Also I use 1Password at work and find it a bit doddery compared to LP, which is no speed daemon itself.
All in all, it does take (much) more than 30 minutes.
Any shortcuts used by extensions based on the WebExtensions API are changeable. If you're on Firefox, press Ctrl+Shift+A (or go to about:addons), open the gear menu, and click "Manage Extension Shortcuts".
It’s certainly not perfect, but I’m not quite sure these issues are consistent enough to be indicative of BitWarden’s quality. I mean if its lost your passwords I would assume that’s something worth making an issue about on their GitHub?
I had to modify the native CSV with some vim magic to add a line delimiter for each record so it allowed for spanning over multiple lines in order to successfully import each entry - which also required the importer to allow for an additional EOR marker.
Even then there wasn't a 1:1 column match between pw apps.
Without this step though all sorts of hell breaks loose, and if you don't notice the columns got out of sync during import because a note had a few commas in it what good is it to you really. It's a hell of a mess that you may not notice until its too late.
There should also be a verify feature for any import that can query the original source via some API calls - or use that to do the import. Of course nobody is going to provide that because it means users can leave their ecosystem too easily - but the other thinking is customized backups to a PGP destination suitable for direct import via the sale API calls.
This was for LP to KeePass BTW.
Do we know that considering how they handle iframes and how lax they seem about it?
That's because you don't have or don't know about all those custom fields that don't get exported by LastPass, which turns real migration from 30min to many hours
Also it'd be wise to change passwords during the migration as well given all the hacks, which is another set of hours
I would argue if password updates are required because of LP's insecurity, that's really not a migration issue, that's just a LP issue.
* Use a different name for each account * Use different "personal information" (date of birth, etc.) for every account * Track "security" questions and randomly-generated answers for each account, for services that still use that terrible approach * Track which phone number is associated with each account, for services that uses SMS MFA codes * Attach list of one-time recovery codes to accounts that use those * Attach source of credential information when credentials were sent by someone else for e.g. testing
There's six reasons off the top of my head. I'm sure there are more.
Custom ones are usually all banking sites. One does not use standard field names so bitwarden does not detect it. Another has an extra field for user . (Bank customer company id, password then particular user's name).
If you're still using LP, and haven't been bitten by this, do it now. Do the migration.
Once the migration is done, start rotating passwords as soon as you can.
I have over 300 passwords, multiple cards. Multiple notes. All synced flawlessly.
We know they do, since they got their backups stolen not even a year ago lol.
And why would you even trust a cloud based product. If I can't see the hosted source code storing the password then I'm not trusting it regardless.
How is this possible? I must have at least 50 passwords I use with some regularity and many more I use once a year or so. All my passwords are at least 16 characters long and totally random. Are you able to remember that without compromises like repeat passwords or patterns used for generating them (including website name in password or similar)?
https://www.eff.org/deeplinks/2016/07/new-wordlists-random-p...
This generator uses a different wordlist with about 18000 words.
https://1password.com/password-generator
Using a quick back-of-the-napkin calculation, you get roughly this amount of entropy from 1password's wordlist when compared to random alphanumeric strings [a-zA-Z0-9]:
- 5 words ≈ 12 chars
- 6 words ≈ 14 chars
- 7 words ≈ 17 chars
- 8 words = 19 chars
If we take 5 words as the minimum you'd want to use on a web service: - halvers persia dutiful manes party
- append medalist society duke disobey
- acoustic halo assuage upkeep dexter
- area theist motile align trespass
As a non-native English speaker (which should be obvious from my strained speech), I'd say it's rememberable enough.Anyone else reading this: do not just remember your passwords. Unless you’re Lord Nikon, if you can remember more than a handful of passwords, it’s because they’re weak enough to be memorable. Or worse, used in more than one place!
Use a password manager. Always. For everything.
Nor are my passwords weak. Okay; seeing as one of my passwords expired lately.
U0ptz#^7--9
You zero pee tee zee hash up-thinggy 7 dash dash nine
Another:
L0@!tF..9w&
Lel zero at metal-gear-solid-noise tee follow dot dot nine walks and
I find that stuff very easy to remember. I just make a fantasy story based on the password.
L9d£5"s
Little 9 ducks cost 5 said sir.
HNr!##@t
Hacker News really can suck balls at times.
> And why would you even trust a cloud based product.
1Password's security model sounds pretty reasonable to me. The convenience of having my Passwords backup and synced to my devices is worth the tradeoff in security in my case.
I've got close to 1500 stored passwords. How does one even start to remember those?