Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

41–50 of 587 posts

Re: Lastpass Security Incident

#41
post #20

Someday one of these password managers is going to be hacked wide open and it is NOT going to be pretty.

The core problem is really that passwords suck and should never be the entirety of authentication. Time for hardware tokens! (admittedly there are some big problems when people lose tokens, but at least that's not a problem of insecurity ;-))

Re: Lastpass Security Incident

#42
Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo.

You must make sure the exported CSV file has everything!

Re: Lastpass Security Incident

#43
Kudos to the CEO for disclosing this as it's happening and writing the post. This disclosure post is direct, forthright about what's known, specific about engaging help, and explicit about notifying people as more happens. Hacking sucks, but the CEO's post is IMHO on the right track.

Re: Lastpass Security Incident

#44
post #20

Someday one of these password managers is going to be hacked wide open and it is NOT going to be pretty.

I don't use them, but my conclusion is that at least one major cloud password manager has been hacked already without any disclosure. If they disclose it, the company should logically be dead. Thus, the incentive would just be to cover it up.

Can you elaborate more? Which? Why do you think this? I also agree with you and I think it’s one that rhymes with shome paus werd. But I think it happened early in their “cloud” journey

Re: Lastpass Security Incident

#45

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

It also didn't export attachments when I used it (long while ago now though)

Re: Lastpass Security Incident

#46
post #37
post #33

Earlier quoted context omitted.

Come on now. How is that baffling?

in what other tech stack is it a good idea to have all your eggs in one basket? that's why it's baffling. The convenience is outweighed by the possible loss.

There are lots of enterprise tech stacks where you have a single (or single-as-possible) centralized secret store… it’s far from uncommon, I.e., Hashicorp Vault, AWS Secrets Manager, Google Cloud KMS.

Re: Lastpass Security Incident

#47
post #37
post #33

Earlier quoted context omitted.

Come on now. How is that baffling?

in what other tech stack is it a good idea to have all your eggs in one basket? that's why it's baffling. The convenience is outweighed by the possible loss.

What percentage of the population even thinks about "tech stacks"? That's the group of people who probably already is using something else. Everyone else is still catching up to not having a password that's just "password1234"

People get their credential compromised via shared passwords way more than compromises of Lastpass or Chrome or 1Password. Sure, it's a bigger risk if your manager is compromised, but for most people it's as much "eggs in one basket" as people only having one bank account which is probably true of nearly everyone.

Re: Lastpass Security Incident

#49
I used to be a lastpass customer a few years ago, until I switched to Bitwarden. Can you tell me that you actually delete users data when they delete their account? Or do you keep backups which were also hacked? i.e. are your ex-customers also affected?
Post reply on HN