> JOIN OUR NEWSLETTER
> Enter your email for updates from the LastPass Blog.
301–310 of 587 posts
> JOIN OUR NEWSLETTER
> Enter your email for updates from the LastPass Blog.
> We recently detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo. We immediately launched an investigation, engaged Mandiant, a leading security firm, and alerted law enforcement. EXACTLY why so many companies opt to stay on-prem, to the amazement and bewilderment of every vendor sales rep that calls on the phone. Go ahead and ask t…
> Our investigation determined that the threat actor gained access to the Development environment using a developer’s compromised endpoint. While the method used for the initial endpoint compromise is inconclusive, the threat actor utilized their persistent access to impersonate the developer once the developer had successfully authenticated using multi-factor authentication.
This is similar to other recent hacks, e.g. where a crypto company was hacked when a developer opened a malicious PDF he thought was a job offer.
So, in other words, being on cloud vs. on prem, and potential supply chain hacks, had nothing to do with it.
So sick and tired of everyone jumping to conclusions to fit their preconceived notions of what is good/bad when it comes to security.
Earlier quoted context omitted.
But shouldn't a blacksmith be able to make a nail before he makes me a suit of armor?
> But shouldn't a blacksmith be able to make a nail before he makes me a suit of armor? Yes. But I think there's a reasonable upper limit to the amount of time a company can expect someone to spend on a job opportunity. If they're burning an appreciable amount of that time on a trivial coding exercise, that's not great.
You're missing the point.
The premise is that someone capable can blast through trivial assignments in no time. Either this is the final proficiency challenge or there are subsequent, harder questions. In the former case, why not see the salary/offer and then decide?
How does LastPass implement their security challenge, where they rate your passwords and compare them to known mass password leak incidents? Does that require an upload of plaintext passwords to the server?
Not sure why you would think that was necessary or at all likely. We have these things called hashes...
Earlier quoted context omitted.
You laugh at that coding assignment for a senior position but you'd be surprised how many "senior" people interview that would struggle with that and be unable to complete it.
No doubt when GP refused to complete the coding assessment the people who designed it thought “aha! Yet another non-coder filtered out by our process!”
Add "This person doesn't know about my firm's hiring process, aren't willing to do basic tasks, doesn't want to work at my firm," etc.
Earlier quoted context omitted.
Post-It notes are a safer option than password managers. And it's absolutely outrageous to say this: But not every single account you have needs a unique password. Just ones which can actually allow someone to impersonate you meaningfully, cost you money, or gather sensitive data about you. Response to @palata because of rate-limiting: The problem is people tend not to only put unimportant accounts in their password…
Where do you store your TOTP tokens, then? Post It note?
Product idea! A little e-ink display (let's call it a Password Storage Device or PSD) with a tiny processor and enough memory to store all your passwords. Make them cheap enough that you can have a few redundant copies in various places. - OS sees the device as a keyboard - Two versions. One with bluetooth, and one with only USB for a little more security. - Open source software package to sync your collection of PSD…
No offense, but this is such a hacker solution. :) And as mentioned, already exists in many forms. Passwords and login credentials are dead. No user wants to deal with them. Password managers are a solution to somewhat sanely and securely manage this complexity, and not something that the average user wants to think about. In that sense, they don't improve security overall, and introduce many other issues (a centrali…
Earlier quoted context omitted.
I have interviewed many “senior” candidates who can’t do simple coding exercises. I think that starting out with a simple exercise like that weeds out a ton of people without putting undue burden on the good developers.
I ask a lot of questions that I preface with: I hope you are slightly insulted by the questions I'm about to ask. They get progressively more complex as we go, but the candidate is fully aware they are filter questions that I hope they clear with zero effort.
When I'm explaining the process I usually preface with these being designed to gauge their skill level, not just make sure they meet some minimum floor, so there are going to be some easy questions and some that are hard and I don't necessarily expect them to answer all of them and not to get discouraged or be afraid to say they don't know. I usually just keep going until they miss a couple in a row.
If someone actually doesn't know the job, I'm only asking maybe 5-10 relatively simple questions and thanking them for their time.
Earlier quoted context omitted.
Come on now. How is that baffling?
in what other tech stack is it a good idea to have all your eggs in one basket? that's why it's baffling. The convenience is outweighed by the possible loss.
Do you really think that’s safer?
Earlier quoted context omitted.
You laugh at that coding assignment for a senior position but you'd be surprised how many "senior" people interview that would struggle with that and be unable to complete it.
Especially now that the "senior" titled is handed out to people with 3-5 years of experience.