Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

251–260 of 587 posts

Re: Lastpass Security Incident

#251
post #192

Earlier quoted context omitted.

Are you talking about 1Password? What makes you think that?

No idea what they are talking about, or why they feel the need to withhold information, but a quick search turned up this interesting comment: https://www.reddit.com/r/1Password/comments/lkfg5p/what_happ...

Meh. There's a zillion other ways for someone to get a password other than a major breach. Random speculation on Reddit doesn't mean jack shit.

Re: Lastpass Security Incident

#252

I know people will deny it but don't underestimate security by obscurity. Why use the most well known password manager which is a huge target for nation states everywhere? Nobody is attacking my provider (which I won't say)

nation states? lol.

I would rather use the most popular password manager that's been audited, and never had a hack (1Password).

Then we have your "less well known" provider. They have probably outsourced their dev work to cheapest Indian firm they could find.

So I guess congrats on your data being public?

Re: Lastpass Security Incident

#253
post #184

The best is to use something like Keepassxc, synced peer to peer by Synchting or Resilio. Nobody will be involved with your passwords. Keepassxc supports Yubikey, so you can lock it down strongly!

Do you not suggest using Dropbox to sync KeePassXC? Their FAQ on site seems to support (and encourage?) the use of Dropbox for syncing.

Re: Lastpass Security Incident

#254

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

Also if you try to export multiple times it will start spitting out exports full of duplicates. Only safe way is to export right after a fresh session login.

Re: Lastpass Security Incident

#255
post #136

The Verge has more information [1] "This comes just months after LastPass confirmed that hackers had stolen some of its source code in August and had access to LastPass’ internal systems for four days before getting detected. It looks like this new attack is connected, as Loubba says it determined that hackers gained access to user data “using information obtained in the August 2022 incident.”" https://www.theverge.c…

Far better than the blog post, which leaves out crucial info.

Just read it looking for that extra info and not seeing it? the blog post and this article seem to have the identical information in them. The blog post is in a series, so for background on the "four days in august" you can scroll down.

it's certainly not acceptable that all they are saying is "certain elements of our customers’ information." very unacceptable, if it's credit card numbers or home addresses, they have to reveal that. the current language makes it look like they want to hide some kind of very bad news which is worse. Also their August post indicated that the developer account that was compromised had no access to customer data, so why exactly was that wrong.

Re: Lastpass Security Incident

#256
post #139

Is there a better cloud-based alternative to LastPass? I see KeePass being mentioned but I’m not interested in the keeping devices in sync myself.

I can never recommend 1Password enough. When it comes to hosted options, they are hands down the best. Worth pointing out that they also have integrated 2FA, if you're satisfied with first and second factor living in the same spot. https://1password.com

What exactly about 1Password is safer, including their cloud hosted options?

Curious as I may switch.

Re: Lastpass Security Incident

#257
post #139

Is there a better cloud-based alternative to LastPass? I see KeePass being mentioned but I’m not interested in the keeping devices in sync myself.

I can never recommend 1Password enough. When it comes to hosted options, they are hands down the best. Worth pointing out that they also have integrated 2FA, if you're satisfied with first and second factor living in the same spot. https://1password.com

What exactly about 1Password is safer, including their cloud hosted options?

Curious as I may look at multiple options.

Re: Lastpass Security Incident

#258
post #241
post #184

The best is to use something like Keepassxc, synced peer to peer by Synchting or Resilio. Nobody will be involved with your passwords. Keepassxc supports Yubikey, so you can lock it down strongly!

Yubikeys (and more generally CTAP) do not really help with locking down local password managers. The KeePassXC FAQ even explicitly explains that.

From the KeePassXC FAQ: "Additionally, you can use a key file filled with an arbitrary number of random bytes or a YubiKey to further enhance your master key"

https://keepassxc.org/docs/#faq-keepassx

Re: Lastpass Security Incident

#259
post #60

Earlier quoted context omitted.

I generate the password and stored them in my password manager under the notes. 1Password added functionality seemingly recently to add security questions and generate a random word string that I use these days.

I hate password managers. They sign you out way too often and god forbid you’re on another PC.

You can set how often they log you out, and I have a phone...

Re: Lastpass Security Incident

#260
post #232

Earlier quoted context omitted.

How much should you worry about security with a setup like this? I have reasonable Linux skills, but I wouldn’t want my VM to get pwned because I forgot to update it.

Honestly I don't even bother with hosting it in a cloud instance. I host Bitwarden on my home network, and whenever one of my devices opens the Bitwarden browser plugin or mobile app (at home), it will automatically sync everything. From that point on you can continue using Bitwarden without it needing to connect to the server. So on one hand, I lose the ability to sync when I'm not on my home network. On the other h…

and what if your TV or thermostat, with access to your private network, gets compromised? do you have that machine locked down good enough to protect against an inside-the-firewall attack?
Post reply on HN