Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

161–170 of 587 posts

Re: Lastpass Security Incident

#161
post #112

Earlier quoted context omitted.

> You just have to deal with the very mild inconvenience of keeping your database synchronized across devices. Which is pretty easy with SyncThing. Other services like Dropbox are also fine if you have a sufficiently high entropy password. The danger isn't in the "online", but a third party being able to decrypt your passwords.

> Which is pretty easy with SyncThing Is SyncThing available for iOS? I thought it wasn’t but I’d love to be wrong.

It's not

Re: Lastpass Security Incident

#162
For those that do not know

Yubico hardware stuff does work with both Bitwarden and BitLocker

It's the solution I will be transitioning to at some point.

Note, GitHub requires 2-auth fall of 2023 in case anyone forgot.

Re: Lastpass Security Incident

#163
post #43

Kudos to the CEO for disclosing this as it's happening and writing the post. This disclosure post is direct, forthright about what's known, specific about engaging help, and explicit about notifying people as more happens. Hacking sucks, but the CEO's post is IMHO on the right track.

Not to mention, this is mentioned nowhere on the LastPass page itself - only on that of the corporate owners.

Re: Lastpass Security Incident

#165
post #43

Kudos to the CEO for disclosing this as it's happening and writing the post. This disclosure post is direct, forthright about what's known, specific about engaging help, and explicit about notifying people as more happens. Hacking sucks, but the CEO's post is IMHO on the right track.

Ridiculous take. Absolutely zero kudos because it was obvious to everyone that this was the most likely outcome way back in August. Back in August the company issued a bullshit statement that they'd ruled out that the intruder accessed customer data. Now they are saying they did lose customer data.

[deleted]

Re: Lastpass Security Incident

#166
post #25

it's so baffling to me that people give ALL their password to a third party, commercial, organization...

This. And their business model is literally to convince people to trust them with their most valuable secrets. Behold the power of marketing.

Re: Lastpass Security Incident

#167

And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…

I haven't touched KeePass in a while(especially since it always had its quirks outside of Windows, being .NET), but KeePassXC which started as a merger of all the various patches to KeepassX(the QT implementation), has been very active. It has a more secure browser integration than the original had, although it's worth noting that nothing ever came close to the accuracy of 1Password when it comes to website quirk integration[1]. There's also TouchID, OTP, better encryption and Yubikey integration of the top of my list.

I'd suggest using it in conjunction with Keepass2Android and KyPass(on iOS, someone mentioned Strongbox), although the Keepass2Android syncs and merges properly and the iOS does not.

[1] https://keepassxc.org/project/

Re: Lastpass Security Incident

#168

And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…

I keep them local too, but I haven't found a solution on how to keep my laptop and phone in sync. It is not fun having to type a 30+ character password consisting uppercase+lowercase letters, numbers and special characters on a mobile device. But it has helped me to keep my phone clutter free, so maybe there's an upside to it too :)

I use a combination of a local only solution for the "master list" of passwords that I backup to cloud storage (which is not synced to my phone) in conjunction with the saved passwords & sync capabilities of Firefox for accessing it on my phone. Occasionally I'll be in a position where I'm on my phone and Firefox doesn't happen to have my latest password saved, so I just initiate a password reset for whatever that service is, set it to a new password, and then circle back later when I'm back on my machine to update my local only storage solution. It's not the most streamlined and user friendly, but it works well enough.

Re: Lastpass Security Incident

#170

Earlier quoted context omitted.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.

I have a small orange password book… oddly. If that gets stolen I think I’d be in big trouble. However it doesn’t have my email address in it. Answers to those inquisitions of a password reset nature are within.
Post reply on HN