Hacker News new | ask | show | jobs
by SubiculumCode 3095 days ago
That is a whole lot of opinion, but not much substance. What makes LastPass inferior to these other options?
2 comments

> What makes LastPass inferior to these other options?

Well, for one, the very first sentence of the article here.

The article whose "exploit" requires handing your unlocked phone to someone?
> (Edit #1, 7.30pm GMT): A lot of people are saying that this flaw requires physical access. However, as I pointed out above, you don’t need physical access, a maliciously installed application can easily access the activity and capture the code.)
So you don't need physical access you just need to install a malicious application? Okay then.

Why can one application even explore and access the views of another?

Accessibility APIs
You'd be surprised how many people (not on HN) use extremely weak (or no) unlocking mechanisms for their devices. It overlaps with the set of folks who would want to use LastPass because of how easy it is.
Do you know what is easier than using last pass for people who use weak unlocking mechanisms? Using the same password everywhere.

I'd be surprised if there was any overlap at all where you claim.

Well, I have several family members that fall in the "I use a pattern to unlock my phone or do not use anything to lock it, but store passwords in Last Pass" category. So I guess you're wrong.
And which just got revealed,and will probably be fixed.
The article that is literally not about Lastpass's password manager?

Lastpass Authenticator is not their password manager. It is a Google Authenticator competitor...

If they have a history of shitty security practices (this app), then why should we fully trust other apps they make?
You're going to double down on completely misreading the article and misquoting as to why their Password Manager is insecure? Come on...
None of which has anything to do with this thread, your claims, or your erroneous claim that the article was about their password manager. Keep doubling down...
Perhaps I could have clarified better, but I was speaking to the various nasty security issues they’ve had mainly.

I also find their apps to be ugly as sin, but that’s a personal preference.

When your rival is KeePass you don't really need to do much in terms of UI/UX