LastPass Now Checks If Your Sites Are Affected by Heartbleed
blog.lastpass.com
blog.lastpass.com
(I can think of a few process and fee reasons this approach might be picked. Perhaps a CA might offer a free new cert and revocation, if and only if the new cert has the same validity range as the one it replaces. An ops team might prefer one consistent time of year for the ceremony of non-emergency certificate rotation.)
I didn't notice any field in the cert-viewers of Firefox or Chrome that could reliably tell the true issue-date of a new certificate.
Is LastPass just looking at the start of the validity, or does it have some way to know if the certificate is truly new?
We wish we had all site's certificate fingerprints from before this started so we could utilize that data -- if anyone has it, an email to securit@lastpass.com would be greatly appreciated.
For example, here's the Perspectives report on lastpass.com showing the brand-new key as well as the old ones: http://i.imgur.com/hJkFTAy.png
I am far from an expert in this so perhaps I
I notice herokuapp.com's CA is DigiCert, so perhaps they have the opposite policy, of giving the reissued cert the same start date as the revoked cert.
I don't think there's a standard field in an X.509 cert for issue date.
It's possible to download a CA's CRL and look for revoked certs, but all you get are serial numbers and revocation dates, not subject names.
[1] - news.netcraft.com/archives/2014/04/08/half-a-million-widely-trusted-websites-vulnerable-to-heartbleed-bug.html
Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
Things like their security check are just icing on the cake.
I use LastPass Premium
You could store your passwords in a git repo to get a sort cross-platform thing going on.
It works on EVERY platform because gpg is available for EVERY platform and it's just a bunch of files in a hierarchy, so however your sync files, you sync these.
It has as strong a master encryption as your gpg key and git is a great way of versioning your passwords: "wait, I used to have the same password for gmail and yahoo mail, but then I stopped using yahoo mail and changed my gmail password to something really secure, but now I need to get into yahoo for some reason (yes, literati, I still love you). git log --grep accounts.google.com".
We also have an extension into Dolphin, and you can utilize Chrome utilizing our fill method -- if you don't like them there are options to disable them too reducing the perceived extra bulk.
Call me old fashioned, but I'd rather copy/paste than rely on the web browser within the app. The lack of attention for the desktop Firefox extension is what drove me to alternatives. After switching away, I realized I was paying for a payed proprietary system with no real benefits from an open source solution.
We're happy you found a tool that works for you -- that's what we want everyone to do -- it doesn't need to be LastPass but people need to use something -- reusing passwords constantly is just painful.
I can see an argument about cross-platform use but is there another reason or reasons?
thanks,
I suspect that the password manager in most browsers have received less attention than it deserves, partly because all the vendors been trying very hard to get people to drop passwords altogether. Mozilla pushed Persona, Google pushed Google accounts, Microsoft pushed Microsoft accounts. I wonder if Mozilla will start paying attention to the password manager now that it has given up on Persona.
LastPass et al. have a lot of additional features that make a lot of sense once you accept that you'll be stuck with dozens of passwords for the foreseeable future. For example, LastPass offers to generate a random password for each site, recognizes when you change your password, helps you organize websites into categories, and alerts you to weak passwords.
TL;DR Firefox with a strong master password was considered safe at the time of that article's writing (June 2013). That + Firefox Sync is what I use - I would also be interested in anything more up to date on why this is or isn't a good idea.
It is, however, the browser’s job to protect your passwords against other websites and the like, and I would be worried if there were bugs in that area, but your link doesn’t say anything about them (note also that using a password manager with an extension for protection against someone taking over the browser is useless, as that someone also owns the extension and hence can impersonate it towards the seperate password manager).
I'd still recommend it, despite those problems.
Lastpass overall is comfy, you do everything within your browser, it sync without much problems and you can use it on the go with the official applications and addons. One downside is that everything is closed source. The other one is that I find their addon is trying to do too much, and it's not polished enough (at least, their Firefox one). I've had tons of annoyances with it.
Keepass instead is awesome because it's opensource and you own your data. But you can feel that not everything is nicely integrated. I use a Firefox addon (PassIFox) for filling username/password, and it works pretty nicely, but you have to set it up (and it's kinda a pain to get it working on Linux). I use an application on Android (Keepass2Android) which has a different UX, and doesn't have the fancy input method that the lastpass app has (instead you just copy/paste, and there is a keyboard for autofilling but I find it mostly annoying). The integrated sync support only ftp/webdav, and not everyone has a server providing those around (and I never got webdav to work anyway). Sure, you can sync the file with dropbox or other "cloud" solutions, but this implies even more software in your chain.
I never got to try OnePass sadly, as there's no Linux version.
Anyway, I'd say: Try both, and see which one you prefer. Keepass is libre, and lastpass has a free tier, so you don't have to put any money in it. Just use them for a bunch of sites for a bunch of days, and then decide.
There are KeePass addons for (from memory) SCP, SFTP, and FTPS (does anyone still really use FTP?), as well as others.
1) Dropbox
2) USB stick
All that aside though, I certainly can't see any logical argument for the statement "Free software is a prerequisite for digital security." It could be argued that open source software is such a prerequisite (although I wouldn't necessarily agree), but if anything I expect that paying for software would ultimately tend to make it more secure.
Besides, it lacks applicability in this case. LP encrypts all your stuff client side before sending it along for storage, and the browser plugins that handle this are open source by way of being browser plugins. Whatever happens server side after that is mostly irrelevant.
For critical stuff, I want to minimize the amount of proprietary stuff. I already have Windows (as a VM host), Lenovo and VMware to trust - but at least that's not directly connected to the Internet[1]. Why add a third party that could suffer a remote compromise or worse?
1: Host runs VMs, has no protocols bound to NIC but passes it through to a gateway VM which acts as a router for the other VMs. KeePass can run on the host, so a VM compromise is somewhat limited.
It's still in alpha but will be released on all major platforms once its ready.
Disclaimer: I'm the developer
LastPass if sync/mobility is most important and you're fine trusting a (US?) company.
There's probably a reason this is a bad idea. Let's hear it! :)
Plus, if any changes are to be made to the authentication process it should be migrating to two-factor auth across all services.
I've thought it would be nice to consolidate 2-factor authentication methods in a single service, then require a single, 2nd factor authenticator for access to the service or vault. So a yubi-key like authenticator with your lastpass that then authenticates using 2-factor protocols of some sort automatically; again, trading security for convenience, but would also allow for things like auto-changing of all passwords (which happening more often couldn't hurt security) while still under protection of a 2-factor authentication.
I take this to mean that I'm giving LastPass's web server my actual master password, and that they will do server-side decryption of my Vault and have server-side access to my passwords in cleartext.
Is that accurate?
[1] https://lastpass.com/index.php?securitychallenge=1&lang=en-U...
So while you can't look at the code running on their servers, it seems to me that you certainly can know they don't have access to your vault.
Thanks guys!
I think you're wrong:
Unauthorised access to computer material.
(1)A person is guilty of an offence if— (a)he causes a computer to perform any function with intent to secure access to any program or data held in any computer [F1, or to enable any such access to be secured]F1 ; (b)the access he intends to secure [F2, or to enable to be secured,]F2 is unauthorised; and
Lastpass is not trying to secure the web wervers with the check