Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

181–190 of 587 posts

Re: Lastpass Security Incident

#182
post #124
post #116

Never using online password manager is a good start. Only use encrypted local password manager preferably on encrypted file system and never use same passwords and emails. Best have seperate emails at least for the most important data. Also generating random 50+ alpha-numeric-symbols.

Easier said than done, sadly.

The pass command makes this significantly easier:

https://www.passwordstore.org/

There's even a decent Android client:

https://github.com/android-password-store/Android-Password-S...

Re: Lastpass Security Incident

#183

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

This really hurt me last year, when I migrated away. I didn't realize at the time how much didn't come with, so I've been playing the reset / recovery game since.

Re: Lastpass Security Incident

#184
The best is to use something like Keepassxc, synced peer to peer by Synchting or Resilio. Nobody will be involved with your passwords.

Keepassxc supports Yubikey, so you can lock it down strongly!

Re: Lastpass Security Incident

#186
post #69

What does the hacker news community think about Google Chrome's internal password manager?

The one where you can just launch chrome and click the eyeball icon to see what the password is? Or does chrome have something fancier I am not aware of?

Usually requires a system password to actually see them.

Re: Lastpass Security Incident

#187
post #43

Kudos to the CEO for disclosing this as it's happening and writing the post. This disclosure post is direct, forthright about what's known, specific about engaging help, and explicit about notifying people as more happens. Hacking sucks, but the CEO's post is IMHO on the right track.

(this subthread was originally part of https://news.ycombinator.com/item?id=33809508, but we merged the comments hither)

Re: Lastpass Security Incident

#188
post #22

Earlier quoted context omitted.

Most of them are build without having decrypted passwords or keys for them on server, so attacker would need to get to the point where they can craft malicious update to the client (or exploit the client)

1. Get access to build infrastructure (e.g. via supply chain attack) 2. Inject code in build to export user's passwords to remote server after update is installed

Worth noting that open-source projects where your password store is saved locally are vulnerable to the same attack.

Re: Lastpass Security Incident

#189
post #66

Earlier quoted context omitted.

i use diceware. my mothers maiden name is sternness-ardently, and i am a proud graduate of blade-purge-satin-dash elementary! …apparently.

blade-purge sounds like a good name for a metal band

Did that dude just tell you she likes cloth?

Re: Lastpass Security Incident

#190

Great, now I'm going to have to rename my dog.

I never pick a real answer to my security questions. It just seems pointlessly dangerous.

Years ago for my university student account, you were allowed to provide the question. I figured I would never need to use it, so I set the question to "Dicks?". I was very immature and thought that was funny.

A few years later after the semester break I forgot my password. I had to email IT to reset it, and they replied "Please provide the answer to your security question: Dicks?". And I had to reply "Yes no problem, the answer is Dicks". It was an awkward email exchange, but in my defence I had immediately remembered the answer so it served its purpose.

Post reply on HN