3 ms·
As somebody that has been using lastpass for many years and continues to do so… I just do not understand how people who pick weak master passwords complain abou
by peter422 3y ago
As somebody that has been using lastpass for many years and continues to do so… I just do not understand how people who pick weak master passwords complain about this.
The lastpass documentation makes clear over and over that your entire DB can be compromised but as long as they don’t have the master password, you are safe. How people do not think one step past this and realize they need a very secure master password is beyond me.
And yes I know there will be a host of comments telling me they are in the password business so they need better something and guides and whatever, fine. But for anybody with the slightest bit of common sense, lastpass was and still is secure and lived up to their promise.
- daydream 3y agoWhy do you still use lastpass?
- kstrauser 3y agoYou’re right to a point, but there’s a world of difference in ways you can store a password. If their algorithm were a single round of MD5, it’s going to be a lot easier for an attacker to guess a password than if they were using Argon2. I don’t think LastPass is using MD5, but my point is that their job is to make any master password harder to guess. They’re not doing it.
- michaelmrose 3y agoYou are overestimating the technical ability of users by orders of magnitude. Even people who are nominally "experts" in one technical area at least adjacent to computing who are completely useless outside of the most basic thing. Running a business or a project implies dealing with people as they actually are not as we might hope they could be.