Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

171–180 of 587 posts

Re: Lastpass Security Incident

#171
post #112

And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…

> You just have to deal with the very mild inconvenience of keeping your database synchronized across devices. Which is pretty easy with SyncThing. Other services like Dropbox are also fine if you have a sufficiently high entropy password. The danger isn't in the "online", but a third party being able to decrypt your passwords.

> Which is pretty easy with SyncThing.

That keeps the whole database file synchronized, sure. But KeePass synchronizes at the level of each entry.

Re: Lastpass Security Incident

#172
post #112

Earlier quoted context omitted.

> You just have to deal with the very mild inconvenience of keeping your database synchronized across devices. Which is pretty easy with SyncThing. Other services like Dropbox are also fine if you have a sufficiently high entropy password. The danger isn't in the "online", but a third party being able to decrypt your passwords.

> Which is pretty easy with SyncThing Is SyncThing available for iOS? I thought it wasn’t but I’d love to be wrong.

iOS seems to require some sort of File Provider implementation for syncing, which seems to work anywhere from terrible to mediocre.

But maybe I misunderstand the situation.

Re: Lastpass Security Incident

#173

And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…

I keep them local too, but I haven't found a solution on how to keep my laptop and phone in sync. It is not fun having to type a 30+ character password consisting uppercase+lowercase letters, numbers and special characters on a mobile device. But it has helped me to keep my phone clutter free, so maybe there's an upside to it too :)

I use Syncthing for that. It syncs over my home WiFi network only.

Re: Lastpass Security Incident

#174
post #125

Earlier quoted context omitted.

What's the alternative? 1. Have people manage their own secrets storage? Most people don't have the time or ability do this securely either. I'd rather pay someone else to secure infra, code, distribution, encryption, backups, etc. for me. 2. Reuse the same password on every site? One site gets hacked and now you're screwed. 3. Memorize a unique, long password for every site? Not feasible. Third-party/commercial pass…

The alternative to fully cloud-based solutions would be a local, open source kdbx client (Keepass, KepassXC, etc) with the password database situated on a cloud storage (Dropbox/Google Drive/etc). This way, one gets the best of both worlds.

This can be a nice compromise, but it's not without downsides. Personally, 99% of the authenticated software I use is in my browser, and the usability of an extension that has a little badge to tell me I have an account on this site and autofill capabilities is really tough to pass up. Further, because it's an extension, it can know what site I'm on, which all but eliminates my risk of falling prey to phishing attempts.

Re: Lastpass Security Incident

#175
post #139

Is there a better cloud-based alternative to LastPass? I see KeePass being mentioned but I’m not interested in the keeping devices in sync myself.

Bitwarden is better, but Vaultwarden (the self-hosted version written in Rust) is the absolute best option. Host it yourself on a free tier VM in one of the clouds, configure a backup solution, and never worry about it again. And you don't need to trust anyone with your passwords. Use tailscale if you want to get fancy and keep it off the public internet or go the easy route and install fail2ban and expose it via pub…

Can you give some idea why Bitwarden is better?

Re: Lastpass Security Incident

#176

> was able to gain access to certain elements of our customers’ information This is frustratingly vague. This incident started 4 months ago, and you can't provide any details? If it wasn't such a PITA to move off LastPass, I would do so. They got me.

[deleted]

Re: Lastpass Security Incident

#177
post #112

Earlier quoted context omitted.

> You just have to deal with the very mild inconvenience of keeping your database synchronized across devices. Which is pretty easy with SyncThing. Other services like Dropbox are also fine if you have a sufficiently high entropy password. The danger isn't in the "online", but a third party being able to decrypt your passwords.

> Which is pretty easy with SyncThing Is SyncThing available for iOS? I thought it wasn’t but I’d love to be wrong.

[deleted]

Re: Lastpass Security Incident

#178

Earlier quoted context omitted.

What's the alternative? 1. Have people manage their own secrets storage? Most people don't have the time or ability do this securely either. I'd rather pay someone else to secure infra, code, distribution, encryption, backups, etc. for me. 2. Reuse the same password on every site? One site gets hacked and now you're screwed. 3. Memorize a unique, long password for every site? Not feasible. Third-party/commercial pass…

Passwords suck. Move on to something better.

like what ?

Re: Lastpass Security Incident

#179

And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…

I haven't touched KeePass in a while(especially since it always had its quirks outside of Windows, being .NET), but KeePassXC which started as a merger of all the various patches to KeepassX(the QT implementation), has been very active. It has a more secure browser integration than the original had, although it's worth noting that nothing ever came close to the accuracy of 1Password when it comes to website quirk int…

On iOS there is strongbox and keepassium also.

Re: Lastpass Security Incident

#180

Earlier quoted context omitted.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.

answer$(first-word-in-question)
Post reply on HN