• Tangent5280@lemmy.world
      link
      fedilink
      English
      arrow-up
      32
      ·
      10 months ago

      I feel like atleast one of these has been hacked at some point in the past, but I cant remember which.

      • hperrin@lemmy.world
        link
        fedilink
        English
        arrow-up
        55
        arrow-down
        6
        ·
        10 months ago

        It was LastPass, but the passwords themselves weren’t leaked. All of these encrypt the password.

        • Passerby6497@lemmy.world
          link
          fedilink
          English
          arrow-up
          22
          ·
          10 months ago

          the passwords themselves weren’t leaked

          You’re not wrong, but you kinda are. The plaintext passwords weren’t released, but the encrypted blobs were stolen. Unfortunately, the LastPass defaults were absolutely shit so people have been able to selectively attack the blobs and decrypt the vaults, leading to millions in crypto being stolen.

          I was a long time supporter of LastPass, but they haven’t been responsible stewards of sensitive information. The fact that they failed to encourage or force existing customers to update the encryption settings as they updated their defaults is negligent and is disqualifying in my opinion.

        • Z4rK@lemmy.world
          link
          fedilink
          English
          arrow-up
          19
          ·
          10 months ago

          There is no excuse for LastPass and it absolutely should not be treated with your passwords or secrets.

          • shaggy959500@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            ·
            10 months ago

            Security Now is amazing. For anyone that wants the deep dive tech perspective, plus what it means for everyday people and users, this is a great option.

        • Tangent5280@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          10 months ago

          Ah, alright, thanks. Thats a good thing then, that you cant get to the passwords even if you hack the company.

      • boatswain@infosec.pub
        link
        fedilink
        English
        arrow-up
        18
        ·
        10 months ago

        KeePass doesn’t store your stuff in the cloud; it’s all local storage. You can sync your encrypted KeePass DB in a number of different ways; personally, I go for SyncThing, but you can use Box or whatever.

    • fmstrat@lemmy.nowsci.com
      link
      fedilink
      English
      arrow-up
      21
      ·
      edit-2
      10 months ago

      Based on experiences helping people migrate away, I’d suggest removing LastPass from your list. See other replies for why.

      Note: For those that care, not only is BitWarden FOSS, it can also be self hosted easily using VaultWarden.

      • hperrin@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        10 months ago

        I added a note. I personally use Bitwarden and would recommend it, but I didn’t want to give a biased recommendation. If, for whatever reason, one of the others works better for someone, just using an encrypted password manager is way better than not.

        • fmstrat@lemmy.nowsci.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          10 months ago

          Oh I feel you. I did a ton of research on toilet paper (of all things) and made a recco and my post was deleted as an “ad”, hah

      • Ghoelian@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        3
        ·
        10 months ago

        Only issue I have with 1Password is their Android app. It works great most of the time, except that they didn’t implement the Android autofill stuff correctly.

        It sees Firefox as a browser and offers autofill suggestions for the websites just fine, but apparently Fennec isn’t on their allowed browser list or something. It just sees Fennec as another android app and doesn’t offer logins for the website I’m on, just ones that I’ve linked to the Fennec app.