Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

191–200 of 587 posts

Re: Lastpass Security Incident

#191

And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…

> you could still find yourself in a jam if their service goes down

This is true for many password managers that sync with the cloud. I use 1Password and I've made sure that I install apps on at least a couple of devices because the apps a local copy of the password data that can be accessed offline.

I've done that with another password manager that I used in the past too.

I used KeePass in the past and would likely still be using it if I didn't get 1Password free (free family account if your employer has a business account) and if I didn't need to have secure sharing with my wife.

Let me know if you know of a secure, convenient way to share password entries with another person using KeepPass that doesn't involve you sharing the your whole password database. I know you can have yet another password database that only contains shared records... but that definitely fails the convenience factor.

Re: Lastpass Security Incident

#192
post #44

Earlier quoted context omitted.

I don't use them, but my conclusion is that at least one major cloud password manager has been hacked already without any disclosure. If they disclose it, the company should logically be dead. Thus, the incentive would just be to cover it up.

Can you elaborate more? Which? Why do you think this? I also agree with you and I think it’s one that rhymes with shome paus werd. But I think it happened early in their “cloud” journey

Are you talking about 1Password? What makes you think that?

Re: Lastpass Security Incident

#193

And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…

Yes, if you can keep your password local it's still the best option.

Sadly, once your use case becomes complicated and you need to share between devices, and potentially have partial sharing between people (e.g. your spouse, your parents etc.), it becomes a nightmare to manage. In particular trying to explain how sync is supposed to work with a third party on iOS is just pain.

I'm eyeing at self-hosted BitWarden instances, but then I kinda fear to someday be the one shooting myself in the foot and nuking everyone's literally life critical credentials...

Re: Lastpass Security Incident

#194
post #43

Kudos to the CEO for disclosing this as it's happening and writing the post. This disclosure post is direct, forthright about what's known, specific about engaging help, and explicit about notifying people as more happens. Hacking sucks, but the CEO's post is IMHO on the right track.

Hacking is why we’re here. It’s criminal and exploitative behavior that sucks.

Re: Lastpass Security Incident

#195
post #112

And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…

> You just have to deal with the very mild inconvenience of keeping your database synchronized across devices. Which is pretty easy with SyncThing. Other services like Dropbox are also fine if you have a sufficiently high entropy password. The danger isn't in the "online", but a third party being able to decrypt your passwords.

"Other services like Dropbox are also fine if you have a sufficiently high entropy password"

That's why you add that binary key file to the mix that you liberally distribute to all your devices. But that you carefully keep far off your sync platform. The danger of a weak password is when a device falls into the wrong hands, a compromised sync platform is much less of a concern (if the file is in the mix).

Re: Lastpass Security Incident

#196

And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…

I keep them local too, but I haven't found a solution on how to keep my laptop and phone in sync. It is not fun having to type a 30+ character password consisting uppercase+lowercase letters, numbers and special characters on a mobile device. But it has helped me to keep my phone clutter free, so maybe there's an upside to it too :)

As mentioned throughout this thread, Syncthing can seamlessly sync between Android phones and Windows/Linux hosts. There are apps for iOS as well, but they can be a bit more finicky due to Apple's app sandbox implementation.

Re: Lastpass Security Incident

#197

Earlier quoted context omitted.

1. Get access to build infrastructure (e.g. via supply chain attack) 2. Inject code in build to export user's passwords to remote server after update is installed

This is a good point, but on the other hand, couldn't any application be hijacked in the same way to include a keylogger/upload plaintext password DBs stored locally by browsers/etc? Somehow this hasn't happened on a mass scale that I'm aware of.

Not exactly, because the JavaScript code can change and be delivered at ANY time. No code signature verification is involved.

An offline password manager is updated a few times a year, and will go through OS repository distribution, with verification of the signature for changes. Or you can download the software from the source website and check the signature.

Re: Lastpass Security Incident

#198
post #139

Is there a better cloud-based alternative to LastPass? I see KeePass being mentioned but I’m not interested in the keeping devices in sync myself.

I’ll second the 1Password recommendations, it’s fantastic software that is becoming better and better. If you’re comfortable with cloud syncing, I can’t imagine a better option than 1Password.

A top 1Password tip is that the business plans include free family plans for every member, so if you can get your employer to use 1Password then you’ll be able to get your personal account for free (which would include your family, too). A very underrated deal!

I recently logged back into my old LastPass account after 5 years and it was fascinating just how bad it is compared to 1Password.

Re: Lastpass Security Incident

#199
post #139

Is there a better cloud-based alternative to LastPass? I see KeePass being mentioned but I’m not interested in the keeping devices in sync myself.

Enpass may be worth a look.

It doesn't do cloud syncing itself, but it lets you pick from a number of different providers (DropBox, iCloud, OneDrive, plus a few others) which you probably already use.

Re: Lastpass Security Incident

#200

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

Uh oh, now I’m paranoid my LastPass export didn’t have everything, and I deleted my account years ago
Post reply on HN