Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

71–80 of 587 posts

Re: Lastpass Security Incident

#71
post #53

Earlier quoted context omitted.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.

I have had this problem, and failed the security check when I told them I had to look it up. Which was a little silly because I just hung up and called back and did it again with the list in front of me.

Re: Lastpass Security Incident

#73
post #20

Someday one of these password managers is going to be hacked wide open and it is NOT going to be pretty.

Sure it’ll result in a lot of issues for minor sites, but most critical services mandate 2FA. So just don’t keep your password and 2FA in these services.

Re: Lastpass Security Incident

#74
If you're a lastpass user, might be wise to avoid logging into lastpass until they update with a resolution - if the attackers got into the build server they could craft attacks that would exfiltrate passwords after user decrypts

Re: Lastpass Security Incident

#75
post #53

Earlier quoted context omitted.

Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.

Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.

In my experience, this usually works, especially with banks.

Re: Lastpass Security Incident

#76
post #22

Earlier quoted context omitted.

Most of them are build without having decrypted passwords or keys for them on server, so attacker would need to get to the point where they can craft malicious update to the client (or exploit the client)

Dependency exploit would be the way for 1Password etc, which are now basically wrapped web apps.

Only web apps have dependencies?

Re: Lastpass Security Incident

#78

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

This is years ago now, but every ampersand in my passwords came across wrong. I can't recall if it was missing or url encoded, but even passwords weren't safe.

Re: Lastpass Security Incident

#79
post #60

Earlier quoted context omitted.

How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.

I generate the password and stored them in my password manager under the notes. 1Password added functionality seemingly recently to add security questions and generate a random word string that I use these days.

Note that you should not generate a random password like D27fX$0f7RyD for your security questions. These are designed to give to a human operator on the other end of a phone. If an attacker calls up the account recovery line, gets asked for a security question, and just says "heh, I think it was a string of random characters", there's a decent chance the human operator will let them into the account. As you say, use an actual word string (passphrase) generator, which is a bit less susceptible to this attack.

Re: Lastpass Security Incident

#80
post #53

Earlier quoted context omitted.

Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.

Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.

I haven't tried, but I am not on the phone with support much as I go to great lengths to avoid calling haha. The one time I had to verify my security question, I told the representative that its a long, random character string and they waited for me to open up my password manager to read it out to them.
Post reply on HN