it's so baffling to me that people give ALL their password to a third party, commercial, organization...
What's the alternative? 1. Have people manage their own secrets storage? Most people don't have the time or ability do this securely either. I'd rather pay someone else to secure infra, code, distribution, encryption, backups, etc. for me. 2. Reuse the same password on every site? One site gets hacked and now you're screwed. 3. Memorize a unique, long password for every site? Not feasible. Third-party/commercial pass…
Lastpass Security Incident
81–90 of 587 posts
Re: Lastpass Security Incident
#82My guess is this way of solving old problems may create new ones due to that pesky problem called human nature.
Re: Lastpass Security Incident
#83What does the hacker news community think about Google Chrome's internal password manager?
Re: Lastpass Security Incident
#84Earlier quoted context omitted.
Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.
Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.
Re: Lastpass Security Incident
#85Earlier quoted context omitted.
I never pick a real answer to my security questions. It just seems pointlessly dangerous.
How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.
There will be no reuse, because for Facebook it would be buddyfacebook or dugfacebook, or something else… but you will always be able to guess it in three tries. A computer system doing some kind of pentest isn't going to parse out the "facebook" or "lastpass". A human might, but that's why you rotate through three names. At the point where you have a human targeting your account and actually thinking about your inputs you are probably !@#$ed anyway.
Re: Lastpass Security Incident
#86Earlier quoted context omitted.
Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.
Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.
Re: Lastpass Security Incident
#87"This comes just months after LastPass confirmed that hackers had stolen some of its source code in August and had access to LastPass’ internal systems for four days before getting detected. It looks like this new attack is connected, as Loubba says it determined that hackers gained access to user data “using information obtained in the August 2022 incident.”"
https://www.theverge.com/2022/11/30/23486902/lastpass-hacker...
Re: Lastpass Security Incident
#88Re: Lastpass Security Incident
#89Time for hardware tokens based on DNA, so that nobody gets online unless they are exactly and uniquely who they are, and fully trackable from all points of contact. To get in, you must have the token. Bad actors lose access similar to jail time. Unless they can hack their DNA to be unique again, they don't get back in except on parole or after punishment. My guess is this way of solving old problems may create new on…