Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

111–120 of 587 posts

Re: Lastpass Security Incident

#111
post #60

Earlier quoted context omitted.

I generate the password and stored them in my password manager under the notes. 1Password added functionality seemingly recently to add security questions and generate a random word string that I use these days.

I hate password managers. They sign you out way too often and god forbid you’re on another PC.

My work provides me with a 1Password subscription (for both work personal use) that I take advantage of that is pretty good. I think they only require you to reauthenticate with your master password once every two weeks or something. I use a PIN, biometrics, or my Apple Watch to unlock it when it timeouts in between that two week period, and I've had no problems syncing between several of my devices.

Re: Lastpass Security Incident

#112

And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…

> You just have to deal with the very mild inconvenience of keeping your database synchronized across devices.

Which is pretty easy with SyncThing. Other services like Dropbox are also fine if you have a sufficiently high entropy password. The danger isn't in the "online", but a third party being able to decrypt your passwords.

Re: Lastpass Security Incident

#113

Earlier quoted context omitted.

Have you ever tried to see if they'd let you bypass the question? I've wondered if saying "it's a bunch of gibberish" could work.

I've done something like this with my bank, I tell them it's a bunch of nonsense because the security question recovery is just a variation of a weak password so we'll need to validate me some other way. They always can

I was on a first date and forgot my wallet so the first place we went was the bank. I had to repeat all my info 3x. I leveled with them and pointed to my date and said I need $100. They gave me the $100.

Re: Lastpass Security Incident

#114
post #55

Earlier quoted context omitted.

How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.

You store the answers in your password manager and treat them like passwords

Yup. You pretty much have to do this. I love signing into my bank's bill payment system. "You appear to know your password and possess your second factor. But what's your favorite book? WRONG YOUR FAVORITE BOOK IS ACTUALLY NOW YOUR ACCOUNT IS LOCKED."

Even if you're using real answers, you will be locked out of your account if you don't treat them like passwords. Eventually.

Re: Lastpass Security Incident

#115

And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…

This, very much so. I use KeepassXC (Strongbox on iOS) with Seafile to sync the database files. It's only gotten better over the years, and I'd rather see my donation money go directly to the developers than get slurped up into some SaaS that doesn't care about me or security anyway.

Re: Lastpass Security Incident

#116
Never using online password manager is a good start. Only use encrypted local password manager preferably on encrypted file system and never use same passwords and emails. Best have seperate emails at least for the most important data. Also generating random 50+ alpha-numeric-symbols.

Re: Lastpass Security Incident

#117

Earlier quoted context omitted.

How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.

memorable symbols and the site name !%!%example.com%!%!

I used to do something like this. I avoid it now, and use a pass phrase of a few words as answers to these questions, stored as a password.

It was clear to me after I had to read such a security question answer over the phone to unlock an account the CSR was perfectly happy with "gibberish over the phone == gibberish in front of me", meaning my attempt to secure things made it less secure in the end.

Re: Lastpass Security Incident

#118
post #72

What does HN community feel about Google chrome's internal password manager compared to third party ones?

I'm not sure if they fixed it, but in the past any process that was running in your user account or admin on your PC could dump the plaintext of this trivially, for many years. Reply to @jeffbee: You basically have to have that threat model, because ordinary users are running dozens of untrustworthy processes on their machines. Real world security has to assume the user is not a security expert.

A process running as my user or admin on my PC can also just inject input events to transfer money out of my bank account. You cannot have a useful threat model that models yourself as a threat.

Re: Lastpass Security Incident

#120
post #43

Kudos to the CEO for disclosing this as it's happening and writing the post. This disclosure post is direct, forthright about what's known, specific about engaging help, and explicit about notifying people as more happens. Hacking sucks, but the CEO's post is IMHO on the right track.

Ridiculous take. Absolutely zero kudos because it was obvious to everyone that this was the most likely outcome way back in August. Back in August the company issued a bullshit statement that they'd ruled out that the intruder accessed customer data. Now they are saying they did lose customer data.

Is this the same incident as the August incident (https://blog.lastpass.com/2022/11/notice-of-recent-security-...)? From this blog post, it’s not clear to me that they are.

EDIT to correct: Thanks to the link posted by u/voganmother42, this is indeed related!

Post reply on HN