Showing posts with label Video. Show all posts
Showing posts with label Video. Show all posts

Monday, August 09, 2021

LastPass is Broken. Seriously Broken

Irony
I have used and recommended LastPass for years. It has allowed me to create random passwords for a gazillion websites that I have used or visited over the years. But I no longer wish to pay for the service: I have found the open source BitWarden product instead. I migrated all my passwords to BitWarden, and it seems to work just as well.
It seems, however, that LastPass just doesn't want to say goodbye. No matter what I do, I can't delete my account. And they don't make it easy, either. First, you have to find the part of the website that "enables" you to delete the account.
Log in to your LastPass account and click on "Account Settings" at the bottom left. Then scroll down to "Account Information" and click on the "My Account" link.
Don't waste your time trying to cancel your PayPal recurring payment. There isn't one. LastPass stopped using PayPal, but hasn't updated its website to reflect this. Nor has it informed its customers. So, you will be sent on a wild goose chase at PayPal that will only waste your time and achieve nothing. #Strike1
Rather, click on the button to "Delete or Reset Account".
I suggest you export all your data and click on the "Reset" button. This ensures that you no longer have any passwords stored on the LastPass servers. At least that part works.
Now let's try deleting the account. Click on the "Delete" button.
You should get this fancy dialog box. Click on "Yes" because, actually, we do remember the LastPass master password. How else would we have been able to log in if we didn't?
This dialog box is broken. Presumably it would ask me to type in the master password, or something. I have no idea. #Strike2
Go back to the delete button and answer "No" to the question about remembering the master password. Let's see if that works. Click on the "Send Email" button, just to waste your time. #Strike3
OK, so now you look in your mailbox for the message from LastPass. If you are using Gmail, it's in the "Updates" section of your inbox.
So despite being told to "never click on an email link", we have to click on the email link in the message, which takes us to the following page:
Notice that we didn't have to log in to get here because we don't know our master password, remember? Fortunately, the link does expire after a while. There are supposed to be some buttons and other confirmation goodies on this page, but they aren't there. #Strike4.
So, I contacted the LastPass "help" desk. No help whatsoever. They asked me to try various things, all of which are mentioned above. #Strike5.
The Twitter account ignored my case number and told me to try various things, which didn't help. The link to their "help" mentions buttons that do not appear on the screen.
So far I have tried the following browsers:
  • Internet Explorer 11. No extensions or add-ons
  • Google Chrome, including Incognito mode, with all extensions disabled.
  • Firefox, including private browsing, with all extensions disabled.
  • Microsoft Edge, with no extensions.
I'm running out of options here.
I guess I'll have to wait until my "membership" comes up for renewal and see what happens then.

Update Tuesday 10th August: I tried posting in the LastPass "Community Forum" with some interesting results:
  • The link to this blog article was deleted. #Strike6
  • My question about "Does LastPass have ties to China?" (from the GRC forums) was deleted completely from my LastPass forum post. I'll take that as a "yes".
I asked a simple question:
"Why can't you guys just use basic HTML that is guaranteed to work on all browsers? Clearly this super-sensitive, entirely vulnerable, overly engineered JavaScript spread out over several modules doesn't work."
Let's see if we get a coherent answer.

Update 2: Apparently this is the screen I'm supposed to get:
I decided to try downloading a VirtualBox image from Microsoft that contains just Windows 7 Enterprise Edition and Internet Explorer 11. It only works for 90 days and is designed for web developers to test their websites.
After setting the DNS servers to 1.1.1.1 and 8.8.8.8 in the network settings, I ventured to the lastpass.com page and got the same result as before. This time I was using the default settings for IE 11 as recommended by Microsoft.
I also tried downloading and installing Firefox, and got exactly the same result with their default settings.
This is the Brave browser, again using default settings.
Here is Google Chrome, using default settings.
Finally, Microsoft Edge for Windows 7. It must be Windows 7 that is faulty. So let's try the Microsoft VirtualBox image with MSEdge and Windows 10.
The original Microsoft Edge browser with default settings.
The new Microsoft Edge browser with default settings.
The creaky old Microsoft Internet Explorer 11 browser with default settings.
So if it isn't the choice of browser, or the choice of Windows version, maybe, just maybe, it has something to do with the lastpass.com website? I'm pretty sure the LastPass "help" centre is connecting to another version of lastpass.com, probably the one on their Intranet.
It seems that I'm not the only one who has had this problem.

Update Wednesday 11 August: Remember my trace route (image above)? Well, I got this illuminating response:
Thanks, Glenn, for disregarding possibly helpful technical information. My confidence in your organisation has grown in leaps and bounds. #Strike7
Remember the definition of insanity? Repeating the same thing over and over and expecting a different result. Well, the LastPass "Support" team seems to think that if they give you instructions that didn't work the first time, they will somehow work the next time. Maybe they just aren't saying it loudly enough.
Or if they say something completely incomprehensible, it will somehow make the problem go away:
See if you can figure out what this means. I have no idea.
On a different note, it now turns out that I need to cancel my subscription with PayPal. I have already pointed out that I can't do that because the instructions provided no longer work. So now I have to give them screenshots to show how it doesn't work.
As you can see, there is no "Yes" button to click on.
So now we have some instructions that haven't worked since 2018, but let's try them anyway.
Step 1 and 2 still work: I can click on the gear icon. I can find the "Payments" section, but nothing about "Pre-approved payments" and only one active subscription (Patreon).
I found two LogMeIn entries under "Inactive" but there is no "Cancel" button. #Strike8 Now I know what the pilots in Catch 22 felt like.

Update Thursday 12 August: Eventually, the desired result:
I tried logging in, and it rejected my login. Yay!
It has only taken two weeks to get them to cancel the account. Now I need to go through the same process for my wife's LastPass account. 

Friday, April 06, 2018

Stretchly: the smart way to use your computer

We all sit too long, and if you are like me, stare at the computer screen for far too long. On 10th February I injured my back, and one of the discs in my spine started pinching my left Sciatic nerve. I was on anti-inflammatory medication and pain killers for a few weeks. Sitting, standing, walking and lying down were all uncomfortable if I did any of them for too long.
A friend sent me a video about how bad too much sitting is (see some examples below), and my new experience confirmed this. Then I was told about a program that would interrupt you on the computer and force you to take regular breaks. One of these is Stretchly, and it works wonders!
It's free, open source software that works for Windows, Mac and Linux. Every now and then you are asked to take a "microbreak" of a few seconds, and there are helpful tips to suggest how to take the break. And then about every 30 minutes or so you should take a proper break from the computer. Get up and walk around, and give your back a chance to recover from all the unhealthy sitting (and slouching in my case).
To force you to take the break it puts a big box right in the middle of the screen. The microbreaks only last for a few seconds, but the full break is 5 minutes. Most chiropractors will tell you to take a break from sitting at least every 30 minutes, and Stretchly helps you do this. If you leave your desk for more than 5 minutes before the enforced break, it resets its timers for you. And once the enforced break is up, it sounds a helpful chime to tell you the time is up, so you don't waste time or have to stand around checking the screen.
Since we can only concentrate fully for up to 20 minutes at a time, these breaks actually make you more productive, because they help you regain focus and think about what you are doing. I was apprehensive about this at first, but I find my code is much less buggy and more well thought out because of the enforced breaks. There are plenty of useful features in the program, and if you are going to watch a movie or you need to connect to a client's computer for remote support, you can pause the program for a while. There are plenty of options you can tweak to get it to work just right for you. Check it out!
One final idea from the 4th video below: stand up every time you take a call or use your phone. Great idea. Put the phone somewhere other than your desk to make this happen. It will also reduce your exposure to the radiation from the phone. But that's another story for another day.
Update 19 May: Thanks to feedback from the developer, I discovered that you can change the messages that Stretchly displays, so I was able to add in the exercises that my Bio-Kineticist has recommended. I also found an Android app called "Big Ben Bonger" that plays the Big Ben chimes on my phone. I can set it to go off every half hour when I'm working on other people's computers.



Tuesday, July 11, 2017

This Video Should Make You Angry


I thought South Africa was a screwed up country, but the greatest hypocrites on the planet have to be the USA. They even have the audacity to call themselves "Americans" to the exclusion of the remaining population of two continents, including such countries as Canada, Mexico, Brazil, Argentina, Chile and a dozen more. And every 16 years or so they elect a moron for 8 years, followed by a liar for another 8. And so it goes.

Tuesday, July 04, 2017

Happy 4th July, USA


In the supposed land of the free, visit https://www.battleforthenet.com for more information on how the USA is abusing the rights of its citizens.

Monday, May 01, 2017

Julius vs The ANC

This documentary is from the same producer who did the documentary on Marikana that the SABC refused to broadcast. It paints a chilling picture of the years to come, and is well worth watching.

Wednesday, December 28, 2016

Bethlehemian Rhapsody

This video was first posted on YouTube on 7 Jan 2009, yet I only saw it the say before Christmas this year, sent via WhatsApp. It's a great parody. Enjoy! You can also download it (without captions) on http://www.puppetunes.com/

Wednesday, September 28, 2016

Uber Safety: It gets worse

This report, published by eNCA in May 2016, summarises one of the problems that drivers face in Joburg. But it contains a statement that completely outraged me: "Driver partners have access to an emergency line"
Either this is a blatant lie, or none only some of the drivers have heard of it. I have asked several of them, and only one has admitted he has it on his phone, but not memorised it. Just like none few of the drivers have been told to expect passengers to ask them to open the boot after the recent attacks where the attackers hid in the boot. They gave me and my wife a blank stare when we asked, each on different occasions.
But this statement also begs the question: why is there no emergency line for Uber passengers? Because Uber doesn't care, and they have only recently appointed someone to handle their security.
On Wednesday [Sept 21 2016], Uber also announced the appointment of a new head of security for Africa in the form of Deon Du Toit.
So their statement about ".. Our specially-trained incident response teams are available around the clock to handle any urgent concerns that arise ..." is also questionable. They've been in operation for 3 years but only appointed someone last week?
I also found this gem, hidden away in the "receipt" section of the app (i.e. after the emergency is over and you get the receipt for your rape ordeal). Even their reassurances about their "Rapid Response" team is filed in the "After the trip" section of their Safety page.
Update 30 September 2016: eNCA has posted a longer version of its interview with Alon Lits,
CEOGeneral Manager of Uber for South Africa.
In the interview he refers to the ride receipts Uber sent to the rape victims as "speculation", and claims that the arrested driver was not employed during attacks. This begs the question: which driver generated the ride receipt if not the driver arrested? Alternatively, if the driver was no longer employed, how was he able to access the Uber system and log in as a driver?
My personal experence of Uber is that their software is not particularly stable or well designed. This week they managed to send two vehicles simultanously, and charged me for both "trips". How is that even possible?
In the interview he mentions the "two factor authentication" they like to tout. This consists in sending a random code via SMS to the phone of the driver when "he" logs in on that phone. How does that verify anything other than the phone number being used to log in? It doesn't verify the driver at all! They know this too, but refuse to admit it.
Perhaps I'm misunderstanding what Alon said, but he implied that the ".. specially-trained incident response teams ... available around the clock ..." aren't actually based in Johannesburg at all, but operate from Uber offices in California. Seriously!?
Update Sat 1 October: The incident response team is based in the United Kingdom, not California. Like that makes a huge difference.