- 5,318
- 2,402
I feel better and better about my hardcopy notebook. 
Oh no, a cloud-based password manager is using the cloud: why weren't we told? Good job we are safe on forums like PhysicsForums, no cloud-based nonsense here. Connecting computers together and storing stuff on them is all very well, but it would be stupid to allow anyone to access any of it.harborsparrow said:This tells me off the bat that they are using the cloud, which frankly I find horrifying.
You mean the one in your desk drawer where you probably didn't write out the whole pw anyway? Like this?phyzguy said:I feel better and better about my hardcopy notebook.![]()
Exactly! That's exactly what I do. Even if someone somehow got the notebook(unlikely), they would still need to decipher the missing characters that I don't write down.DaveE said:You mean the one in your desk drawer where you probably didn't write out the whole pw anyway? Like this?
Apparently, my lack of confidence wasn't misplaced.vela said:Perhaps it's unfair of me, but it doesn't inspire confidence in the security of their code.
Ouch. I've been a satisfied LastPass customer for several years. But after reading that blog post, I'm going to switch.vela said:It looks like LastPass can definitely be crossed off the candidate list of the best and most secure password managers.
Very well. I have been using Bitwarden for quite some time after LastPass limited free users to either the PC or phone. I bought the paid version of Bitwarden last month, and the primary reason was that it was OSS, and then it was fa cheaper compared to others.vela said:Apparently, my lack of confidence wasn't misplaced.
Jeremi Gosney summarizing the situation with LastPass
It looks like LastPass can definitely be crossed off the candidate list of the best and most secure password managers.
Why?vela said:It looks like LastPass can definitely be crossed off the candidate list of the best and most secure password managers.
I'm not suggesting avoiding password managers in general, just LastPass as the company has repeatedly made poor choices. Use a password manager from a company or project that takes security seriously.Vanadium 50 said:Password Managers might make you 10x or 50x as secure. It's in my view a mistake to avoid them because 10 is not infinity.
Many online shopping carts don't actually store your credit card details to help them defeat hackers - the average website is not as secure as your bank's system. They transfer you to a much more secure credit card processing company which complies with all the local laws on security and that's where you enter the card details. These are companies that work world wide with the big credit card suppliers and are trusted because their security gets checked regularly, and they can afford to invest money in keeping it secure.Vanadium 50 said:They are not trying to:
- Keep yout computers safe from attacks by major world governments
- Keep your credit card and similar information secure once the vendor has it.
I mostly agree with this, however when LastPass refers to something as my "vault" I did expect that it would be encrypted. The fact that the web sites I use, my email addresses as well as other personal information in notes was stored in plain text and may now be easily available to bad actors is unforgivable.Vanadium 50 said:I think it's worth backing up a step and asking what problem a password manager is trying to solve.
You certainly are, although it's not about how good they think they are, its about compliance with the PCI standards.DrJohn said:PS I think you might be more at risk of a vendor storing your card details if they are a BIG company, as they tend to think their systems are better than those of a small shop making only 10 to 50 online sales a week.
According to Gosney, much of the vault was unencrypted, so there is no need to crack the master password to access a lot of the information. This revelation is the one I found most surprising. Like others, I assumed the entire vault would be encrypted since that would have been the obvious design choice when storing a vault in the cloud.fluidistic said:the entire encrypted vault of people, meaning that if they could crack the master password, they would gain access to the personal info of people.
The assumption should be that a breach will happen allowing crackers to get a copy of the vault, and the goal should be to design the software so it is still prohibitively difficult for the crackers to access any information inside the vault. LastPass, the password manager, clearly doesn't meet this criterion. That's a problem with the LastPass software.Vanadium 50 said:Can the PWM company lose their customer data. Sure. Every company can, many have, and those that haven't just haven't yet. Many, likely most of these, have had an "inside man", so it's only a matter of time. That's certainly a problem, but it's not the PWM's problem. Maybe it's PWM Corps's problem, but so long as they don't keep your master password (I don't believe any of the major PWMs do) it's not a PWM problem.
This. And they are making it worse by not being transparent about what is and what is not encrypted in the so-called "vault", still only saying "stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data".vela said:According to Gosney, much of the vault was unencrypted, so there is no need to crack the master password to access a lot of the information. This revelation is the one I found most surprising. Like others, I assumed the entire vault would be encrypted since that would have been the obvious design choice when storing a vault in the cloud.
That would be an issue for many people. I, for instance, would like my passwords accessible from any device and from anywhere. Updating at one place should show the updated version everywhere without me taking the hassle to copy again.MikeeMiracle said:It's an offline program
Then you could place the encrypted vault in dropbox or google drive, or something similar. This way, you recreate a LastPass-like password manager, except that it is more secure (lmao), and even if bad actors get their hands on your vault, you know they won't get any information from it.Vanadium 50 said:I'm not sure a purely local solution is ideal. I need passwords on my Windows systems, my Linux systems and in some cases my phone. Having strong passwords for some accounts and 'qwerty' for the rest is not a good idea.
I think of computer security as a resistor network. Increasing it always helps, but once most of the current is diverted to another branch, increasing it further helps only a little. I also view it like a steering wheel immobilizer on your car - if it convinces the bad actor to overlook me and bother someone else, it's done its job.
This opens up another line of attack - steal the encrypted file and then attempt to decrypt it at your leisure.fluidistic said:Then you could place the encrypted vault in dropbox
Then I missed your point. How do you do a synchronization between your Linux and Windows password vaults, if it isn't local? Do you have something in mind like a self hosted Bitwarden software, or something else?Vanadium 50 said:This opens up another line of attack - steal the encrypted file and then attempt to decrypt it at your leisure.
Vanadium 50 said:Additionally, while I have privacy concerns about how LastPass does things. If I ret a brute force decryption and get gobledygook, I don't know if this is password gobledygoo or non-password gobledygoo. (I can try it, but that takes times and alerts people that an attack is in progress). But if I try a password and it gives me Quicken, Amazon, Chase and Porn-U-Copia (nobody else likes this name? Really?) I am pretty sure I have unlocked the vault.
So whil;e I don't like the design choice they made, its unfair to say there is no reason to do it this wau.
It's not an either-or. It's both a security issue and a privacy issue.Vanadium 50 said:I think the "vault is unencrypted" story is not really coming at it from the right direction. This isn't a security issue, it's a privacy issue.
Wrichik Basu said:That would be an issue for many people. I, for instance, would like my passwords accessible from any device and from anywhere. Updating at one place should show the updated version everywhere without me taking the hassle to copy again.
An alternative is to use open-source password managers like Bitwarden. LastPass is closed-source, so no one can confidently know what it is doing, but for open-source software, there is the advantage that security researchers are able to audit the code and find deficiencies.MikeeMiracle said:That come's down to how security conscious you are and how much you can trust online sources.
My impression of many "experts" is that they tend to overestimate the risk of sharing a vault over the cloud. So they'll tell you in one breath how to generate a strong password that will take billions of years of computing power on average to crack, and in another breath, imply that if a cracker gets that encrypted info, they'll break it in a matter of minutes.MikeeMiracle said:That come's down to how security conscious you are and how much you can trust online sources.
LastPass did employ this policy for the encrypted information, what they call "sensitive data." The marketing wasn't incorrect in that sense, but it was misleading as most users reasonably assumed that meant all of their data was encrypted.MikeeMiracle said:I had a similar debate about password manager previously on this forum and introduced the concept of zero knowledge policies and was assured that LastPass employed this policy and that a local solution was not required. It would seem whoever made that assertion was incorrect. I am not blaming them for being wrong, they fell for the marketing of LastPass which turned out to be incorrect and why I avoid any "big names" when it comes to storing things online.
I don't see it as a real advantage because practically speaking, no one ever comprehensively audits the project's code voluntarily because it's a lot of work and requires expertise. Companies and projects can, however, hire security experts to audit their code.Wrichik Basu said:An alternative is to use open-source password managers like Bitwarden. LastPass is closed-source, so no one can confidently know what it is doing, but for open-source software, there is the advantage that security researchers are able to audit the code and find deficiencies.