Earlier quoted context omitted.
I generate the password and stored them in my password manager under the notes. 1Password added functionality seemingly recently to add security questions and generate a random word string that I use these days.
I hate password managers. They sign you out way too often and god forbid you’re on another PC.
Lastpass Security Incident
111–120 of 587 posts
Re: Lastpass Security Incident
#112And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…
Which is pretty easy with SyncThing. Other services like Dropbox are also fine if you have a sufficiently high entropy password. The danger isn't in the "online", but a third party being able to decrypt your passwords.
Re: Lastpass Security Incident
#113Earlier quoted context omitted.
Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.
I've done something like this with my bank, I tell them it's a bunch of nonsense because the security question recovery is just a variation of a weak password so we'll need to validate me some other way. They always can
Re: Lastpass Security Incident
#114Earlier quoted context omitted.
How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.
You store the answers in your password manager and treat them like passwords
Even if you're using real answers, you will be locked out of your account if you don't treat them like passwords. Eventually.
Re: Lastpass Security Incident
#115And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…
Re: Lastpass Security Incident
#116Re: Lastpass Security Incident
#117Earlier quoted context omitted.
How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.
memorable symbols and the site name !%!%example.com%!%!
It was clear to me after I had to read such a security question answer over the phone to unlock an account the CSR was perfectly happy with "gibberish over the phone == gibberish in front of me", meaning my attempt to secure things made it less secure in the end.
Re: Lastpass Security Incident
#118What does HN community feel about Google chrome's internal password manager compared to third party ones?
I'm not sure if they fixed it, but in the past any process that was running in your user account or admin on your PC could dump the plaintext of this trivially, for many years. Reply to @jeffbee: You basically have to have that threat model, because ordinary users are running dozens of untrustworthy processes on their machines. Real world security has to assume the user is not a security expert.
Re: Lastpass Security Incident
#119Great, now I'm going to have to rename my dog.
Re: Lastpass Security Incident
#120Kudos to the CEO for disclosing this as it's happening and writing the post. This disclosure post is direct, forthright about what's known, specific about engaging help, and explicit about notifying people as more happens. Hacking sucks, but the CEO's post is IMHO on the right track.
Ridiculous take. Absolutely zero kudos because it was obvious to everyone that this was the most likely outcome way back in August. Back in August the company issued a bullshit statement that they'd ruled out that the intruder accessed customer data. Now they are saying they did lose customer data.
EDIT to correct: Thanks to the link posted by u/voganmother42, this is indeed related!