Gentoo Archives: gentoo-user

From: Dale <rdalek1967@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: [OT] Seamonkey and LastPass
Date: Sat, 28 Nov 2009 22:04:16
Message-Id: 4B119E39.3090105@gmail.com
In Reply to: Re: [gentoo-user] Re: [OT] Seamonkey and LastPass by Alan McKinnon
1 chrome://messenger/locale/messengercompose/composeMsgs.properties:
2 > On Saturday 28 November 2009 05:50:42 »Q« wrote:
3 >
4 >> On Sat, 28 Nov 2009 00:57:54 +0200
5 >> Alan McKinnon<alan.mckinnon@×××××.com> wrote:
6 >>
7 >> [about LastPass]
8 >>
9 >>
10 >>> What I find incredible is that people will accept the site's say-so
11 >>> that the site admins can't read the data. They have not proven
12 >>> anything, merely asserted something.
13 >>>
14 >>> The only way to do give that guarantee is to encrypt the data. Which
15 >>> then needs a key. Someone must keep the key and it's either you or
16 >>> them. If it's them, they can decrypt the data (same reason as DRM is
17 >>> doomed to failure) and if it's you - well if you lose the key you
18 >>> lose the data.
19 >>>
20 >>> Are you telling me that there are people gullible enough to actaully
21 >>> fall for that one?
22 >>>
23 >> They claim that the decrypted data never leaves your computer and they
24 >> they don't have a key to it. Many, many things aren't clear, such as
25 >> what kind of encryption is used (same as the US gov't uses for "Top
26 >> Secret" stuff, they say, heh), where and how the key is stored on your
27 >> machine, on and on. I wouldn't dream of using them, but yeah, they have
28 >> a substantial number of users.
29 >>
30 > I have an alarm system in my head. It's called the "Security by bullshit
31 > baffles brains Alert". It's ringing right now ;-)
32 >
33 > Mind you, I have vendors who use exactly the same throw-around-bullshit-
34 > statements-and-see-what-sticks approach. It works on the Account Managers all
35 > the time, and works on us techies none of them time.
36 >
37 > Lucky for us, techies rule around here. We get to tell the Account Managers
38 > that the vendor is talking crap, that we don't have to explain why, that we
39 > are not buying their crap and we are not using it, so please tell the vendor
40 > to leave the building and stop wasting my time :-)
41 >
42 >
43
44 And to think I came here to ask others opinion BEFORE doing this. I was
45 curious as to how this could work myself and if they can be trusted, or
46 SHOULD be trusted. Seems everyone thinks no one should.
47
48 That said, because of the way my bank and credit card site accepts the
49 login and password, I bet it wouldn't work for them anyway. If I wanted
50 a really long password that would be hard to guess, those two would be it.
51
52 Dale
53
54 :-) :-)

Replies

Subject Author
Re: [gentoo-user] Re: [OT] Seamonkey and LastPass Marcus Wanner <marcusw@×××.net>
Re: [gentoo-user] Re: [OT] Seamonkey and LastPass Stroller <stroller@××××××××××××××××××.uk>