Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've only ever used Apple's iCloud Keychain [0]. It has always worked great, and seems to have good security in order to enable; it asks for the local login password that you signed onto one of your other devices with, but it feels scarily easy to see ALL your passwords in plaintext with just a single Face ID authentication.

I'd be more comfortable with bio-authenticating per password (though that might use more battery) and preferably asking for the password/code if you look up more than 5 passwords too quickly, but I'd rather have to trust a big company than a smaller third-party that gets acquired and sold around.

What are the advantages of LastPass and other password managers over iCloud Keychain?

[0] https://support.apple.com/en-ae/HT204085



I too was a happy user of iCloud keychain for many years. Except one day, I made a new password on my Mac, but even after a few hours it hadn't sync'd to my iPhone.

I followed some instructions and toggled iCloud keychain sync on my iPhone (just turned it off and on) and it proceeded to erase about 250 of my 300 saved passwords. Wasn't able to get to my other devices fast enough to turn off the networking - they had all already been deleted from my Mac, iPad, etc as well.

Spent an entire weekend resetting passwords - never again. I am now a happy Bitwarden user. Even if it eats all my passwords one day, at least it's trivial to export them all to CSV.


>preferably asking for the password/code if you look up more than 5 passwords too quickly

Great, so rather than being able to access all your passwords, the attacker can only access your two personal email, company sso (including email), and two bank accounts. The rest can be obtained with password resets.


LastPass is cross platform. I use an iPhone, a Windows 10 desktop, and a linux laptop. How do you access iCloud Keychain on non-apple devices?


I slack them to myself, of course


If only there would be a browser extension for anything other than safari on OS X. Manually copying passwords (and then saving in chrome) gets real annoying


Can't check now, but I thought Chrome did integrate with the system Keychain.


I don't use Keychain to manage most of my passwords (because I have Windows devices), but when I click a password field, the space above the keyboard says "Passwords". If I click on that, it lets me choose between LastPass or Keychain.


I use keychain for convenience, but I also don’t enable touchID or faceID for this very reason. Too easy for someone to gain access to all of your credentials. With touchID, anytime you’re unconscious, anyone can get access to all of your stuff.

KeepassX works well as the actual database of credentials.


What is your threat model where someone has access to you while you are unconscious who also wants your web passwords?


I don’t understand the question. I don’t want anyone to be able to get access to my credentials while I’m unconscious or incapacitated, so I don’t use touchID or faceID.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: