Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

371–380 of 587 posts

Re: Lastpass Security Incident

#371
post #338

Earlier quoted context omitted.

I have a different perspective. I feel that specific coding task tells me absolutely nothing about the seniority of the person performing the task and tells me very little about their qualifications.

And it does not have to, that's what the later stages are for. This task is just a pre-filter, something to weed out surpirsingly high number of people who claim to be able to code but actually can't.

Now if we could just standardise this so you didn't have to do several coding assignments for every position you apply for. I'm sure most people needs to apply to more than one company to actually get hired, especially with all the layoffs now.

Re: Lastpass Security Incident

#372
post #78

Earlier quoted context omitted.

This is years ago now, but every ampersand in my passwords came across wrong. I can't recall if it was missing or url encoded, but even passwords weren't safe.

That is especially surprising, considering that passwords are more than likely going to contain special characters.

LastPass's own generator puts them in there.

Re: Lastpass Security Incident

#373

Earlier quoted context omitted.

Uh oh, now I’m paranoid my LastPass export didn’t have everything, and I deleted my account years ago

Personally, I'm more paranoid concerning whether the deletion actually worked when I deleted my LastPass three or four major security incidents ago...

You should probably change all your passwords anyway..

Re: Lastpass Security Incident

#374

Product idea! A little e-ink display (let's call it a Password Storage Device or PSD) with a tiny processor and enough memory to store all your passwords. Make them cheap enough that you can have a few redundant copies in various places. - OS sees the device as a keyboard - Two versions. One with bluetooth, and one with only USB for a little more security. - Open source software package to sync your collection of PSD…

You could have it MITM between your keyboard and computer. Depending on the mode it records your key presses to an entry, or replays an entry. Otherwise it just passes through. Probably just needs a screen and like 3 buttons: record/play/navigate mode (use your keyboard to actually navigate).

That model (with record) would need me to come up with passwords and type them. Seems like a hassle and a security problem.

Re: Lastpass Security Incident

#375
post #226

I once started an interview process as a senior developer at Goto, the company behind LastPass. The contact was a first phone call where someone simply asked the number of experience I had in software development, Java programming, etc. I thought it was weird that basically all they got from the phone call was a bunch of numbers. The weirdest part tho what that they asked how many years of experience I had in... open…

You laugh at that coding assignment for a senior position but you'd be surprised how many "senior" people interview that would struggle with that and be unable to complete it.

And if you think a suit extends card then you’ve violated LSP.

Re: Lastpass Security Incident

#376

Earlier quoted context omitted.

LastPass blog post on Sept 15 said the hack was accomplished with a compromised developer machine: > Our investigation determined that the threat actor gained access to the Development environment using a developer’s compromised endpoint. While the method used for the initial endpoint compromise is inconclusive, the threat actor utilized their persistent access to impersonate the developer once the developer had succ…

You're missing the point entirely. When you're on prem you only have to worry about your own employees opening sketchy PDFs. When you're not, you have to worry about everyone in your supply chain opening sketchy PDFs. Nevermind the fact that the next time a major world conflict occurs, the big 4 cloud providers will probably be destroyed, taking about 90% of the western economy with it.

If a conflict escalates to the point where the cloud providers are destroyed, you’re gonna have bigger worries than that my friend.

Re: Lastpass Security Incident

#377
post #368

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

I'm curious what did people migrate to, and is there any feature disparities?

1Password. The largest feature disparity is 1password is designed and built by competent engineers. The history of breaches and technical mistakes Lastpass has made over the years is amazing for a tech company let alone a password manager.

Re: Lastpass Security Incident

#378

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

Is it obvious that it failed (e.g. displays an error), or does it just silently skip over the entry?

Re: Lastpass Security Incident

#379
post #139

Is there a better cloud-based alternative to LastPass? I see KeePass being mentioned but I’m not interested in the keeping devices in sync myself.

How about https://pwsafe.org/ and their releases on github https://github.com/pwsafe/pwsafe/releases?q=non-windows&expa... ?

Re: Lastpass Security Incident

#380
post #226

I once started an interview process as a senior developer at Goto, the company behind LastPass. The contact was a first phone call where someone simply asked the number of experience I had in software development, Java programming, etc. I thought it was weird that basically all they got from the phone call was a bunch of numbers. The weirdest part tho what that they asked how many years of experience I had in... open…

I did. Interview for AWS principal engineer position and their screening call had a 20 minutes make a code like structure to solve this problem. They did not ask me to write Java or anything compiled but something that shows I can actually turn my idea into some for of code. I think having such kind of question is very much expected and I would wonder if a company does not have it for external/unknown hires.
Post reply on HN