17 ms·
LastPass appears to be holding users' passwords hostage
- whitepoplar 5y agoLast time I checked (a couple years ago), the only seemingly trustworthy password managers were 1Password and pass. Has this changed?
- RupertHandjob 5y agoHow is 1Password more trustworthy than opensource and "audited" Bitwarden?
- whitepoplar 5y agoMembers of the security community whom I trust gave their recommendation to those two products and went out of their way to suggest not using other products. I trusted that advice and picked 1Password. Also, AFAIK, even though 1Password is closed source, it has been audited.
- msoad 5y agoI use iCloud Keychain because Apple is not in business of making money off a password manager. They charge me more via their hardware sales scheme but at the end of the day it’s a good experience overall
- halfmatthalfcat 5y agoCan you share passwords with iCloud Keychain? I ask because I heavily use the family vaulting in 1PW to share common passwords amongst family.
- msoad 5y agoSharing is available only via AirDrop. You can copy the password too. But no "shared password".
- Someone1234 5y agoA solution that isn't cross-platform at all. Non-starter for me.
- msoad 5y agoThey have a Windows app. I only have iPhone, iPad and Mac so not sure how good it is. https://support.apple.com/guide/icloud-windows/set-up-icloud-passwords-icw2babf5e03/icloud https://support.apple.com/guide/icloud-windows/set-up-icloud...
- mrtranscendence 5y agoI see your point, and if I were (say) a Linux user I of course wouldn't use iCloud. But as someone whose entire digital life is on iOS and macOS, it doesn't bother me that it may not work (or work as well) on other platforms.
- mdavis6890 5y agoStrange - the fact that Apple is not trying to make money from passwords seems like a good reason NOT to use it. Though I don't have much experience with keychain so I can't comment on that specifically. (I do have a lot of Apple devices I like though). I feel more comfortable when a company is trying to earn my money by delivering a good product with good service. Of course that doesn't always work out, but I feel it's a better shot.
- mrtranscendence 5y agoWell, Apple isn't directly making money from selling subscriptions to the iCloud Keychain, but it's a fairly important factor in making iOS and macOS straightforward to use for many people (including me). So the indirect business case for keeping it around and performing well is pretty sound.
- thomascgalvin 5y agoThe older (and busier) I get, the more I'm willing to put up with a walled garden that just works. Apple is not (always) a good actor; they've been caught intentionally degrading the performance of older hardware, in order to increase sales of new hardware. But, they seem very keen on maintaining the privacy and safety of their users, which is true of essentially no other tech company on the planet. I'm still not all-in on the Apple ecosystem, but stuff like this always makes me pause.
- bborud 5y agoSo a company that requires users to trust them decides to be sneaky and untrustworthy. I just got a strong incentive to check out the competition.
- staticassertion 5y agoI just exported all of my passwords using only the extension.
- gruez 5y agoThe reddit post specifically mentions this >- Only making the export function available via the desktop browser plugin, despite locking peoples accounts to either Desktop or Mobile after 3 switches between these platforms.
- staticassertion 5y agoOh, I misunderstood that statement. The browser extension works perfectly fine on my computer, which is not what I would call a "desktop browser plugin", especially for software that at one point actually did have a desktop browser plugin but, afaik, does not anymore.
- iratewizard 5y agoI'm glad I can point to things like this after years of telling people to drop logmein jr
- londons_explore 5y agoAll it takes is for someone to write a little chrome extension to export everything and import it into competing software...
- tablespoon 5y ago> All it takes is for someone to write a little chrome extension to export everything and import it into competing software... Though it would be foolish to trust such an extension, given the existence of practices like extension hijacking. I'm sure someone could make a lot of money with a "secretly export LastPass passwords to attacker" extension.
- yoav 5y agoThis is exactly why I switched to another password manager when they announced LogMeIn had bought them. Same gross tactics and lock in. IIRC LogMeIn refused to let me delete my credit card details or cancel my plan and their “support contact” was completely unresponsive. Can’t remember if I just used fake card details or blocked the transaction by locking/cancelling the credit card but it was a real nightmare.
- kabdib 5y agoI had ten years prepaid premium on LastPass, being an early adopter (it was a good product and a good price at the time). After they were acquired, LogMeIn was quite happy to charge my credit card for the premium service, for several years running. Never did get a refund.
- johnmarcus 5y agoLastPass has become garbage since it was purchased by LogMeIn (or whatever parent garbage company owns them these days). I can't comprehend why anyone would use them. I can only personally recommend Bitwarden instead - it's open source and can never decrypt your passwords on prem. Browser plugin, mobile app, enterprise versions, etc. It has it all, and hasn't been a cunt to it's users from day 1. Also, unlike LastPass, they haven't been hacked multiple times. I can not comprehend why anyone trusts them with their passwords - the company I work for included I'm afraid.
- zucked 5y agoThis is going to turn into a thread full of recommendations for PW managers before long, so here's my plug for Bitwarden.
- khimaros 5y agoi especially recommend vaultwarden, the community developed self hosted backed.
- ravar 5y agoI use pass. The provided password manager in linux. passmenu provides a great workflow for inputting the passwords.
- encryptluks2 5y agoI really like how pass saves passwords as a gpg file, so when you sync with a cloud provider you can see specifically what passwords are being synced. When you store everything as a single database file, not only does sync not show you differences, but you have to resync the entire DB file each time you change something.
- gspr 5y agoPass, the piece of software that, per line of code it possesses, has improved my digital life more than any other. A true gem!
- bentcorner 5y agoI use Keepass + Onedrive sync (Windows + Android). It's been working well for many many years and I see no reason to switch. If I had to recommend a pw manager to someone I'd probably suggest they just save them in-browser, and use the same browser (Chrome/FF/Edge) across all their devices. Chrome has a pretty good password suggestion feature. Other browsers are probably not far behind.
- at-fates-hands 5y agoCame here to say the same thing. Been using Keepass for years without any issue and won't switch. I started it using quite a while ago after someone on here recommended it and haven't looked back since.
- turblety 5y ago> If this is true, they are in major violation of Article 20 of the GDPR. I honestly have no idea how the GDPR got implemented. A true policy that actually benefits the citizens of Europe, in a world where most policies are to screw over everyone but the rich.
- zucked 5y agoHere's a hint: non-compliance is basically a finger wag, perhaps a slap on the wrist in the most extreme case.
- lixtra 5y agoLook at the examples yourself, to form an opinion: https://www.enforcementtracker.com/ https://www.enforcementtracker.com/
- lb1lf 5y ago-Well, Amazon got a €750M ($850M) slap on their wrist, which while not sufficient to put them out of business surely must have hurt someone's feelings (not to mention their bonuses...)
- efitz 5y agoWhen LastPass was acquired a few years back, I saw the writing on the wall and changed to 1Password. Thank goodness I dodged this bullet.
- TAForObvReasons 5y ago1Password is another proprietary SaaS password manager. You "dodged this bullet" but shouldn't you also be concerned that 1P will do the same thing in the future?
- mplewis 5y ago> When LastPass was acquired Maybe, if someone acquires 1Password?
- InGoodFaith 5y agoThe company vision can change even without acquisition. Having an open source and self-hsotable alternative (that also has a SaaS equivalent if you so choose) seems to be the more prudent choice.
- Xylakant 5y ago1password explicitly say what happens if your subscription lapses; your account will be frozen and placed in a read only state: https://support.1password.com/frozen-account/ https://support.1password.com/frozen-account/ Now, the question is “why would I trust this?” to which I answer: I trust them to safeguard my passwords.
- Qub3d 5y ago> Now, the question is “why would I trust this?” to which I answer: I trust them to safeguard my passwords. Isn't that tautological? I trust 1Password more than LastPass simply because you _must_ pay for it. Freemium upsells are a dark pattern, and the temptation to monetize data on free users is much greater than paid.
- pleonasticity 5y agoI just tried exporting my LastPass database without any issue.
- hcurtiss 5y agoI recently exported to Microsoft Authenticator/Edge without any trouble at all.
- AlexandrB 5y agoNeither a bug nor an intentional ploy would surprise me. When I last used LastPass (2018) the web UI was quite buggy and difficult to use. Since then they have been acquired[1] by a PE firm and are about to be spun off again[2] as an independent company. Heaven knows who's steering the ship over there. [1] https://www.ghacks.net/2019/12/18/logmein-lastpass-to-be-acquired-by-private-equity-firms/ https://www.ghacks.net/2019/12/18/logmein-lastpass-to-be-acq... [2] https://www.theverge.com/2021/12/14/22833319/lastpass-independent-company-logmein https://www.theverge.com/2021/12/14/22833319/lastpass-indepe...
- lini 5y agoI had issues exporting my LastPass database to a CSV file a couple of weeks ago from a browser (no plugin installed). They seemed to render the CSV data inside a <pre> tag in an HTML page (I have no CSV browser plugin installed). I had to copy the text manually from the HTML source and paste/import it in another password manager.
- tiku 5y agoI was removed from a team account, after that I could no longer access my account until the company reinstated me temporarily. Very weird behavior because it was a private account first..
- alar44 5y agoIf you used the same email account I think that's expected behavior.
- futhey 5y agoConfirmed working 10:46am PST: Sign in to LastPass web -> Advanced Options -> Export -> Verify export by email -> Advanced Options -> Export (again) -> List of passwords in CSV format.
- deleted 5y ago[deleted]
- jmrm 5y agoHave you checked this thing I commented? Just to know if it's just a personal problem or it is global: https://news.ycombinator.com/item?id=29896882 https://news.ycombinator.com/item?id=29896882
- jonathanlb 5y agoI wasn't able to reproduce the error. I got a CSV that seems complete.
- withinrafael 5y agoSame, cannot reproduce. CSV export was easy and appears to be error-free. <shrug!>
- dadjoker 5y agoSame here. I pay for LastPass, and I was able to export w/o a problem.
- tytso 5y agoThe problem is if you aren't a paying customer, and you are locked to the mobile app, it doesn't have the password CSV option. So if you can access the desktop web option, sure, it works. But that's not true for all users.
- bborud 5y agoConfirmed broken. CSV file contained barely a dozen entries. Real list is hundreds. I guess Bitwarden secured itself a test-run. edit: for clarity, the downloaded csv was defective, the csv shown seems complete. This is a problem
- bostik 5y agoI can say with full confidence that this at least has nothing to do with their hostage situation: > Having no formal support channel When I last had to deal with their so-called support, all contact details were very efficiently hidden. Once you found a page with a phone number, and the hours you could call them, there was one final surprise: "The phone number you are trying to reach is not in use". The only contact that works reliably at LastPass is their billing department. Make of that what you will.
- techdragon 5y agoWhile it was harder than it should have been to reach them. The one support interaction I’ve ever needed to have with them (domain name change went badly with master password email account re-verification before I added a secondary email) was amazing. They had a thorough security checking, identification confirmation process that would make it more difficult for social engineering, they were able to fix up the email over the course of a 45 minute phone call (I did mention it was thorough)
- SV_BubbleTime 5y agoYou guys did better than me, I gave up trying to find a phone number and used their ticket system… it was not good. Issue was eventually resolved but wow, what a mess.
- Reubachi 5y agoAh, the Jagex method.
- deleted 5y ago[deleted]
- hffftz 5y agoI usually use this website to find companies' phone numbers: https://gethuman.com/phone-number/LastPass https://gethuman.com/phone-number/LastPass It tells you that it is a credit monitoring service when you call, but it is indeed the password manager service.... 800-830-6680 and then press 3 (the other 2 options disconnect you)
- acheron 5y agoThe export works fine, I just did it about a week ago. Lies, on Reddit? Shocked pikachu face.
- rodmena 5y agoI don't understand why people should use LastPass while there is this robust multiplatform and totally free "BitWarden" is available. Marketing power.
- jscohn85 5y agoHere is my reason, at least: https://community.bitwarden.com/t/custom-fields-and-automatic-fields-parsing-save-all-entered-data/12730 https://community.bitwarden.com/t/custom-fields-and-automati...
- Qub3d 5y agoThey have added custom fields at some point, because my AWS is autofilling the account ID with one: https://i.imgur.com/Ark4XH9.png https://i.imgur.com/Ark4XH9.png
- misnome 5y agoI switched to BitWarden when they dropped the subscription requirement for mobile, continued charging for my subscription for over a year and then announced they’d start charging again. It’s… fine, but many areas of integration with browser and on iOS are significantly less polished and pleasant to use. Things like credit cards are entirely manual on iOS. It’s definitely a worse experience on the convenience side. That, and even though it’s relatively easy to migrate, it’s even easier to not spend the effort reworking your workflows and ways you use password tools.
- camtarn 5y ago> it’s even easier to not spend the effort reworking your workflows and ways you use password tools. Yeah, this. I've been using LastPass since 2012 - four years before BitWarden even existed. BitWarden actually looks excellent and I'm tempted to switch, but the easiest thing is just to not do anything.
- barreira 5y agoAlthough I understand your point from a psychological point of view, in my experience switching from LP to BW was an easy task.You can create a temporary CSV to export your Lastpass vault and import it in Bitwarden. It takes 2 minutes maybe. The rest is just switching which app you use to fetch your passwords. Although that was prior to the shenanigans this post's article talks about.
- gilbetron 5y agoAs a LastPass user, I'm getting a bit nervous. I've looked through various other threads on suggestions, but, since it is inevitable - what do people recommend and why? I'd prefer only answers from people that have been using their solution for at least a couple of years, and even better, people that have been using theirs for even longer and through multiple iterations of "weird things happened to password manager X" cycles :)
- riffic 5y agobitwarden seems to be the favorite so far - open source, self-hostable if needed, and pretty easy to use. There's a free reimplementation of its server which also seems to be highly recommended: https://github.com/dani-garcia/vaultwarden https://github.com/dani-garcia/vaultwarden
- impalallama 5y agoSecond Bitwarden, I moved from Lastpass to it last year and the process was painless. iOS and Browser support were at a parity that I just uninstalled one installed the other and was ready to go.
- mattwad 5y agoBeen using bitwarden and love it! I don't think it offers 2-factor but you can replace that with Authy or Google Authenticator
- karmanyaahm 5y agoIt does have 2-factor in the paid plan.
- lstmemery 5y agoI'd like to recommend Aegis Authenticator, which is FOSS. It also encrypts tokens at rest, has password protection and the ability to export tokens. Lastpass Authenticator does not do that, so I spent an hour yesterday manually resetting all my 2FA.
- 5y ago
- riffic 5y agoThis company is so rotten. Just look at their recent track record showing pure user hostility. Why is anyone still using them?
- foxtrottbravo 5y agoProbably because they make it hard enough to leave so that the majority of end-users just swallow the pill
- tablespoon 5y ago> This company is so rotten. Just look at their recent track record showing pure user hostility. Why is anyone still using them? Inertia. Lastpass still works, and frankly it's not high on my list of priorities to research and switch to a new password manager. Some people have time to obsess over this stuff, I don't anymore. And frankly, data export barriers wouldn't be a difficulty for me (I wouldn't mind re-keying stuff if that's what it took, and that's what I did to get my passwords into LastPass). Deciding on a direction is way more work, and that's the real barrier. Also, it's kind of pointless. The alternatives will almost certainty be some open source thing with major UX friction and personal maintenance burden, or some for-profit service that will eventually be corrupted in exactly the same way as LastPass has.
- andybak 5y ago> Just look at their recent track record showing pure user hostility. Why is anyone still using them? Because I've managed to miss any news damning enough to make me decide to switch. It's possible that either: a) I've overlooked something b) You and I have different priorities c) You're being hyperbolic. I genuinely don't know which but your phrasing and tone makes me lean towards (c) The internet is full of people shouting "God. [Company] is the worst!" - if you want to be persuasive then it's probably better to not sound like them.
- riffic 5y agoYou can lean towards C all you want and I admit my phrasing and tone will come across a certain way, but the track record isn't hard to dig up if you just take a cursory look. Let me give you this own site's experiences with the company. https://www.google.com/search?q=lastpass+site:news.ycombinator.com https://www.google.com/search?q=lastpass+site:news.ycombinat...
- JackMcMack 5y agoRoot cause of this issue: export is only possible from the desktop browser plugin, but lastpass locks free users to either desktop or mobile. If your account is locked to mobile, you can't export your passwords. I have another related issue: it is not possible to export your TOTP seeds from lastpass authenticator. I contacted the lastpass/logmein dpo, which (in my case at least) got forwarded to their generic support-by-email. They were slow to respond, and eventually claimed they could not export my one time passwords because they are encrypted. This is obviously false, they can decrypt the data just fine (I actually switched to a new phone, authenticator data got synced as you would expect). And other apps such as Google Authenticator allow you to export your data. I filed a gdpr complaint with my national Data Protection Authority, which after a long response time got accepted, and is now forwarded to the Irish DPA. If you want to assert your rights, contact Lastpass/Logmein at privacy@logmein.com or via their support page [0] (from their privacy page [1]), and demand access to your data. If they refuse, or do not respond within 30 days, file a complaint with your DPA [2], with proof that you requested your data but got denied. [0] https://support.logmeininc.com/contactus https://support.logmeininc.com/contactus [1] https://www.logmein.com/nl/legal/privacy/international#rights https://www.logmein.com/nl/legal/privacy/international#right... [2] https://edpb.europa.eu/about-edpb/about-edpb/members_en https://edpb.europa.eu/about-edpb/about-edpb/members_en
- LordBadminton 5y agoThe complaint page for the UK's national data protection authority, ICO: https://ico.org.uk/make-a-complaint/your-personal-information-concerns/ https://ico.org.uk/make-a-complaint/your-personal-informatio... The contact page for the California Privacy Protection Agency: https://cppa.ca.gov/about_us/contact.html https://cppa.ca.gov/about_us/contact.html The contact info for the national data protection authorities in the EU, Iceland, Liechtenstein, and Norway is linked at [2] in the comment above.
- wiether 5y agoWhen they were acquired by LogMeIn a few years ago, the thread on HN about it was recommending switching to Bitwarden. Which I did. In a few weeks, I'll have to pay $10 to renew it. Meanwhile, since December we have those kind of worrying news from LastPass which is almost 4 times more expensive than Bitwarden.
- laurent92 5y agoThe only thing important about a password manager is the amount of the bug bounty. In economic theory, it should be higher than the assets you protect with the password manager.
- SV_BubbleTime 5y agoI wanted to use BW. Even had a talk with their lead engineer and CEO about switching my company over. Seems like a good product but at least two years ago their commercial offering was abysmal, basically no way to run a managed system with user accounts for their personal things and work entires that I could control or deploy. Lastpass Enterprise has issues, but it does allow the above.
- mkdirp 5y ago> basically no way to run a managed system with user accounts for their personal things and work entires that I could control or deploy. Could you elaborate on this? I'm not an enterprise user, however, as a happy commercial Bitwarden user, I was annoyed that the company I worked for moved to LastPass relatively recently. I'd love to know what may have made them choose LP over Bitwarden.
- Macha 5y agoLastpass lets you (possibly with a large enough enterprise account?) give free personal accounts to your employees, seperate to their business accounts, that the employees can link with the business accounts. This gives the employees a single interface to access their business and personal passwords, while giving the company a business account it can see stats (but not passwords) of, and terminate to cut off access to without locking a user out of their personal passwords (the personal account gets downgraded to a free account). Personally I don't use that as I have bitwarden set up for my personal accounts and would rather trust that.
- stelonix 5y agoI don't know, maybe I'm old-fashioned, but I never used and never will use a password manager. I can't think of a reason to let a business know all my passwords while also making it my single point of failure.
- Handytinge 5y agoIt sounds like a cloud hosted password manager isn't a good choice for you. However not all password managers are cut from the same cloth. There are many offline/locally encrypted options.
- tomjakubowski 5y agoHow do you manage your credentials then? Before using a password manager, the best thing I could manage was variations on a similar password. But sites with arcane password requirements tend to break this. I was _really_ disappointed when 1password dropped support for Dropbox sync and pushed everyone onto their storage. I'm uncomfortable, like you, with the truly single point of failure this way: I would much rather diffuse the storage and master credentials to separate parties.
- stelonix 5y agoI do like you said, small variations. Things get difficult once there are bizarre requirements, but then I just login by "forgot my password". Another commenter replied (s)he has over 400 credentials; I don't think I have even 100 let alone 400 logins.
- wintermutestwin 5y ago>I don't think I have even 100 let alone 400 logins. And the real question is: how many of these logins require max level of security?
- dahart 5y agoWhy is that the real question? The advantage of a password manager is you can default to max security with no more effort than poor security. Many of my accounts have changed over time, it’s not uncommon to add payment to a trial account, or for personal information to accumulate. There are plenty of good reasons to always use maximum security in order to lower your risk and prevent future accidents.
- jmrm 5y agoWatch out! Another "bug" of the LastPass happens when you export your accounts. I have exported all my accounts via the web interface, and the three times I've done that it export a truncated CSV file with about 30 lines, while printing the whole file content in the web page you access. That means the CSV you downloaded probably is not complete and you have to copy some lines from the web. I was lucky to investigate a weird warning, about some missing fields in the last row, that SQLite gave me after importing all the accounts to a database.
- jrockway 5y agoI did this a few months ago and didn't run into that problem. I basically did a "make before break" migration. I kept LastPass available for several months after importing the database into 1Password, while using 1Password day to day. I never needed to refer to LastPass, so I finally unsubscribed and deleted my account. I have read some others on HN describe stories where it didn't go so well. Private Notes not exported (I saw this on HN before I cancelled, but mine all came over), incomplete exports (I got everything), etc. But yeah... do be careful and give yourself a grace period.
- zerof1l 5y agoThat's why I never used LastPass and never will. KeePass ftw!
- anm89 5y agoSo happy I jumped shipped to a different password manager and got away from this dumpster fire
- OptionX 5y agoGlad I dropped them as soon as they made the change to limit the number of connected clients behind a paywall. Changed to bitwarden. Same functionality (at least for my uses) free and with the option of you spinning up your own server for your personal use (versus the cloud option).
- Havoc 5y agoOne more to add: Not only do they limit switching between phone and desktop, if you request desktop site on a phone you get a css render salad. Got mine exported during the recent scare without too much pain. But yeah - going to move away from Lastpass. Everything about them seems to be going sour fast
- komadori 5y agoThe problem I had with LastPass is that if you have any billing problem then you're immediately kicked down with to the free tier with all the problems that entails, including loss of access to regular support. Worse, they had a bug that prevented me upgrading back to premium with new payment details. The special contact form for billing support was non-obvious and they were not especially prompt or helpful. I've since migrated to BitWarden. No problem exporting, thank goodness, but it wouldn't have suprised me!
- dahart 5y ago> If this is true, they are in major violation of Article 20 of the GDPR. Is this reasonable, or trying to whip up resentment based on speculation? It partly feels questionable because the author is a US resident, and the company is a US company - of course that’s no reason not to discuss/comply with GDPR - but paired with the lack of specifics and the explicit speculation with words like “appears” and “likely knowingly” that have no accompanying proof, it feels like more hit piece than valid legal concerns. There may be real, valid, and large reasons to have resentments here, I have no opinion on that. But LastPass doesn’t necessarily “have” everyone’s passwords, because many are encrypted and LastPass can’t decrypt them. Does article 20 really apply to data encrypted such that the company has no access? That seems unlikely. Article 20 might require that LastPass export someone’s user profile and credit card information, but it was not designed as way for people to demand UI features they want or force companies to offer service for free, right?
- the8472 5y agoIf they're storing the encrypted data on your behalf then they should be able to provide that, plus instructions how to decrypt it.
- dahart 5y agoSure, but are they truly compelled by EU law to do this for people in the EU, to export encrypted data? GDPR applies to PII, and encrypted data the company can’t access is not personally identifiable information, and the company doesn’t necessarily “have” the unecrypted data. It seems like Article 20 does not automatically apply here. (This all aside from the question of whether GDPR applies to Americans using American services.)
- SavantIdiot 5y agoI've been paying for one license of LastPass to use on multiple computers and phones since 2012. Never any problems. What the heck are y'all doing with it that makes it so unreliable for you? The only problem I have is that my iPhone 7 doesn't always detect my USB-C UbiKey NFC, but I think that's a UbiKey or iPhone problem.
- 4ec0755f5522 5y agoI use Firefox / Safari built-in password management. I do not know how secure they are but no issues in 10+ years and I certainly have access to all passwords in my keychain/account. Not locked behind some corporate service. They are saved locally. Both easily generate long random passwords, etc. For me this is a solved problem (until Firefox's service is hacked, of course) to the point that my real pain point is remembering the random strings I use for "security question" answers. For that I use a KeepPass database. But I wish FF/Safari would see the need and add security questions fields to their management. No way am I giving real information for those. Why yes my mother's maiden name is cd559b1085b94b2dad32bb9e458e2422 so sorry to hear it was leaked, SONY. https://en.wikipedia.org/wiki/2011_PlayStation_Network_outage https://en.wikipedia.org/wiki/2011_PlayStation_Network_outag...
- qvrjuec 5y agoI use a password manager(Bitwarden) to: 1. avoid vendor lockin (if I want to switch browsers I can, or switch from iOS to Android) 2. enable portability, with passwords not just being available locally requiring manual migration to other devices Do you have problems/qualms with the above just using browser password managers?
- daveidol 5y agoIsn't this difficult to manage passwords in apps other than a browser though? Plus, I use 1Password to store other sensitive data like SSN etc.
- bwat48 5y agonot really, on desktop I can just go to firefox menu | passwords and search/view/copy any of my saved passwords on android, firefox can autofill passwords in any app
- alfiedotwtf 5y agovi ~/.passwords.txt ... problem solved
- pmlnr 5y agoKeepassxc + syncthing. Password managers are too important to rely on someone else's computer.
- u2077 5y agoAny subscription based password manager is holding your passwords hostage. Not sure why this is news.
- jarbus 5y agoSo glad I switched to pass years ago
- deleted 5y ago[deleted]
- AndrewHayes 5y agoI was just able to export mine. As some have said the web export gave a truncated set. However the chrome browser plugin export function worked just fine and gave me a full export from two separate accounts. This included one account that was seemingly locked in the web browser because I had cancelled my subscription and was locked into a re-subscribe page with no other options to proceed that I could figure out. Just painlessly (finally) deduplicated my pwds in excel and imported to a bitwarden family plan. It's been so painless. The features I'm seeing make me fairly certain I'll be paying for a family org plan.
- meta-level 5y agoMaybe they should just change their name to LostPass and everything's fine again