Lastpass Security Incident
321–330 of 587 posts
Re: Lastpass Security Incident
#322Earlier quoted context omitted.
Far better than the blog post, which leaves out crucial info.
Just read it looking for that extra info and not seeing it? the blog post and this article seem to have the identical information in them. The blog post is in a series, so for background on the "four days in august" you can scroll down. it's certainly not acceptable that all they are saying is "certain elements of our customers’ information." very unacceptable, if it's credit card numbers or home addresses, they have…
Re: Lastpass Security Incident
#323Will never understand why people use managed password management services when things like the KeePass KDBX format exist.
Multiple devices? Central management? I use KeePass so I don't know, but I assume there are valid reasons
Re: Lastpass Security Incident
#324Earlier quoted context omitted.
Especially now that the "senior" titled is handed out to people with 3-5 years of experience.
There was a blog post on HN a few days ago by someone who taught himself programming during covid and landed senior roles (multiple, simultaneously, by lying to the employers).
Re: Lastpass Security Incident
#325Earlier quoted context omitted.
Not sure why you would think that was necessary or at all likely. We have these things called hashes...
that doesn't explain anything. they shouldn't be uploading unsalted hashes either. and if it's salted, it won't match with any database
Re: Lastpass Security Incident
#326Will never understand why people use managed password management services when things like the KeePass KDBX format exist.
If you wish to understand, all you have to do is ask someone outside the hn-tech-bubble.
Re: Lastpass Security Incident
#327Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!
This is years ago now, but every ampersand in my passwords came across wrong. I can't recall if it was missing or url encoded, but even passwords weren't safe.
Re: Lastpass Security Incident
#328Just in time to give a boost to passkeys. https://fidoalliance.org/passkeys/
These probably won't replace password managers, just result in passkey managers... Dashlane already supports passkeys & 1password just announced intent to support soon.
Re: Lastpass Security Incident
#329Earlier quoted context omitted.
No offense, but this is such a hacker solution. :) And as mentioned, already exists in many forms. Passwords and login credentials are dead. No user wants to deal with them. Password managers are a solution to somewhat sanely and securely manage this complexity, and not something that the average user wants to think about. In that sense, they don't improve security overall, and introduce many other issues (a centrali…
Considering that 99% of web app password authentication reduces to email authentication via ‘forgot password’, a good first step would be dropping the password and just using emailed tokens (or links) directly.
It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells).
Unfortunately google requires either their app or SMS. They dropped pure totp for some reason.
Awful experience.
Re: Lastpass Security Incident
#330> We recently detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo. We immediately launched an investigation, engaged Mandiant, a leading security firm, and alerted law enforcement. EXACTLY why so many companies opt to stay on-prem, to the amazement and bewilderment of every vendor sales rep that calls on the phone. Go ahead and ask t…
LastPass blog post on Sept 15 said the hack was accomplished with a compromised developer machine: > Our investigation determined that the threat actor gained access to the Development environment using a developer’s compromised endpoint. While the method used for the initial endpoint compromise is inconclusive, the threat actor utilized their persistent access to impersonate the developer once the developer had succ…
When you're on prem you only have to worry about your own employees opening sketchy PDFs. When you're not, you have to worry about everyone in your supply chain opening sketchy PDFs.
Nevermind the fact that the next time a major world conflict occurs, the big 4 cloud providers will probably be destroyed, taking about 90% of the western economy with it.