For anyone reading this, please use the official 1Password import functionality, not this: https://support.1password.com/import-lastpass/
For anyone reading this, please use the official 1Password import functionality, not this: https://support.1password.com/import-lastpass/
EDIT
I just revisited that link I shared, and I have to say, it takes some real chutzpah to turn around and accusing me of advising insecure practice when the link I shared literally talks about just that:
Due to the nature of this application, ๐๐ฒ ๐๐๐ฟ๐ผ๐ป๐ด๐น๐ ๐๐ฟ๐ด๐ฒ ๐ฒ๐๐ฒ๐ฟ๐๐ผ๐ป๐ฒ ๐๐ผ ๐ฑ๐ผ๐๐ป๐น๐ผ๐ฎ๐ฑ ๐๐ต๐ฒ ๐๐ผ๐๐ฟ๐ฐ๐ฒ ๐ฐ๐ผ๐ฑ๐ฒ, review it quickly, and compile it yourself to use this tool. However, we do recognize that this may be beyond the means of all security-minded folk out there looking to make the switch, so we are providing signed binaries available for download. If you do opt to use the binary download, make sure to validate the authenticode signature like so: ...
Pumping your passwords through some random code on Github that has a "be smart" label doesn't make it a good idea.
Would be so easy to imitate you, reupload the code with an exploit. For giggles, if I was making this into a hijack I'd leave all your warnings in and even make them bigger and more obvious, confident in the knowledge that 99%+ of my stolen users wouldn't read the code or would just download the binaries sight unseen.
That is such a salient point, generally.
2) Don't read the code.
3) ???
4) Forever don't know what or when it happened.
>Would be so easy to imitate you, reupload the code with an exploit.
Put your keyboard where your fingers are: do it by tomorrow morning and post here when you're done.
Now that you know there's an official LastPass importer for 1Password, I'm curious why you're defending your version rather than updating your blog post, unlinking your original HN comment and deprecating the GitHub repo.
I believe you're genuine and just trying to help. If there's an attack, it wouldn't be you doing it โ it'd be someone else replacing the binaries on an old 2017 post without you noticing. WordPress is just as insecure as phpBB. Like the other commenter said, "Just because you put a warning label on a bad practice doesn't mean it's a good practice."
The details were hazy, but in 2016, there was a way to export your passwords from LastPass and import them into 1Password, though I don't think there was a way to do so on windows (which I believe is what your importer addresses).
After LastPass vulnerability in July 2016, I switched to 1Password.
If I recall, I had to sign up for LastPass premium to pull my passwords to my phone, and then use keychain to import them to 1pass.
I don't think that solution would work for Windows users back in 2016.
As for OP, my take is you clicked a bad link triggering a zero day vulnerability in your browser, or perhaps you logged in on Lastpass via a VPN or Tor? Its pure speculation though.