Am I the only one who thinks it's crazy to put all of your passwords on a companies cloud where every single one of their other customers password vaults also lives?
Aside from putting the burden for file management of the vault on the customer, help me understand how local storage (with backups) isn't the safest place to keep my passwords from being compromised.
Ghost/spam traffic is a real problem for GA. UA codes are public and can be targeted with spam referrals or simply randomly hit (especially for UA codes that end in -1).
Filtering spam and getting useful data on GA is a never ending job that Google keeps making harder. (re removal of Service Provider / Network Domain [1])
Are those fees also present for transactions that are refunded immediately before they batch (i.e. testing). Let's say a stripe IP wasn't whitelisted on the server and started being denied coming back, causing transactions to fail. If I want to do a quick live environment test on this it now costs my client money, which is not ideal.
>the reality is that it's no different than using 1Password with sync enabled.
Except that a users LastPass vault lives in the "cloud" so that a compromise of that password can likely open the door and makes it a more enticing target to begin with. Compared the likely hood of merely getting at the 1password vault (assuming it's not synced to the cloud) being a significant barrier.
Again, for me this discussion is educational, I'm curious how having this data in the cloud could ever be considered more secure than local storage.
Thanks for the link to the 1password compromise, although, I stand by my point, that compromise is due to extraneous features as opposed to the core functionality. Being conservative myself, that's not a feature I use.
I see 1password's main vulnerability being that someone could gaining access to a device and vault passcode or obtaining that passcode through a keylogger.
I'm not sure how difficult it would be to brute force into 1Password locally but either way it's a low benefit game compared to the potential access with a compromise to a cloud based scenario like LastPass.
This isn't the first time that LastPass has had security issues and it seems like a fools game to use a password manager that keeps you data in the cloud.