Earlier quoted context omitted.
I never pick a real answer to my security questions. It just seems pointlessly dangerous.
Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.
Lastpass Security Incident
71–80 of 587 posts
Re: Lastpass Security Incident
#72Re: Lastpass Security Incident
#73Someday one of these password managers is going to be hacked wide open and it is NOT going to be pretty.
Re: Lastpass Security Incident
#74Re: Lastpass Security Incident
#75Earlier quoted context omitted.
Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.
Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.
Re: Lastpass Security Incident
#76Earlier quoted context omitted.
Most of them are build without having decrypted passwords or keys for them on server, so attacker would need to get to the point where they can craft malicious update to the client (or exploit the client)
Dependency exploit would be the way for 1Password etc, which are now basically wrapped web apps.
Re: Lastpass Security Incident
#77Re: Lastpass Security Incident
#78Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!
Re: Lastpass Security Incident
#79Earlier quoted context omitted.
How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.
I generate the password and stored them in my password manager under the notes. 1Password added functionality seemingly recently to add security questions and generate a random word string that I use these days.
Re: Lastpass Security Incident
#80Earlier quoted context omitted.
Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.
Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.