Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

301–310 of 587 posts

Re: Lastpass Security Incident

#301
There’s something hilarious about reading their blog to understand what has happened from their side, to getting this wonderfully annoying pop up urging me to sign up to their newsletter multiple times:

> JOIN OUR NEWSLETTER

> Enter your email for updates from the LastPass Blog.

Re: Lastpass Security Incident

#302

> We recently detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo. We immediately launched an investigation, engaged Mandiant, a leading security firm, and alerted law enforcement. EXACTLY why so many companies opt to stay on-prem, to the amazement and bewilderment of every vendor sales rep that calls on the phone. Go ahead and ask t…

LastPass blog post on Sept 15 said the hack was accomplished with a compromised developer machine:

> Our investigation determined that the threat actor gained access to the Development environment using a developer’s compromised endpoint. While the method used for the initial endpoint compromise is inconclusive, the threat actor utilized their persistent access to impersonate the developer once the developer had successfully authenticated using multi-factor authentication.

This is similar to other recent hacks, e.g. where a crypto company was hacked when a developer opened a malicious PDF he thought was a job offer.

So, in other words, being on cloud vs. on prem, and potential supply chain hacks, had nothing to do with it.

So sick and tired of everyone jumping to conclusions to fit their preconceived notions of what is good/bad when it comes to security.

Re: Lastpass Security Incident

#303

Earlier quoted context omitted.

But shouldn't a blacksmith be able to make a nail before he makes me a suit of armor?

> But shouldn't a blacksmith be able to make a nail before he makes me a suit of armor? Yes. But I think there's a reasonable upper limit to the amount of time a company can expect someone to spend on a job opportunity. If they're burning an appreciable amount of that time on a trivial coding exercise, that's not great.

!!!

You're missing the point.

The premise is that someone capable can blast through trivial assignments in no time. Either this is the final proficiency challenge or there are subsequent, harder questions. In the former case, why not see the salary/offer and then decide?

Re: Lastpass Security Incident

#304
post #294

How does LastPass implement their security challenge, where they rate your passwords and compare them to known mass password leak incidents? Does that require an upload of plaintext passwords to the server?

Not sure why you would think that was necessary or at all likely. We have these things called hashes...

that doesn't explain anything. they shouldn't be uploading unsalted hashes either. and if it's salted, it won't match with any database

Re: Lastpass Security Incident

#305

Earlier quoted context omitted.

You laugh at that coding assignment for a senior position but you'd be surprised how many "senior" people interview that would struggle with that and be unable to complete it.

No doubt when GP refused to complete the coding assessment the people who designed it thought “aha! Yet another non-coder filtered out by our process!”

Why limit it there?

Add "This person doesn't know about my firm's hiring process, aren't willing to do basic tasks, doesn't want to work at my firm," etc.

Re: Lastpass Security Incident

#306
post #285

Earlier quoted context omitted.

Post-It notes are a safer option than password managers. And it's absolutely outrageous to say this: But not every single account you have needs a unique password. Just ones which can actually allow someone to impersonate you meaningfully, cost you money, or gather sensitive data about you. Response to @palata because of rate-limiting: The problem is people tend not to only put unimportant accounts in their password…

Where do you store your TOTP tokens, then? Post It note?

Definitely not where you store your passwords! In my case, since I don't store my passwords on my phone, I have my TOTP app there, and then for backup, I print the QR codes when I set up TOTP and secure them in the physical world. Restoring my 2FA setup to a new phone is easy: I just scan through the stack of paper!

Re: Lastpass Security Incident

#307
post #297

Product idea! A little e-ink display (let's call it a Password Storage Device or PSD) with a tiny processor and enough memory to store all your passwords. Make them cheap enough that you can have a few redundant copies in various places. - OS sees the device as a keyboard - Two versions. One with bluetooth, and one with only USB for a little more security. - Open source software package to sync your collection of PSD…

No offense, but this is such a hacker solution. :) And as mentioned, already exists in many forms. Passwords and login credentials are dead. No user wants to deal with them. Password managers are a solution to somewhat sanely and securely manage this complexity, and not something that the average user wants to think about. In that sense, they don't improve security overall, and introduce many other issues (a centrali…

Considering that 99% of web app password authentication reduces to email authentication via ‘forgot password’, a good first step would be dropping the password and just using emailed tokens (or links) directly.

Re: Lastpass Security Incident

#308

Earlier quoted context omitted.

I have interviewed many “senior” candidates who can’t do simple coding exercises. I think that starting out with a simple exercise like that weeds out a ton of people without putting undue burden on the good developers.

I ask a lot of questions that I preface with: I hope you are slightly insulted by the questions I'm about to ask. They get progressively more complex as we go, but the candidate is fully aware they are filter questions that I hope they clear with zero effort.

I have a series of questions in various areas designed to be in increasing order of difficulty, but I don't expect them to clear them all0-they ramp up to "deep and esoteric knowledge".

When I'm explaining the process I usually preface with these being designed to gauge their skill level, not just make sure they meet some minimum floor, so there are going to be some easy questions and some that are hard and I don't necessarily expect them to answer all of them and not to get discouraged or be afraid to say they don't know. I usually just keep going until they miss a couple in a row.

If someone actually doesn't know the job, I'm only asking maybe 5-10 relatively simple questions and thanking them for their time.

Re: Lastpass Security Incident

#309
post #37
post #33

Earlier quoted context omitted.

Come on now. How is that baffling?

in what other tech stack is it a good idea to have all your eggs in one basket? that's why it's baffling. The convenience is outweighed by the possible loss.

The alternative is spreading your eggs all over the farm, with no way to keep track of where they all are. Many will be put somewhere, then forgotten about.

Do you really think that’s safer?

Re: Lastpass Security Incident

#310

Earlier quoted context omitted.

You laugh at that coding assignment for a senior position but you'd be surprised how many "senior" people interview that would struggle with that and be unable to complete it.

Especially now that the "senior" titled is handed out to people with 3-5 years of experience.

There was a blog post on HN a few days ago by someone who taught himself programming during covid and landed senior roles (multiple, simultaneously, by lying to the employers).
Post reply on HN