Hacker News new | ask | show | jobs
by eccbits 3032 days ago
Laspass is massively insecure in all aspects of its design & history - including many facepalm-worthy breaches... It's terrible.
3 comments

As someone who uses the service, could you go into detail? Please do consider this a sincere query to your claim, I would like to know more
Wikipedia has a good overview of their (known) security lapses. Two server breaches, one known to have exfiltrated sensitive information. Several browser plugin vulnerabilities, one of which allowed arbitrary plaintext passwords to be stolen.

https://en.m.wikipedia.org/wiki/LastPass#2011_security_breac...

LastPass’s history is troubling but they’re also the biggest target out there. IMO, the entire space of “cloud” password managers is inherently untrustworthy.

Nothing like a bit of hyperbole in the morning.
Off topic, but what makes you say LastPass is insecure, provided of course that you follow common sense rules like strong master password + 2FA?