Hacker News new | past | comments | ask | show | jobs | submit login

If you're not going to use 1Password, which is still the only commercial password manager I'll recommend, "pass" is probably your best alternative.



As a LastPass user, any particular reasons why I should avoid them? Is it down to all the security issues they've faced lately?


Neither are deal breakers for me, but I get issues with their plugins sometimes.

The deal breaker for me before vs 1PW was that I would store quite a bit of info in 1PW for some logins. Filling out a whole sign up form might include birthday security question/answer, name, and more. For various reasons, I don't always use real info so having this info automatically saved or easily added as new fields is great. I know Lastpass has a few extra field options and a notes section within each login, but the fields aren't enough and I don't want to have to manually add all the info into the notes like some people I know do. I'd rather pay a few dollars more a month and get the convenience and time saved.

I'm sure it makes up for the extra ~$25 a year. And the family plan at $60 a year for up to 5 family members isn't a bad deal in my opinion either if that can work for you. I know it sucks compared to buying the apps one time, but I don't feel it is as bad the outcry was/still is.

I guess I'm looking at this strictly in terms of what is best for my day to day life. It's not worth it worrying about a few extra dollars a month when I only have a handful of subscriptions as it is.


1Password is the only commercial password manager I recommend, but I'll go further than that when it comes to LastPass and say: I really think you should avoid LastPass, and, if you're using it, migrate to something else.

I'm not going to go into details, sorry.


Why do the trouble of replying but fail to explain your reasons? That's wasting your own time mostly.

I would recommend 1password over lastpass as well. First reason being the security issues of lastpass chrome extension. Though claimed it is fixed now they have claimed before on other issues only to be proven wrong after. I simply don't trust them anymore with my data.

But even more I would choose 1password over its usability. I used lastpass before but switched during the past few security issues reported. I have never looked back. 1Password is much better integrated in your mobile devices. The app feels more robust and is easier to operate. In addition the whole process of setting up your devices felt easier and more secure using 1password.

Second. My wife understands it which is a big plus. She doesn't complain anymore about the cumbersome lastpass. We keep a shared vault as well. That alone is worth every penny and maybe the only reason I keep with a commercial password manager. I don't think she will use the alternatives.

I would strongly advice you to at least try it. It claims to be able to import your lastpass though personally I didn't try as my lastpass was a bit of a mess.


I understand why it makes people uncomfortable to know that they're not getting all the information I could possibly convey in a comment.

I don't see how that would make it better for me to not comment at all.


Because an advice without argument is ignored (in many cases). If it were me I would have rephrased my comment to include a summary. That would be sufficient to understand why you said things and in addition would be perceived less cocky. Now it came over as I'm saying this and you are not worth my time explaining the arguments.

Apparently you have knowledge on the subject so a sentence or five would have helped everybody reading this thread. In fact, it is what I would expect from an HN comment. I usually read the comments before the article as on HN there is often more information than the actual article. Most often different sides of the coin are in enlightened in the comments bringing insight in the otherwise one-sided monologue in the article.


I understand why you don't want to go digging up information to link, especially if using a phone. In this case, I think sharing a little truth about LastPass may benefit our community.

https://www.google.com/amp/s/arstechnica.com/security/2017/0...



If it's too much for a content, how about a link to a source that articulates your point? I'm sure many people would appreciate more complete information.


I suspect the reluctance to offer more than a brief recommendation isn't a lack of confidence in the argument, but rather a sensible level of restraint for someone who is in the security industry.


LastPass is the only commercial password manager I recommend. I really think you should avoid 1Password.

I'm not going to go into details, sorry.



You do much work in this field?


It doesn't matter whether he does or not. He's using your own argument against you. Stepping in here and saying, "don't worry guys I'm the expert, so don't ask any questions", is just pompous and doesn't actually convince anybody. Use logic to support your claims, not your resume.


No, sorry.


It's funny. When I was the GP comment I thought "well that's not a very useful comment". Now that I've paid attention to who the author is... I'm getting concerned about LastPass :)


Are you able to say why you aren't willing to go in to details? I respect your CV and am going to switch to 1Password from LastPass based on your comment, but I'm curious whether I need to be concerned about my information being compromised.


Well, shit, two conflicting comments. Which advice do I take? Quite the quandary.


Is your recommendation of 1Password contingent on any particular set up (like only using a "local vault" and not their cloud solution)?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: