Also lastpass has a history of security issues: https://en.wikipedia.org/wiki/LastPass#Security_issues
If you want to use a password manager, you should use something like pass[1].
Also lastpass has a history of security issues: https://en.wikipedia.org/wiki/LastPass#Security_issues
If you want to use a password manager, you should use something like pass[1].
- What LastPass gets is ciphertext, not your unencrypted
passwords. Important detail.
- There are opportunities for LastPass to receive your
master password (i.e. if you enter it on their website).
I haven't audited LastPass. After Tavis Ormandy looked at it earlier this year and published his findings, I wouldn't be surprised if the crypto was totally and hopelessly broken.But to eschew the fact that their app does encrypt passwords before sending them to their servers isn't fair.
You have to put a lot of faith in them and the question why would you always remains.
The thing here is motive and incentive, LastPass has not motive or incentive to handle your passwords in an unencrypted form, it has no motive or incentive to want to know your master password ever since both of those things are just a huge liability for them.
Every password manager, every browser, every OS, every hardware can be backdoored and compromised by their maintainer/manufacturer in a way nearly impossible to detect even in some cases if the source code is fully or partially available, heck how many people ever verify that the package they just grabbed via the package manager was built using an unaltered version of the source code?
To function you need to have some level of trust, you can try to add additional security measures e.g. like not storing highly sensitive passwords in a password manager but even then really depending on how you maintain those passwords you are likely to increase your risk rather than reduce it.
The only other option is to use something like this to-do it yourself.
github.com/ezWebDevTools/ezCryptoJS
Native apps, on the other hand, tend to have signed updates and such. I'd pick a native password manager over a web-based one any day, but the theoretical risk is still there.
Credentials being "remotely stored" would be the case regardless of if you run any other viable storage such as Dropbox. I suppose you can remotely store on your own server, but I'm about a million times more likely to screw up than even a bad cloud company or password manager - so that's a non starter.
I'm sure there are alternatives to LastPass/1pass and similar, but storing encrypted passwords in a local file solves only a small part of the problem.
What people need is centralized & turnkey password management. This has drawbacks , but remember: it competes on security with the only other alternative: using the same password for all sites - That's the most common password management system out there!
To Set this up i need for every new device around... 10 minutes
It isn't THAT hard. Im pretty sure there is a dropbox(or $urCloudProvider) App that Can sync your files too :-)
It's not as straightforward as you assume,now apply it to non-devs.
https://fossdroid.com/a/openkeychain.html https://fossdroid.com/a/password-store.html
When it comes to ease of setup and general UX polish every open solution leaves a lot to be desired. In the choice between insecure and cumbersome, insecure wins every time. Case in point: gmail is what people want in terms of usability. A more secure solution (such as any pgp solution on standalone mail client) is not really an option.