5 ms·
Even the LastPass will be stolen, deal with it (2015) [pdf]
- PainfullyNormal 4y agoThis tweet[0] from about a month ago is pretty interesting. "If you ever wanted to dump someone's entire LastPass vault, this is where you start :D" The author was referring to the linked presentation slides. [0]: https://twitter.com/_MG_/status/1600980559009677313 https://twitter.com/_MG_/status/1600980559009677313
- threads2 4y agomemes really age terribly, dont they
- PainfullyNormal 4y agoWhat are you talking about?
- cassianoleal 4y agoDoes anyone know how other password managers compare? 1password, Bitwarden, etc. Edit: to clarify, I'm asking specifically about client-side security of these products - NOT feature or UI/UX comparisons.
- Caboose8685 4y agoI moved from lastpass to bitwarden about 2 years ago, then to self hosting vaultwarden about 6 months ago. Bitwarden wasn't as feature-full as lastpass at the time, but I liked it a lot. My father was using lastpass in the meantime and I saw it devolve into an unpleasant mess UX wise and these days, ignoring the elephant of the hack, am confident bitwarden is a much better experience overall compared to lastpass.
- cassianoleal 4y agoI have moved away from LastPass as soon as they were bought by LogMeIn. It was already a UX shitshow and it only got worse. I now mostly use 1Password but I also host a VaultWarden instance. I haven't yet moved to it fully because even though 1P is also devolving and I don't like having my passwords db on a 3rd party server, I still find BW's clients clunky especially the browser integration. My question was specifically about the kinds of issues in the OP though. I poked around my Firefox profiles and haven't found much but I don't really know what I'm looking for.
- judge2020 4y agoFor me, 1password continues to work and improve on its features in a good way with biometric unlock support (Windows Hello, iOS/MacOS biometric unlock) and the SSH Agent is nice, so I use it and was paying the yearly subscription for it before my work started to give me a license for free. While it's my choice, I can see why most don't like 1password 8's subscription-only and cloud-only model (you effectively have to use 1password.com, can't store your vault on dropbox gdrive etc).
- cassianoleal 4y agoCheers, I'm also currently on 1P and it's fine. Although I'm not nearly as positive about their improvements as you, it's still a fine product from the user's pov. My question is related to the OP though, I'm not looking for UX/UI or feature comparisons.
- kmfrk 4y agoPeople have been dunking on LastPass for a very long time. I haven't seen the same infosec people do the same with 1Password and Bitwarden. The constant criticism was a bit push to finally get me to move to 1P. The one good thing about LastPass was basically how easy it was to set up. Everything else was a bit of a mess. 1Password was tricky to set up, and they took a bit longer to launch a cloud service. One thing that bothers me about 1Password is that they only let you set up one security key, which is very impractical for people like me. OTOH, this is not unusual, and I assume part of it is to keep bad actors from adding more security keys to your account or something like that. Still not great when you can lose access to everything if you lose your key.
- cassianoleal 4y ago> People have been dunking on LastPass for a very long time. I haven't seen the same infosec people do the same with 1Password and Bitwarden. This is my impression as well. What I wonder is whether this is because they haven't tried to find these issues with the other products, or they just failed to find them so nothing ever got published, or if it did no one noticed it. I find the latter hard to believe as I suspect marketing departments would have been all over it. That said, to me LastPass was always terrible. Back in the day I moved from KeePass to LP for the browser integration but everything was so buggy and unreliable that eventually I moved away. 1Password was better but the cloud service brings some of the same worries as LastPass.
- deleted 4y ago[deleted]
- dark-star 4y agoI still use KeePass, albeit with a ridiculously high iteration count to protect against brute-forcing. It's completely client-side, so no cloud involved and nobody to blame other than you if your vault gets into the wrong hands ;-) Although personally, I use OneDrive to sync it across devices
- cassianoleal 4y agoYeah, that's what I used to do as well - although I used Dropbox and later iCloud for syncing. Browser integration, less than great iOS clients and other quality-of-life features eventually made me find an alternative. I might look into it again.
- hprotagonist 4y agokeepassium for ios is good now.
- cassianoleal 4y agoThanks, I'll check it out.
- InCityDreams 4y agoKeepass, and manual copying to my pfhone along with the keyfile. 100% security on me, myself and I.
- phphphphp 4y agoLastPass is a standout candidate for worst password manager, as has been the case for many years. The other popular password managers, like 1Password and Bitwarden, are certainly not perfect but they're leagues ahead of LastPass. 1Password, for example, has written extensively about their security model and have done so proactively, including a lengthy whitepaper: https://1passwordstatic.com/files/security/1password-white-paper.pdf https://1passwordstatic.com/files/security/1password-white-p... LastPass is garbage because it's LastPass, not because it's a password manager. The only thing LastPass has ever done well is somehow remain relevant despite being terrible: that's an achievement.
- softskunk 4y agoi’d just like to say thank you for linking to that white paper. really a fascinating read, and nicely written. i’m a long-time 1password user and absolutely love it. sure, it involves placing some degree of trust with AgileBits, but for the incredible level of practicality it offers, i view it as a decent trade-off. reading that paper now also makes me a great deal more confident in their security standards.
- Stevvo 4y agoGoogle/Chrome is probably the most secure password manager. They have the greatest incentives to keep it secure along with the largest bug bounties and number of people attacking it.
- cassianoleal 4y agoThanks but I stay away from Google products in general and especially don't install any software written by them on my computers (with the exception of the gcp CLI).
- amarshall 4y agoVideo of the actual talk: https://www.youtube.com/watch?v=MlmEiT5bhxg https://www.youtube.com/watch?v=MlmEiT5bhxg Aside: I never really understood distributing just slides from a talk. Any good talk most of the information isn’t in the slides.
- michaelhoffman 4y agoThere are a lot of talks that aren't good. (Not in any way saying this is one of them.)