Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

101–110 of 587 posts

Re: Lastpass Security Incident

#101

Time for hardware tokens based on DNA, so that nobody gets online unless they are exactly and uniquely who they are, and fully trackable from all points of contact. To get in, you must have the token. Bad actors lose access similar to jail time. Unless they can hack their DNA to be unique again, they don't get back in except on parole or after punishment. My guess is this way of solving old problems may create new on…

[deleted]

Re: Lastpass Security Incident

#102
And here I am still just using KeePass.

I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible.

You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across devices.

Re: Lastpass Security Incident

#103
post #22

Earlier quoted context omitted.

Most of them are build without having decrypted passwords or keys for them on server, so attacker would need to get to the point where they can craft malicious update to the client (or exploit the client)

1. Get access to build infrastructure (e.g. via supply chain attack) 2. Inject code in build to export user's passwords to remote server after update is installed

Simple, but not easy.

Re: Lastpass Security Incident

#104

Time for hardware tokens based on DNA, so that nobody gets online unless they are exactly and uniquely who they are, and fully trackable from all points of contact. To get in, you must have the token. Bad actors lose access similar to jail time. Unless they can hack their DNA to be unique again, they don't get back in except on parole or after punishment. My guess is this way of solving old problems may create new on…

Wouldn't this be easily bypassed by, say, picking up a hair on a street and fabricating the token?

If so, at least bad actors won't have the incentive to cut off your finger or pull an eye out as with the other biometric authentication options :')

Re: Lastpass Security Incident

#105
post #50

Can someone in the know comment here on the succinct and honest scope of breach of passwords stored by LastPass users?

They're encrypted/decrypted by the user's password locally in the app or extension.

How does it work for passwords which you shared with your team on their enterprise plan?

Re: Lastpass Security Incident

#107
post #66

Earlier quoted context omitted.

i use diceware. my mothers maiden name is sternness-ardently, and i am a proud graduate of blade-purge-satin-dash elementary! …apparently.

blade-purge sounds like a good name for a metal band

That's gotta be a diceware option, right?

Re: Lastpass Security Incident

#108

Earlier quoted context omitted.

No one who uses unique passwords can remember them forever. It's a compromise of post-it notes vs managers. Either that or do account recovery every time you need to do your taxes (SOL for encrypted files though). I sadly write passwords down, but dream of a better option.

Post-It notes are a safer option than password managers. And it's absolutely outrageous to say this: But not every single account you have needs a unique password. Just ones which can actually allow someone to impersonate you meaningfully, cost you money, or gather sensitive data about you. Response to @palata because of rate-limiting: The problem is people tend not to only put unimportant accounts in their password…

Well then at least those accounts that are "less important" are probably not worse off in a password manager than sharing one password, are they?

Re: Lastpass Security Incident

#109
post #78

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

This is years ago now, but every ampersand in my passwords came across wrong. I can't recall if it was missing or url encoded, but even passwords weren't safe.

I'm still finding passwords in Bitwarden to old accounts that have `&` in them. Thanks, LastPass!

Re: Lastpass Security Incident

#110
post #43

Kudos to the CEO for disclosing this as it's happening and writing the post. This disclosure post is direct, forthright about what's known, specific about engaging help, and explicit about notifying people as more happens. Hacking sucks, but the CEO's post is IMHO on the right track.

Ridiculous take. Absolutely zero kudos because it was obvious to everyone that this was the most likely outcome way back in August. Back in August the company issued a bullshit statement that they'd ruled out that the intruder accessed customer data. Now they are saying they did lose customer data.
Post reply on HN