[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: lastpass



 > From: Flora <http://www..family/~flora>
 > Date: Sun, 17 Jun 2018 15:41:30 -0400
 >
 > There are advantages and disadvantages to having the passwords on your
 > physical hardware.

The obvious disadvantage is that if someone breaks into your place and
steals your computer, you are potentially screwed.

OTOH, at least you'll know that you have been potentially compromised, and
can laboriously change all your passwords, whereas if your info is stolen
in the ether of cyberspace, you may never know whether you've been
compromised or not.

 > I can access my passwords no matter which device I'm on
 > with LastPass.

That is nice.  But, again, with convenience comes potential
vulnerabilities.

As a back-up, I usually set it up so that I can access my hardware
remotely.  But, it's highly inconvenient and tricky, so I don't depend
upon it.

 > Yes, LastPass has a password generator. I use another random
 > password generator, though - web-based.

How do you do that?

 > I do keep all my software up to
 > date.
 > 
 > I don't use LastPass for my bank. Instead, I have a cyber token, an
 > external hardware device for my 2-Factor Authentication.

You do have a special circumstance, and a special bank (right?).

 > No matter which method you use for your password, I highly recommend
 > multi-factor authentication, especially for your bank, your email, any
 > investments, and any retirement accounts that you may have. Also, never
 > have the same password for any of your accounts.

I would add that you should never use the same email address, either, but
that is much more difficult.  Gmail is fairly convenient:

 https://gmail.googleblog.com/2008/03/2-hidden-ways-to-get-more-from-your.html

 > A password manager will
 > help with this.
 > 
 > Both of these will help keep your accounts more secure - multi-factor and
 > not having the same password for different accounts.
 > 
 > Incidentally, Steve Gibson uses LastPass.

LastPass is pretty secure, but, again, I don't like depending upon or
using cloud services.




Why do you want this page removed?