Time for hardware tokens based on DNA, so that nobody gets online unless they are exactly and uniquely who they are, and fully trackable from all points of contact. To get in, you must have the token. Bad actors lose access similar to jail time. Unless they can hack their DNA to be unique again, they don't get back in except on parole or after punishment. My guess is this way of solving old problems may create new on…
Lastpass Security Incident
91–100 of 587 posts
Re: Lastpass Security Incident
#92Re: Lastpass Security Incident
#93Earlier quoted context omitted.
Same. I use random passwords for any required security questions. It is funny when you call customer support and they ask you to verify a security question though.
Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.
Re: Lastpass Security Incident
#94Will never understand why people use managed password management services when things like the KeePass KDBX format exist.
Re: Lastpass Security Incident
#95Great, now I'm going to have to rename my dog.
Re: Lastpass Security Incident
#96What does HN community feel about Google chrome's internal password manager compared to third party ones?
Reply to @jeffbee: You basically have to have that threat model, because ordinary users are running dozens of untrustworthy processes on their machines. Real world security has to assume the user is not a security expert.
Re: Lastpass Security Incident
#97Will never understand why people use managed password management services when things like the KeePass KDBX format exist.
Re: Lastpass Security Incident
#98Will never understand why people use managed password management services when things like the KeePass KDBX format exist.
Re: Lastpass Security Incident
#99it's so baffling to me that people give ALL their password to a third party, commercial, organization...
U2FsdGVkX19mCN0qo7cyA5EfxgVqPQkygGlHqNgv1jM=
Guess it and post here and I'll supply you with the usernameRe: Lastpass Security Incident
#100Earlier quoted context omitted.
I generate the password and stored them in my password manager under the notes. 1Password added functionality seemingly recently to add security questions and generate a random word string that I use these days.
I hate password managers. They sign you out way too often and god forbid you’re on another PC.