Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

21–30 of 587 posts

Re: Lastpass Security Incident

#21
post #20

Someday one of these password managers is going to be hacked wide open and it is NOT going to be pretty.

I don't use them, but my conclusion is that at least one major cloud password manager has been hacked already without any disclosure. If they disclose it, the company should logically be dead. Thus, the incentive would just be to cover it up.

Re: Lastpass Security Incident

#22
post #20

Someday one of these password managers is going to be hacked wide open and it is NOT going to be pretty.

Most of them are build without having decrypted passwords or keys for them on server, so attacker would need to get to the point where they can craft malicious update to the client (or exploit the client)

Re: Lastpass Security Incident

#24

Earlier quoted context omitted.

Post-It notes are a safer option than password managers. And it's absolutely outrageous to say this: But not every single account you have needs a unique password. Just ones which can actually allow someone to impersonate you meaningfully, cost you money, or gather sensitive data about you. Response to @palata because of rate-limiting: The problem is people tend not to only put unimportant accounts in their password…

I do post-it notes and a couple of master passwords for things I don't care about, so I don't disagree. I need to make 2 points though. 1, enough 'non-sensitive' data can eventually become sensitive when taken as a whole, and 2 post-it notes are less secure if they are at a place of employment, think teachers. Maybe the best option is one of those physical access password managers like KeePass

KeePass on something normally-offline like a thumb drive is probably a decent compromise where needed, but I'd still encourage people to keep their most sensitive passwords either undocumented or partially/incorrectly documented.

Re: Lastpass Security Incident

#26
post #22
post #20

Someday one of these password managers is going to be hacked wide open and it is NOT going to be pretty.

Most of them are build without having decrypted passwords or keys for them on server, so attacker would need to get to the point where they can craft malicious update to the client (or exploit the client)

Dependency exploit would be the way for 1Password etc, which are now basically wrapped web apps.

Re: Lastpass Security Incident

#30
post #25

it's so baffling to me that people give ALL their password to a third party, commercial, organization...

For most people, non-technical people in particular, their biggest exploit risk is they re-use the same username and password everywhere, one website gets popped and their creds get in the open, and then people use those creds to get into everything else.

Anything that gets them to use unique, strong passwords for everything vastly improves their general security, even if they are using a third party, commercial organization.

Post reply on HN