Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

351–360 of 587 posts

Re: Lastpass Security Incident

#351

Earlier quoted context omitted.

Also if you try to export multiple times it will start spitting out exports full of duplicates. Only safe way is to export right after a fresh session login.

Wow. Is LastPass generally just really bad software? These bugs mentioned in this subthread make it sound like amateur hour.

It's packed with enormous amount of bugs that make the day to day experience terrible.

I want to move but I'm terrified of the export process

Re: Lastpass Security Incident

#352

> was able to gain access to certain elements of our customers’ information This is frustratingly vague. This incident started 4 months ago, and you can't provide any details? If it wasn't such a PITA to move off LastPass, I would do so. They got me.

> If it wasn't such a PITA to move off LastPass, It's really not. As the quality of their software declined severely starting around 4-5 years ago, I put off moving because I assumed it would be a huge hassle. It turned out to be surprisingly easy. I have since deleted my LastPass account and wouldn't trust that company to mop my floors.

I don‘t think the quality of the product was any better previously; they were the first to offer cloud hosted password management as far as I remember and that, plus being cheaper than 1Password last time I compared, are their only benefits in my opinion.

Re: Lastpass Security Incident

#353

Earlier quoted context omitted.

There was a blog post on HN a few days ago by someone who taught himself programming during covid and landed senior roles (multiple, simultaneously, by lying to the employers).

Do you have the link?

It was this story, but the actual post is gone:

https://news.ycombinator.com/item?id=33739094

It's still archived, though:

https://web.archive.org/web/20221119032911/https://overemplo...

and

https://web.archive.org/web/20221116023708/https://overemplo...

Key takeaways:

> I started learning to code in 2019 as my new years resolution.

> Job #1 Senior front end dev

> Job #2 Senior front end engineer

> Job #3 Front end engineer (mid-level)

Re: Lastpass Security Incident

#354
post #317

Product idea! A little e-ink display (let's call it a Password Storage Device or PSD) with a tiny processor and enough memory to store all your passwords. Make them cheap enough that you can have a few redundant copies in various places. - OS sees the device as a keyboard - Two versions. One with bluetooth, and one with only USB for a little more security. - Open source software package to sync your collection of PSD…

Isn’t this a yubikey? Except a yubikey can also do a lot more, primarily sign tokens without private key ever leaving the device. Which, as someone else explained below, is far superior to plain text passwords.

Yubikey is really great, but it's for 2FA, not password storage. My thought was to replace cloud password managers.

Re: Lastpass Security Incident

#355
A couple of days ago some of my sensitive information (stored in LastPass) was used trying to access different services. I‘m still trying to identify how the data got breached.

Re: Lastpass Security Incident

#356

Earlier quoted context omitted.

You laugh at that coding assignment for a senior position but you'd be surprised how many "senior" people interview that would struggle with that and be unable to complete it.

I'm currently doing interviews for a senior firmware dev position and was stunned by this. Today I talked to a guy who couldn't tell me what an interrupt was in any technical detail. His coding was worse than a first year college students. 5 of the 6 people I've talked to so far bombed the coding portion.

This isn't intended as a rebuttal, but I've learned to stay away from deeply technical questions in embedded. As long as the interviewee is sufficiently paranoid about C, is recognizably experienced via conversation, and knows the basic concepts I don't press too hard on their specific skillset.

There are just too many niches where the knowledge we each consider necessary simply isn't. I had one particularly bad interviewer grill me on how the ARM GIC worked in detail (e.g. interconnect details, differences between versions, etc) because they considered it basic knowledge. I've personally never needed to know anything about it that wasn't in a TRM.

Re: Lastpass Security Incident

#357
post #184

The best is to use something like Keepassxc, synced peer to peer by Synchting or Resilio. Nobody will be involved with your passwords. Keepassxc supports Yubikey, so you can lock it down strongly!

Do you not suggest using Dropbox to sync KeePassXC? Their FAQ on site seems to support (and encourage?) the use of Dropbox for syncing.

Syncing with Dropbox worked well for me. When you deal with an adversarial server holding your ciphertexts, you have to be a bit careful with the encryption. But keepass is good, AFAIK.

Syncthing improves the security, for instance, just in case a vulnerability creeps into the keepass code.

Re: Lastpass Security Incident

#358

Earlier quoted context omitted.

You laugh at that coding assignment for a senior position but you'd be surprised how many "senior" people interview that would struggle with that and be unable to complete it.

It's a great way to weed out the junior devs that cheated their way through school (or are too dumb to figure it out via stackoverflow) and the senior devs that haven't actually done any real programming in a long time. An engineer at our competitor got laid off and my PM found out and hired the guy to do FPGA work. My PM knew the guy through some contracts we had with the competitor and assumed he was an expert in t…

I am one of those people who just won't exaggerate or lie on my CV or during an interview. I say "i'm not sure, i'd google it the first couple times it came up". I'm not a programmer though. I have a weird skillset that doesn't mesh or gel with what recruiters are looking for, so on the rare occasion i get a recruiter on the phone, i tend to get a job offer at the end of the sequence.

I've had a few startup jobs, a couple megacorp jobs (not Apple), and a handful of mom and pop and defunct business jobs as well.

My least favorite interview questions involve regex or deep internals of BSD or Linux, my favorite interview questions are off the cuff solutions to problems presented, and then backtracking the explanation.

I've also been asked to perform job interviews for positions that i probably ought know enough about to interview a candidate for, but I went off my gut feeling about how the person acted in what i consider a stressful situation (a slew of interviewers asking asinine questions). I don't like interviewing, i am not very good at finding candidates that are "in for the long haul" but every time we were tasked with finding someone who can do X before end of Q3, my hired candidate recommendations always nailed it in that time frame. All this is to say, i find the whole process ridiculous. My CV apparently looks like a train wreck. I refuse to wear a tie or get a haircut. I'm eerily relaxed in interview situations.

My trick? one time i hung out with a CEO of an IT company from the PNW, and they basically told me everything i thought i knew was trash, my resume was trash, my attitude was trash, and the only thing i was good at was solving problems in a hurry. We did, in fact, get coffee for our meetup. I scrapped every idea of what a resume should look like - what i envisioned a perfect professional resume looked like - and started fresh. I learned to say no to most recruiters in a way that made them ask me about different "opportunities" more aligned with my personal ethics and values in the future.

I have 4 FPGAs, and i've never done anything with them, because the bitstream is proprietary on all of them. I wouldn't hesitate to tell an interviewer that i am interested in FPGAs and custom ASICs, because i am. I'm also interested in bacteria, but i won't be applying to a bioscience lab anytime soon. I certainly wouldn't say "yeah i can program an FPGA", or C, or do front end development, or any of that.

From my reading of these sorts of comments, in aggregate, most people try to impress the interviewers. I want them to impress me.

Does this make me privileged? Probably.

Re: Lastpass Security Incident

#359

Earlier quoted context omitted.

Is there a web UI ? If yes - I guess an attacker can just send "bad" JS to the client and steal the master password no? Or inject a malicious update. Most people probably have auto updates?

Yes, this is one of the concerns. In theory a browser addon should take a while for the bad guys to update and publish, but are the existing addons downloading and using server-provided JS? One would hope not, but that's hardly a safe assumption these days. I know Mozilla takes a pretty hard stance against this sort of thing, but it's not all caught in review. And then there's the electron style apps - those should b…

> are the existing addons downloading and using server-provided JS? One would hope not, but that's hardly a safe assumption these days

This reminds me of a very brief security review I did of a 3rd-party browser extension that was being installed on everybody's laptop at a previous job. The extension itself had very little code, it was just something that bootstrapped with code from the company's servers. There was no real way to review it or freeze a reviewed version.

The kicker was that the server-provided JS was being loaded over plain http (and no, nothing was checking signatures or anything like that).

Re: Lastpass Security Incident

#360

Earlier quoted context omitted.

> But shouldn't a blacksmith be able to make a nail before he makes me a suit of armor? Yes. But I think there's a reasonable upper limit to the amount of time a company can expect someone to spend on a job opportunity. If they're burning an appreciable amount of that time on a trivial coding exercise, that's not great.

!!! You're missing the point. The premise is that someone capable can blast through trivial assignments in no time. Either this is the final proficiency challenge or there are subsequent, harder questions. In the former case, why not see the salary/offer and then decide?

Typically, because one has other opportunities that are no less compelling and where potential employers show respect for candidates' time.

I have a GitHub profile with a lot of code on it and on my resume I highlight projects I've done a lot of work on. "What if faked tho?"--there's literally too much there to be worth faking. If a hiring manager looks at my resume, has the option of going to my GitHub profile, and between the two goes "I'm going to hand him a college-level Java problem because I'm not sure," then there probably isn't a way we're going to work together. And that's okay, on both sides of it; there are a lot of developers who aren't bothered by that kind of low-trust relationship. I am. Not a fit.

(This is in contrast to, for example, asking a question like that during an interview. Interviews are bidirectional, and are showing an investment in the hiring process on the part of the employer. If a card-deck Java problem is worth addressing with my time, then it's worth addressing with your interviewer's time. The contrapositive is also true.)

Post reply on HN