maybe enabling that would help?
- tentacleuno 5y agoYou can also use Syncthing and the merge function! It comes in very handy when two devices have made changes to the password database file and you end up with merge conflicts :D
- fragmede 5y ago1Password has a cloud-based option these days, for better or worse.
- runlevel1 5y agoAnd soon they'll _only_ have a cloud-based option with no option for local-only vaults. https://1password.community/discussion/comment/602340/#:~:text=1Password%207%20will%20be%20the%20last%20version%20of%201Password%20to%20support%20standalone%20vaults https://1password.community/discussion/comment/602340/#:~:te...
- jacquesm 5y agoGotta get those sweet SaaS dollars and never mind the original goals or the user.
- davidstoker 5y agoOf note, LastPass just announced that they are splitting out of LogMeIn and becoming independent again: https://blog.lastpass.com/2021/12/lastpass-investing-even-more-in-your-password-security-in-2022/ https://blog.lastpass.com/2021/12/lastpass-investing-even-mo...
- briffle 5y agoOf course, you must reduce the risk to the parent company before the huge disclosure comes out </sarcasm>
- deleted 5y ago[deleted]
- studiecomput 5y agoWhy do you recommend others to stop using LastPass?
- sliken 5y agohttps://en.wikipedia.org/wiki/LastPass#Security_issues https://en.wikipedia.org/wiki/LastPass#Security_issues
- luckylion 5y agoFrom my interaction with LastPass support (I'm a premium user), they've outsourced to some cheap company where agents have no clue how anything works. It took weeks to get through to somebody who even understands the problem and their reply was essentially "yeah we know it's broken, it's broken because of security". Left a really bad taste in my mouth. I wouldn't be using them at all if I didn't have to for a client.
- ChrisMarshallNY 5y agoI remember reading a blog entry, a few years ago. Someone received a phishing email from "their bank." They responded to the email, and got someone on the horn, immediately. But their bank (the real one), sent them to a horrifying voice jail. The point was that the crooks gave better customer service than the real bank.
- whatsapps2020 5y agoIt makes sense economically. Crooks will steal ~100% of your bank balance in one day. Bank itself earns 1-2% per year.
- ChrisMarshallNY 5y agoYup. The blogger was just being cranky about their bank.
- squeaky-clean 5y ago