Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy technology
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old February 3rd, 2013, 11:40 AM
TOMxEU's Avatar
TOMxEU TOMxEU is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: Slovakia
Posts: 1,535
Default Re: Browsers' password managers vs KeePass? (when auto-entering passwords)

Well it happened over years, that was one the reasons, why I picked Keepass over Laspass at that time. Security triangle applies (security - functionality - easy of use).
__________________
Real-Time: Nothing | On-Demand: Nothing [ Lenovo E525 | Yandex | CCleaner | KC SUMo | WiseCare 365 ] ( BlackViper / DEP / OpenDNS / UAC / WiFiRouter )
  #27  
Old February 5th, 2013, 06:58 AM
tlu's Avatar
tlu tlu is offline
Very Frequent Poster
 
Join Date: Sep 2004
Posts: 2,066
Default Re: Browsers' password managers vs KeePass? (when auto-entering passwords)

Quote:
Originally Posted by TOMxEU
Well it happened over years, that was one the reasons, why I picked Keepass over Laspass at that time. Security triangle applies (security - functionality - easy of use).

You still fail to provide any evidence for your claim. The only case I'm aware of happened in April/May 2011 and was explained in detail in this Lastpass blog post.

The most important point is: Since the Lastpass master password is not stored on their server but only on your computer (and encryption/decryption is only done on your computer), your data was not in danger unless you had a weak master password which was prone to a dictionary attack.

The other important point is that Lastpass introduced several crucial steps since then to improve their security like implementing PBKDF2, CSP etc.
  #28  
Old February 5th, 2013, 07:22 AM
happyyarou666's Avatar
happyyarou666 happyyarou666 is offline
Frequent Poster
 
Join Date: Jan 2012
Posts: 675
Default Re: Browsers' password managers vs KeePass? (when auto-entering passwords)

evidence ?, you dont need evidence just some common sense , password databases get hacked daily , sure files may be encrypted but still its sure as hell not worth it if you cant revover them, no offense , but it shouldnt even stand to debate , storing ones passwords locally vs online,

be it encrypted or not , sorry , thats unless you really dont have high risk passwords in use , then it doesnt matter if you store them online , sure its up to each individual how he handles his security ,once again , i sure as hell wouldnt use the cloud storage/online service model , sorry
  #29  
Old February 5th, 2013, 07:51 AM
tlu's Avatar
tlu tlu is offline
Very Frequent Poster
 
Join Date: Sep 2004
Posts: 2,066
Default Re: Browsers' password managers vs KeePass? (when auto-entering passwords)

Quote:
Originally Posted by happyyarou666
evidence ?, you dont need evidence just some common sense , password databases get hacked daily ,

I requested evidence for TOMxEU's specific claim that the "LastPass database has been hacked at least 3 times and accounts stolen".

Quote:
sure files may be encrypted but still its sure as hell not worth it if you cant revover them,

What are you talking about? If you were familiar with Lastpass, you would know that an encrypted copy of your data is also stored locally on your computer. Thus, if the Lastpass server is hacked or not accessible or Lastpass is even bankrupt you would still have access to your passwords.

Quote:
no offense , but it shouldnt even stand to debate , storing ones passwords locally vs online,

No offense, but it's rather obvious that you're not familiar with Lastpass.

Quote:
be it encrypted or not ,


Ah, I see, it doesn't make a difference to you if the data is encrypted (with AES-256 in the case of Lastpass) or if PBKDF2 is used.
  #30  
Old February 5th, 2013, 08:05 AM
happyyarou666's Avatar
happyyarou666 happyyarou666 is offline
Frequent Poster
 
Join Date: Jan 2012
Posts: 675
Default Re: Browsers' password managers vs KeePass? (when auto-entering passwords)

its been a while since ive used lastpass , so i might be a bit rusty , since last time ive used it it wasnt so, so an encrypted copy is stored on your pc , thats good to know ,and of course it makes a difference in that context if you use aes256 or pbkdf2 -.- , still gona stay with offline password databases instead thou, like keepass ,i dont trust companys with my passwords simple as that , encrypted or not , doesnt give me a good feeling, even when its "uncrackable" , wich you dont know , lastpass isnt opensource thus cant be reviewed, and have you checked if theres any backdoors lately , im certain you havent
 

Wilders Security Forums > Privacy Related Topics > privacy technology « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:05 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums