Bitcoin Forum
May 29, 2017, 04:14:11 AM *
News: If the forum does not load normally for you, please send me a traceroute.
 
   Home   Help Search Donate Login Register  
Pages: [1]
  Print  
Author Topic: Storing my seed in Lastpass  (Read 802 times)
NUFCrichard
Hero Member
*****
Offline Offline

Activity: 966


★Nitrogensports.eu★


View Profile
May 27, 2016, 12:12:14 PM
 #1

How do the Electrum pros here feel about storing the seed in Lastpass?

I haven't done it at the moment, but I do feel like storing bits of paper with seed codes on isn't a great long term strategy.


           █████████████████     ████████
          █████████████████     ████████
         █████████████████     ████████
        █████████████████     ████████
       ████████              ████████
      ████████              ████████
     ████████     ███████  ████████     ████████
    ████████     █████████████████     ████████
   ████████     █████████████████     ████████
  ████████     █████████████████     ████████
 ████████     █████████████████     ████████
████████     ████████  ███████     ████████
            ████████              ████████
           ████████              ████████
          ████████     █████████████████
         ████████     █████████████████
        ████████     █████████████████
       ████████     █████████████████
▄▄
██
██
██
██
██
██
██
██
██
██     
██
██
▬▬ THE LARGEST & MOST TRUSTED ▬▬
      BITCOIN SPORTSBOOK     
   ▄▄
██
██
██
██
██
██
██
██
██
██     
██
██
             ▄▄▄▄▀▀▀▀▄
     ▄▄▄▄▀▀▀▀        ▀▄▄▄▄          
▄▀▀▀▀                 █   ▀▀▀▀▀▀▀▄▄
█                    ▀▄          █
 █   ▀▌     ██▄        █          █              
 ▀▄        ▐████▄       █        █
  █        ███████▄     ▀▄       █
   █      ▐████▄█████████████████████▄
   ▀▄     ███████▀                  ▀██
    █      ▀█████    ▄▄        ▄▄    ██
     █       ▀███   ████      ████   ██
     ▀▄        ██    ▀▀        ▀▀    ██
      █        ██        ▄██▄        ██
       █       ██        ▀██▀        ██
       ▀▄      ██    ▄▄        ▄▄    ██
        █      ██   ████      ████   ██
         █▄▄▄▄▀██    ▀▀        ▀▀    ██
               ██▄                  ▄██
                ▀████████████████████▀




  CASINO  ●  DICE  ●  POKER  
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
   24 hour Customer Support   

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise here.
1496031251
Hero Member
*
Offline Offline

Posts: 1496031251

View Profile Personal Message (Offline)

Ignore
1496031251
Reply with quote  #2

1496031251
Report to moderator
defined
Sr. Member
****
Offline Offline

Activity: 448


View Profile
May 27, 2016, 12:15:18 PM
 #2

LastPass Password Manager is made to do this.
Do not forget to make backups and use a strong password.
NUFCrichard
Hero Member
*****
Offline Offline

Activity: 966


★Nitrogensports.eu★


View Profile
May 28, 2016, 08:23:10 AM
 #3

ok thanks, I don't like to keep all my eggs in one basket, so even though I trust lastpass, I wasn't sure about having my seed(s) on there.
I guess I will keep my hard copy stored away and investigate further if storing my seed in lastpass is 100% safe.


           █████████████████     ████████
          █████████████████     ████████
         █████████████████     ████████
        █████████████████     ████████
       ████████              ████████
      ████████              ████████
     ████████     ███████  ████████     ████████
    ████████     █████████████████     ████████
   ████████     █████████████████     ████████
  ████████     █████████████████     ████████
 ████████     █████████████████     ████████
████████     ████████  ███████     ████████
            ████████              ████████
           ████████              ████████
          ████████     █████████████████
         ████████     █████████████████
        ████████     █████████████████
       ████████     █████████████████
▄▄
██
██
██
██
██
██
██
██
██
██     
██
██
▬▬ THE LARGEST & MOST TRUSTED ▬▬
      BITCOIN SPORTSBOOK     
   ▄▄
██
██
██
██
██
██
██
██
██
██     
██
██
             ▄▄▄▄▀▀▀▀▄
     ▄▄▄▄▀▀▀▀        ▀▄▄▄▄          
▄▀▀▀▀                 █   ▀▀▀▀▀▀▀▄▄
█                    ▀▄          █
 █   ▀▌     ██▄        █          █              
 ▀▄        ▐████▄       █        █
  █        ███████▄     ▀▄       █
   █      ▐████▄█████████████████████▄
   ▀▄     ███████▀                  ▀██
    █      ▀█████    ▄▄        ▄▄    ██
     █       ▀███   ████      ████   ██
     ▀▄        ██    ▀▀        ▀▀    ██
      █        ██        ▄██▄        ██
       █       ██        ▀██▀        ██
       ▀▄      ██    ▄▄        ▄▄    ██
        █      ██   ████      ████   ██
         █▄▄▄▄▀██    ▀▀        ▀▀    ██
               ██▄                  ▄██
                ▀████████████████████▀




  CASINO  ●  DICE  ●  POKER  
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
   24 hour Customer Support   

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
OmegaStarScream
Hero Member
*****
Offline Offline

Activity: 938



View Profile
May 28, 2016, 11:40:56 AM
 #4

LastPass is an online password manager ,It's definitely not recommended to store your seed or anything related to your private keys there.
I'd suggest storing them on KeePass instead since it's an offline password manager and you have a portable database file .kdx which you can use it anywhere as long as you have your Master key.

PS : LastPass got hacked last year - https://www.coinprices.io/posts/a-guide-to-basic-password-security-the-danger-of-last-pass

NUFCrichard
Hero Member
*****
Offline Offline

Activity: 966


★Nitrogensports.eu★


View Profile
May 30, 2016, 12:00:30 PM
 #5

LastPass is an online password manager ,It's definitely not recommended to store your seed or anything related to your private keys there.
I'd suggest storing them on KeePass instead since it's an offline password manager and you have a portable database file .kdx which you can use it anywhere as long as you have your Master key.

PS : LastPass got hacked last year - https://www.coinprices.io/posts/a-guide-to-basic-password-security-the-danger-of-last-pass
I had read that article, but it also seemed to be somewhat rubbished as advertising for KeePass.

KeePass had had it's problems too: https://thehackernews.com/2015/11/password-manager-hacked.html

I already have LastPass and love it, I just wasn't sure about using it for seeds


           █████████████████     ████████
          █████████████████     ████████
         █████████████████     ████████
        █████████████████     ████████
       ████████              ████████
      ████████              ████████
     ████████     ███████  ████████     ████████
    ████████     █████████████████     ████████
   ████████     █████████████████     ████████
  ████████     █████████████████     ████████
 ████████     █████████████████     ████████
████████     ████████  ███████     ████████
            ████████              ████████
           ████████              ████████
          ████████     █████████████████
         ████████     █████████████████
        ████████     █████████████████
       ████████     █████████████████
▄▄
██
██
██
██
██
██
██
██
██
██     
██
██
▬▬ THE LARGEST & MOST TRUSTED ▬▬
      BITCOIN SPORTSBOOK     
   ▄▄
██
██
██
██
██
██
██
██
██
██     
██
██
             ▄▄▄▄▀▀▀▀▄
     ▄▄▄▄▀▀▀▀        ▀▄▄▄▄          
▄▀▀▀▀                 █   ▀▀▀▀▀▀▀▄▄
█                    ▀▄          █
 █   ▀▌     ██▄        █          █              
 ▀▄        ▐████▄       █        █
  █        ███████▄     ▀▄       █
   █      ▐████▄█████████████████████▄
   ▀▄     ███████▀                  ▀██
    █      ▀█████    ▄▄        ▄▄    ██
     █       ▀███   ████      ████   ██
     ▀▄        ██    ▀▀        ▀▀    ██
      █        ██        ▄██▄        ██
       █       ██        ▀██▀        ██
       ▀▄      ██    ▄▄        ▄▄    ██
        █      ██   ████      ████   ██
         █▄▄▄▄▀██    ▀▀        ▀▀    ██
               ██▄                  ▄██
                ▀████████████████████▀




  CASINO  ●  DICE  ●  POKER  
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
   24 hour Customer Support   

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
OmegaStarScream
Hero Member
*****
Offline Offline

Activity: 938



View Profile
May 30, 2016, 12:15:24 PM
 #6

LastPass is an online password manager ,It's definitely not recommended to store your seed or anything related to your private keys there.
I'd suggest storing them on KeePass instead since it's an offline password manager and you have a portable database file .kdx which you can use it anywhere as long as you have your Master key.

PS : LastPass got hacked last year - https://www.coinprices.io/posts/a-guide-to-basic-password-security-the-danger-of-last-pass
I had read that article, but it also seemed to be somewhat rubbished as advertising for KeePass.

KeePass had had it's problems too: https://thehackernews.com/2015/11/password-manager-hacked.html

I already have LastPass and love it, I just wasn't sure about using it for seeds

I'm only giving you an advice here man so it's up to you but I have to mention few things :

that hack was in 2015 and there were other versions of it and they keep updating it so it's secure now. Someone won't simply target you with a KeePass stealer in the first place unless he knows you are using it . Unlike LastPass where he won't target you personally but will target the whole database and get a lot of users passwords and then It's just a matter of time till the information's gets used or sold in the Darknet .
As a bitcoin , I suppose you understand that using online wallets (Coinbase/Blockchain.info) is unsecure , yes ? If it's the case then it's the same case for LastPass .

BitcoinSupremo
Hero Member
*****
Offline Offline

Activity: 490


★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
May 31, 2016, 08:32:28 PM
 #7

I saved my Seed in a Libreoffice 5 document in Linux, and put a strong password to that document, in addition to that, compressed it and put also a strong password to the rar file. Put that file in different USB plus in my laptop and desktop. Today I needed that file and restored my electrum wallet in my laptop without any problem at all. This is the best way to store your seed in my opinion.

BitcoinNewsMagazine
Hero Member
*****
Online Online

Activity: 798



View Profile WWW
June 01, 2016, 01:09:58 AM
 #8

If you are serious about security of your bitcoin your seed should never be displayed or typed on an online computer. Use a hardware wallet instead and write your seed on paper, store securely. If you use a hardware wallet that permits encryption of the seed with a passphrase you keep in your head you have an additional layer of protection. Using a PIN and simple passphrase on a Trezor provides very good security. Since the seed is worthless without the passphrase you can leave the seed with friends. Just do not forget your passphrase!

NUFCrichard
Hero Member
*****
Offline Offline

Activity: 966


★Nitrogensports.eu★


View Profile
June 01, 2016, 07:09:54 AM
 #9

If you are serious about security of your bitcoin your seed should never be displayed or typed on an online computer. Use a hardware wallet instead and write your seed on paper, store securely. If you use a hardware wallet that permits encryption of the seed with a passphrase you keep in your head you have an additional layer of protection. Using a PIN and simple passphrase on a Trezor provides very good security. Since the seed is worthless without the passphrase you can leave the seed with friends. Just do not forget your passphrase!

I am serious about security, but as this thread is showing, it really isn't as easy as it seems!  I don't want to have to remember anything, if I leave my Bitcoin untouched for a while, I will forget any decent password/phrase.
I quite like BitcoinSupremos idea, but then where do you store the 2 strong passwords?  I guess the chances of someone getting into lastpass, taking each of those passwords, and having access to my saved .rar file, is pretty remote.

I have read some trezor threads about them crashing/malfunctioning, I think I would go for a paper wallet before a trezor.


           █████████████████     ████████
          █████████████████     ████████
         █████████████████     ████████
        █████████████████     ████████
       ████████              ████████
      ████████              ████████
     ████████     ███████  ████████     ████████
    ████████     █████████████████     ████████
   ████████     █████████████████     ████████
  ████████     █████████████████     ████████
 ████████     █████████████████     ████████
████████     ████████  ███████     ████████
            ████████              ████████
           ████████              ████████
          ████████     █████████████████
         ████████     █████████████████
        ████████     █████████████████
       ████████     █████████████████
▄▄
██
██
██
██
██
██
██
██
██
██     
██
██
▬▬ THE LARGEST & MOST TRUSTED ▬▬
      BITCOIN SPORTSBOOK     
   ▄▄
██
██
██
██
██
██
██
██
██
██     
██
██
             ▄▄▄▄▀▀▀▀▄
     ▄▄▄▄▀▀▀▀        ▀▄▄▄▄          
▄▀▀▀▀                 █   ▀▀▀▀▀▀▀▄▄
█                    ▀▄          █
 █   ▀▌     ██▄        █          █              
 ▀▄        ▐████▄       █        █
  █        ███████▄     ▀▄       █
   █      ▐████▄█████████████████████▄
   ▀▄     ███████▀                  ▀██
    █      ▀█████    ▄▄        ▄▄    ██
     █       ▀███   ████      ████   ██
     ▀▄        ██    ▀▀        ▀▀    ██
      █        ██        ▄██▄        ██
       █       ██        ▀██▀        ██
       ▀▄      ██    ▄▄        ▄▄    ██
        █      ██   ████      ████   ██
         █▄▄▄▄▀██    ▀▀        ▀▀    ██
               ██▄                  ▄██
                ▀████████████████████▀




  CASINO  ●  DICE  ●  POKER  
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
   24 hour Customer Support   

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
BitcoinNewsMagazine
Hero Member
*****
Online Online

Activity: 798



View Profile WWW
June 01, 2016, 02:47:02 PM
 #10

If you are serious about security of your bitcoin your seed should never be displayed or typed on an online computer. Use a hardware wallet instead and write your seed on paper, store securely. If you use a hardware wallet that permits encryption of the seed with a passphrase you keep in your head you have an additional layer of protection. Using a PIN and simple passphrase on a Trezor provides very good security. Since the seed is worthless without the passphrase you can leave the seed with friends. Just do not forget your passphrase!

I am serious about security, but as this thread is showing, it really isn't as easy as it seems!  I don't want to have to remember anything, if I leave my Bitcoin untouched for a while, I will forget any decent password/phrase.
I quite like BitcoinSupremos idea, but then where do you store the 2 strong passwords?  I guess the chances of someone getting into lastpass, taking each of those passwords, and having access to my saved .rar file, is pretty remote.

I have read some trezor threads about them crashing/malfunctioning, I think I would go for a paper wallet before a trezor.


When you use Trezor the seed in effect is your bitcoin; the plastic device is a tool. You can crush your Trezor and be back up again in less than half an hour by recovering the seed to a new Trezor. Many folks who use Trezor keep a spare around in case of loss. I have never had a problem with Trezor crashing or malfunctioning. Once in a while the myTrezor.com site is down is all. If that happens you just use your Trezor with local Electrum.

Freakin
Full Member
***
Offline Offline

Activity: 154


View Profile
May 19, 2017, 04:13:27 AM
 #11

Bumping an old thread to add my $.02

Storing your seeds online is no good. 

I personally use lastpass for all my passwords.  The data are encrypted client side and never transmitted or stored unencrypted on Lastpass's servers.  They were hacked a year or two ago but the databases storing the encrypted passwords were not compromised.  I believe they only got user information.  Lastpass caught the hack themselves (either in progress or shortly afterward) by detecting an abnormal traffic pattern between some of their servers. 

So while I trust my encrypted passwords to lastpass, I don't trust the clients that decrypt those passwords (including my own computer) with my seed.  There are vulnerabilities in Lastpass clients that essentially trick the lastpass extension into filling hidden form fields on a website with all your passwords and posting them to their server behind the scenes.  This may be fixed already, but it doesn't mean another zero-day exploit won't be revealed in the client that can do the same.

Don't trust your seed to an online computer if you care about the BTC that the private keys can access.
jonald_fyookball
Legendary
*
Offline Offline

Activity: 1092



View Profile
May 19, 2017, 04:47:16 AM
 #12


First of all, if its a medium to large amount, keep it in cold storage.

but even small amount, I'm not sure I recommend lastpass... my understanding was data Is kept locally but not the best idea if your computer dies..just email yourself the seed or write it down (again for small amounts)


kolloh
Hero Member
*****
Offline Offline

Activity: 980



View Profile
May 19, 2017, 02:28:59 PM
 #13


First of all, if its a medium to large amount, keep it in cold storage.

but even small amount, I'm not sure I recommend lastpass... my understanding was data Is kept locally but not the best idea if your computer dies..just email yourself the seed or write it down (again for small amounts)



If you value security, don't ever email yourself a seed. Email is extremely insecure and is in plaintext (unless encrypted with PGP or something). Storing in LastPass would be much more secure than email. That being said, it is probably a bit safer to store the seed offline in a secure place.

.BitDice.               ▄▄███▄▄
           ▄▄██▀▀ ▄ ▀▀██▄▄
      ▄▄█ ▀▀  ▄▄█████▄▄  ▀▀ █▄▄
  ▄▄██▀▀     ▀▀ █████ ▀▀     ▀▀██▄▄
██▀▀ ▄▄██▀      ▀███▀      ▀██▄▄ ▀▀██
██  ████▄▄       ███       ▄▄████  ██
██  █▀▀████▄▄  ▄█████▄  ▄▄████▀▀█  ██
██  ▀     ▀▀▀███████████▀▀▀     ▀  ██
             ███████████
██  ▄     ▄▄▄███████████▄▄▄     ▄  ██
██  █▄▄████▀▀  ▀█████▀  ▀▀████▄▄█  ██
██  ████▀▀       ███       ▀▀████  ██
██▄▄ ▀▀██▄      ▄███▄      ▄██▀▀ ▄▄██
  ▀▀██▄▄     ▄▄ █████ ▄▄     ▄▄██▀▀
      ▀▀█ ▄▄  ▀▀█████▀▀  ▄▄ █▀▀
           ▀▀██▄▄ ▀ ▄▄██▀▀
               ▀▀███▀▀
        ▄▄███████▄▄
     ▄███████████████▄
    ████▀▀       ▀▀████
   ████▀           ▀████
   ████             ████
   ████ ▄▄▄▄▄▄▄▄▄▄▄ ████
▄█████████████████████████▄
██████████▀▀▀▀▀▀▀██████████
████                   ████
████                   ████
████                   ████
████                   ████
████                   ████
████▄                 ▄████
████████▄▄▄     ▄▄▄████████
  ▀▀▀█████████████████▀▀▀
        ▀▀▀█████▀▀▀
▄▄████████████████████████████████▄▄
██████████████████████████████████████
█████                            █████
█████                            █████
█████                            █████
█████                            █████
█████                     ▄▄▄▄▄▄▄▄▄▄
█████                   ▄█▀▀▀▀▀▀▀▀▀▀█▄
█████                   ██          ██
█████                   ██          ██
█████                   ██          ██
██████████████████▀▀███ ██          ██
 ████████████████▄  ▄██ ██          ██
   ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ ██          ██
             ██████████ ██          ██
           ▄███████████ ██████▀▀██████
          █████████████  ▀████▄▄████▀
[/]
Pages: [1]
  Print  
 
Jump to:  

Sponsored by , a Bitcoin-accepting VPN.
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!