Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

51–60 of 587 posts

Re: Lastpass Security Incident

#51

Great, now I'm going to have to rename my dog.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.

Re: Lastpass Security Incident

#52

Earlier quoted context omitted.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

they never know that i secretly use the name of my imaginary pet from grade 1 rather than my actual first pets name.

I use random strings and store them in a Passwordsafe db. Ever since the Sony PSN hack which IIRC did include secret questions and answers.

(I may be mistaken, but I do know it was absolutely the last time I gave a company true information for security questions).

Re: Lastpass Security Incident

#53

Great, now I'm going to have to rename my dog.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.

Re: Lastpass Security Incident

#54

Great, now I'm going to have to rename my dog.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

i use diceware. my mothers maiden name is sternness-ardently, and i am a proud graduate of blade-purge-satin-dash elementary!

…apparently.

Re: Lastpass Security Incident

#55

Earlier quoted context omitted.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.

You store the answers in your password manager and treat them like passwords

Re: Lastpass Security Incident

#56

Earlier quoted context omitted.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.

in the notes field of the appropriate keepass entry.

Re: Lastpass Security Incident

#57
post #25

it's so baffling to me that people give ALL their password to a third party, commercial, organization...

For most people, non-technical people in particular, their biggest exploit risk is they re-use the same username and password everywhere, one website gets popped and their creds get in the open, and then people use those creds to get into everything else. Anything that gets them to use unique, strong passwords for everything vastly improves their general security, even if they are using a third party, commercial orga…

Yep. I fell in the trap of using repeat passwords because I was lazy. One of them leaked and someone overseas started using my personal Plex server. I setup LassPass the next day and changed everything to unique strong passwords. LastPass is cross platform and the convenience is worth what the risk for personal use.

Re: Lastpass Security Incident

#58
post #39

Earlier quoted context omitted.

Dependency exploit would be the way for 1Password etc, which are now basically wrapped web apps.

even with everything, given the norms of lock files for even the most basic of web apps, you're still at "need to roll out a client update". Now that's not to say that something can't be sneaked into other work! But the bar is a bit higher than "take over a dependency"

that's what happend to solarwinds, it out worked pretty well for the hackers there

Re: Lastpass Security Incident

#59
post #47
post #37

Earlier quoted context omitted.

in what other tech stack is it a good idea to have all your eggs in one basket? that's why it's baffling. The convenience is outweighed by the possible loss.

What percentage of the population even thinks about "tech stacks"? That's the group of people who probably already is using something else. Everyone else is still catching up to not having a password that's just "password1234" People get their credential compromised via shared passwords way more than compromises of Lastpass or Chrome or 1Password. Sure, it's a bigger risk if your manager is compromised, but for most…

> password that's just "password1234"

it's even worse than that. The world's most common password is... password.

Re: Lastpass Security Incident

#60

Earlier quoted context omitted.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.

I generate the password and stored them in my password manager under the notes. 1Password added functionality seemingly recently to add security questions and generate a random word string that I use these days.
Post reply on HN