Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

91–100 of 587 posts

Re: Lastpass Security Incident

#91

Time for hardware tokens based on DNA, so that nobody gets online unless they are exactly and uniquely who they are, and fully trackable from all points of contact. To get in, you must have the token. Bad actors lose access similar to jail time. Unless they can hack their DNA to be unique again, they don't get back in except on parole or after punishment. My guess is this way of solving old problems may create new on…

DNA is easier to lift from unsuspecting victims than it is to hack your alphanumeric code. Thought theft at scale with DNA based systems would be hard. Unless, you’re the government, in which case, good luck.

Re: Lastpass Security Incident

#93
post #53

Earlier quoted context omitted.

Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.

Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.

Anecdotally I've heard of this type of social engineering working. It's probably better to use some randomly generated real words. Another poster suggested diceware.

Re: Lastpass Security Incident

#94

Will never understand why people use managed password management services when things like the KeePass KDBX format exist.

Basically the entire password manager space is the result of "security fatigue". Telling everyone that every single unimportant website they log into requires a unique high security password makes people use bad solutions that make their security worse, like storing all their passwords in a cloud-based single point of failure.

Re: Lastpass Security Incident

#96
post #72

What does HN community feel about Google chrome's internal password manager compared to third party ones?

I'm not sure if they fixed it, but in the past any process that was running in your user account or admin on your PC could dump the plaintext of this trivially, for many years.

Reply to @jeffbee: You basically have to have that threat model, because ordinary users are running dozens of untrustworthy processes on their machines. Real world security has to assume the user is not a security expert.

Re: Lastpass Security Incident

#98

Will never understand why people use managed password management services when things like the KeePass KDBX format exist.

when you have an employee leave your company can you reroll or disable all their work account passwords in keepass? (no; this is good for the user and not useful for the org, but that’s the use case.)

Re: Lastpass Security Incident

#99
post #25

it's so baffling to me that people give ALL their password to a third party, commercial, organization...

I'll do you one better. This is an encrypted base64 password with access to 5 ETH on Coinbase:

    U2FsdGVkX19mCN0qo7cyA5EfxgVqPQkygGlHqNgv1jM=
Guess it and post here and I'll supply you with the username

Re: Lastpass Security Incident

#100
post #60

Earlier quoted context omitted.

I generate the password and stored them in my password manager under the notes. 1Password added functionality seemingly recently to add security questions and generate a random word string that I use these days.

I hate password managers. They sign you out way too often and god forbid you’re on another PC.

How often is way too often?
Post reply on HN