Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

81–90 of 587 posts

Re: Lastpass Security Incident

#81
post #25

it's so baffling to me that people give ALL their password to a third party, commercial, organization...

What's the alternative? 1. Have people manage their own secrets storage? Most people don't have the time or ability do this securely either. I'd rather pay someone else to secure infra, code, distribution, encryption, backups, etc. for me. 2. Reuse the same password on every site? One site gets hacked and now you're screwed. 3. Memorize a unique, long password for every site? Not feasible. Third-party/commercial pass…

Passwords suck. Move on to something better.

Re: Lastpass Security Incident

#82
Time for hardware tokens based on DNA, so that nobody gets online unless they are exactly and uniquely who they are, and fully trackable from all points of contact. To get in, you must have the token. Bad actors lose access similar to jail time. Unless they can hack their DNA to be unique again, they don't get back in except on parole or after punishment.

My guess is this way of solving old problems may create new ones due to that pesky problem called human nature.

Re: Lastpass Security Incident

#84
post #53

Earlier quoted context omitted.

Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.

Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.

I've certainly heard people speculate that would be the case. I always just put together 2-3 words unrelated to the question, e.g. my first grade schoolteacher is "Antique Campfire".

Re: Lastpass Security Incident

#85

Earlier quoted context omitted.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.

Pick your three favorite movie characters for which there is a lot of information about them (name, town where they grew up, age, dog with a name, etc.). Rotate through these three. Append the name of the service. Dog's name? buddylastpass

There will be no reuse, because for Facebook it would be buddyfacebook or dugfacebook, or something else… but you will always be able to guess it in three tries. A computer system doing some kind of pentest isn't going to parse out the "facebook" or "lastpass". A human might, but that's why you rotate through three names. At the point where you have a human targeting your account and actually thinking about your inputs you are probably !@#$ed anyway.

Re: Lastpass Security Incident

#86
post #53

Earlier quoted context omitted.

Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.

Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.

I've done something like this with my bank, I tell them it's a bunch of nonsense because the security question recovery is just a variation of a weak password so we'll need to validate me some other way. They always can

Re: Lastpass Security Incident

#87
The Verge has more information [1]

"This comes just months after LastPass confirmed that hackers had stolen some of its source code in August and had access to LastPass’ internal systems for four days before getting detected. It looks like this new attack is connected, as Loubba says it determined that hackers gained access to user data “using information obtained in the August 2022 incident.”"

https://www.theverge.com/2022/11/30/23486902/lastpass-hacker...

Re: Lastpass Security Incident

#89

Time for hardware tokens based on DNA, so that nobody gets online unless they are exactly and uniquely who they are, and fully trackable from all points of contact. To get in, you must have the token. Bad actors lose access similar to jail time. Unless they can hack their DNA to be unique again, they don't get back in except on parole or after punishment. My guess is this way of solving old problems may create new on…

Isn't DNA more of a "username" than a password?

Re: Lastpass Security Incident

#90

Earlier quoted context omitted.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

It’s seems more dangerous to be in doubt about your answers to security questions

I've had good results from refusing to play this security theatre.
Post reply on HN