Time for my periodic ad for LastPass
In reference to my posting from a few minutes ago, it seems like a good time to put in another plug for my password tool of choice.

The truth is, if the LinkedIn crack had happened a few years ago, I would have been in non-trivial trouble: turns out that my password (now changed, of course) was one that I'd used at a lot of sites. It was consciously my "yeah, whatever" low-security password that I was using for sites that I didn't think were terribly important -- but some of those sites have become more important to me over time.

But the nice thing about LastPass is the way it has changed my habits. It doesn't just keep all of my passwords in a nicely secure locker (hidden behind one mnemonic-to-me but *really* hard to guess password); it also integrates so well with my browsers that it's really easy to *always* use secure passwords. When confronted by a new site, it offers to generate a reasonably high-security random password, and then creates a new record to keep track of that password afterwards.

The result, yes, is that I don't actually *know* most of my passwords. But I don't need to, so long as I have either *some* kind of Internet access, or a machine that has my password locker and LastPass loaded onto it -- which is very nearly all the time. And it means that no two sites have the same password, so even if one site is compromised, the rest of my online identity is still decently safe.

This is an unpaid plug: my only connection to LastPass is as a customer who wants to see the company safe and secure, because they are providing me with an invaluable service. And frankly, at only $12/year for the "premium" service, I consider it well worthwhile to subscribe at that level, even though the free basic service provides most of the important features. IMO it's one of the best bangs for the buck that you can find on the Internet today, and I encourage you to check it out...

do you knwo how it works iwith iDevices?

Don't know. Support for Android is still so-so, although improving: they got clever a little while ago, and wrote a "keyboard driver" that hooks into LastPass, so you can select that to fill in passwords. Still a tad clunky, but better than nothing...

so basically for my iDevices i would have to look up the password and paste it in everytime?

Might be. LastPass does what they can to integrate deeply with browsers (it works great on the desktop), but mobile OSes tend to make this Very Very Difficult. In the case of Android, they're stuck with hacks and workarounds -- better than nothing, but certainly not as good as the desktop experience. Don't know whether iOS provides enough hooks to let it work better...

the reason i ask is that i rarely anymore use a desctop for anythign at all...

@TPau: I just took a quick look, and they have a "made for iPad" version. Haven't tried it out.

I use multiple browsers. It appears I would have to have a separate copy of LastPass for *each* browser as well as each computer. @jducoer, does this match your experience?

Somewhat. They have a pretty unified installer, that tries to install the appropriate bits into each browser that you have on your machine (at least on Windows), and anecdotally there seems to be at least *some* unified login. But I've occasionally had some flakiness when swapping between browsers heavily, so no guarantees there.

That said, I do use it on this work machine, with Chrome, IE and Firefox, and all work well. And they *have* a number of fine-grained installers for those who want more control. But the Windows Universal Installer is usually the right answer for this OS. (I don't see a comparable Universal installer for Mac, though.)

And oh, my -- I just came across LastPass for Applications, which is almost disturbingly powerful. It allows you to instrument Windows desktop apps the same way that LP normally instruments web pages. Interesting...

But mind -- I'm speculating here. I don't have any iOS devices, so I plain and simply don't know what they've managed to do on that side of the fence...

On iOS you can either use their browser, which integrates the functionality, or you can use their javascript bookmarklets which work in any modern browser, and work just fine in mobile safari.

-Happy user for many years.

Thanks for the recommendation - I am appalled to see how many passwords I was re-using. Now: to do the tedious work of fixing that for 70+ sites ... :(

