Earlier quoted context omitted.
Are you talking about 1Password? What makes you think that?
No idea what they are talking about, or why they feel the need to withhold information, but a quick search turned up this interesting comment: https://www.reddit.com/r/1Password/comments/lkfg5p/what_happ...
Lastpass Security Incident
251–260 of 587 posts
Re: Lastpass Security Incident
#252I know people will deny it but don't underestimate security by obscurity. Why use the most well known password manager which is a huge target for nation states everywhere? Nobody is attacking my provider (which I won't say)
I would rather use the most popular password manager that's been audited, and never had a hack (1Password).
Then we have your "less well known" provider. They have probably outsourced their dev work to cheapest Indian firm they could find.
So I guess congrats on your data being public?
Re: Lastpass Security Incident
#253The best is to use something like Keepassxc, synced peer to peer by Synchting or Resilio. Nobody will be involved with your passwords. Keepassxc supports Yubikey, so you can lock it down strongly!
Re: Lastpass Security Incident
#254Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!
Re: Lastpass Security Incident
#255The Verge has more information [1] "This comes just months after LastPass confirmed that hackers had stolen some of its source code in August and had access to LastPass’ internal systems for four days before getting detected. It looks like this new attack is connected, as Loubba says it determined that hackers gained access to user data “using information obtained in the August 2022 incident.”" https://www.theverge.c…
Far better than the blog post, which leaves out crucial info.
it's certainly not acceptable that all they are saying is "certain elements of our customers’ information." very unacceptable, if it's credit card numbers or home addresses, they have to reveal that. the current language makes it look like they want to hide some kind of very bad news which is worse. Also their August post indicated that the developer account that was compromised had no access to customer data, so why exactly was that wrong.
Re: Lastpass Security Incident
#256Is there a better cloud-based alternative to LastPass? I see KeePass being mentioned but I’m not interested in the keeping devices in sync myself.
I can never recommend 1Password enough. When it comes to hosted options, they are hands down the best. Worth pointing out that they also have integrated 2FA, if you're satisfied with first and second factor living in the same spot. https://1password.com
Curious as I may switch.
Re: Lastpass Security Incident
#257Is there a better cloud-based alternative to LastPass? I see KeePass being mentioned but I’m not interested in the keeping devices in sync myself.
I can never recommend 1Password enough. When it comes to hosted options, they are hands down the best. Worth pointing out that they also have integrated 2FA, if you're satisfied with first and second factor living in the same spot. https://1password.com
Curious as I may look at multiple options.
Re: Lastpass Security Incident
#258The best is to use something like Keepassxc, synced peer to peer by Synchting or Resilio. Nobody will be involved with your passwords. Keepassxc supports Yubikey, so you can lock it down strongly!
Yubikeys (and more generally CTAP) do not really help with locking down local password managers. The KeePassXC FAQ even explicitly explains that.
Re: Lastpass Security Incident
#259Earlier quoted context omitted.
I generate the password and stored them in my password manager under the notes. 1Password added functionality seemingly recently to add security questions and generate a random word string that I use these days.
I hate password managers. They sign you out way too often and god forbid you’re on another PC.
Re: Lastpass Security Incident
#260Earlier quoted context omitted.
How much should you worry about security with a setup like this? I have reasonable Linux skills, but I wouldn’t want my VM to get pwned because I forgot to update it.
Honestly I don't even bother with hosting it in a cloud instance. I host Bitwarden on my home network, and whenever one of my devices opens the Bitwarden browser plugin or mobile app (at home), it will automatically sync everything. From that point on you can continue using Bitwarden without it needing to connect to the server. So on one hand, I lose the ability to sync when I'm not on my home network. On the other h…