Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

31–40 of 587 posts

Re: Lastpass Security Incident

#34
post #25

it's so baffling to me that people give ALL their password to a third party, commercial, organization...

For many, the ease of setup and maintenance is worth the risk.

The general population is not going to setup their own open source password manager solution. So going with an easy to use commercial password manager is better than not using one at all.

Re: Lastpass Security Incident

#35

Great, now I'm going to have to rename my dog.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

they never know that i secretly use the name of my imaginary pet from grade 1 rather than my actual first pets name.

Re: Lastpass Security Incident

#37
post #33
post #25

it's so baffling to me that people give ALL their password to a third party, commercial, organization...

Come on now. How is that baffling?

in what other tech stack is it a good idea to have all your eggs in one basket?

that's why it's baffling. The convenience is outweighed by the possible loss.

Re: Lastpass Security Incident

#38
post #22
post #20

Someday one of these password managers is going to be hacked wide open and it is NOT going to be pretty.

Most of them are build without having decrypted passwords or keys for them on server, so attacker would need to get to the point where they can craft malicious update to the client (or exploit the client)

1. Get access to build infrastructure (e.g. via supply chain attack)

2. Inject code in build to export user's passwords to remote server after update is installed

Re: Lastpass Security Incident

#39
post #22

Earlier quoted context omitted.

Most of them are build without having decrypted passwords or keys for them on server, so attacker would need to get to the point where they can craft malicious update to the client (or exploit the client)

Dependency exploit would be the way for 1Password etc, which are now basically wrapped web apps.

even with everything, given the norms of lock files for even the most basic of web apps, you're still at "need to roll out a client update".

Now that's not to say that something can't be sneaked into other work! But the bar is a bit higher than "take over a dependency"

Re: Lastpass Security Incident

#40
post #37
post #33

Earlier quoted context omitted.

Come on now. How is that baffling?

in what other tech stack is it a good idea to have all your eggs in one basket? that's why it's baffling. The convenience is outweighed by the possible loss.

What is the alternative strategy? I think for most people before password managers the strategy would be "have one egg".
Post reply on HN