Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

401–410 of 587 posts

Re: Lastpass Security Incident

#401
post #226

I once started an interview process as a senior developer at Goto, the company behind LastPass. The contact was a first phone call where someone simply asked the number of experience I had in software development, Java programming, etc. I thought it was weird that basically all they got from the phone call was a bunch of numbers. The weirdest part tho what that they asked how many years of experience I had in... open…

This type of self-referencing and self-congratulatory comment is what makes this website worse and worse little by little. You don't add any meaningful information or knowledge and it is something shallow a kid would say to look cool in front of his friends. I am not attacking you, you can do better.

I disagree. The information "Goto has obviously horrible hiring tactics that select Programming-101-graduates for senior positions WHILE operating a security-sensitive product" is meaningful.

Re: Lastpass Security Incident

#402
post #226

I once started an interview process as a senior developer at Goto, the company behind LastPass. The contact was a first phone call where someone simply asked the number of experience I had in software development, Java programming, etc. I thought it was weird that basically all they got from the phone call was a bunch of numbers. The weirdest part tho what that they asked how many years of experience I had in... open…

This type of self-referencing and self-congratulatory comment is what makes this website worse and worse little by little. You don't add any meaningful information or knowledge and it is something shallow a kid would say to look cool in front of his friends. I am not attacking you, you can do better.

Are you sure you are not talking about yourself? Also, simply writing "I am not attacking you" at the end of an attack doesn't help either.

Re: Lastpass Security Incident

#403
post #151
post #20

Someday one of these password managers is going to be hacked wide open and it is NOT going to be pretty.

There were rumors a couple years ago that this already happened to one of them. My layperson's armchair guess is that a successful attacker would probably seek to keep it quiet. If you were a bad person, and you got access of tons of credentials from one of the major trust-us password managers, would you: 1. Focus on finding and looting big-payout cryptocurrency stashes, as quietly as you can (so you can keep doing i…

Most hacks, these days, seem to fall into one of three categories:

1. State actors

2. For profit criminals

3. Teens for lulz and street cred

I guess the first group would probably keep it pretty quiet. The second would keep it quiet until they've abused the data as much as they want to, then sell the remainder on the dark web. The third would make a big noisy mess right away.

Re: Lastpass Security Incident

#404

Earlier quoted context omitted.

This type of self-referencing and self-congratulatory comment is what makes this website worse and worse little by little. You don't add any meaningful information or knowledge and it is something shallow a kid would say to look cool in front of his friends. I am not attacking you, you can do better.

Reflect on the reasons why you’ve just written this very comment. You might be surprised.

I was going to post a comment but I decided it didn’t add much. Maybe if we all refrain from liberal posting it would remove the need to post comments asking for better comments. I’m not sure. I may post too liberally myself.

Re: Lastpass Security Incident

#405

Earlier quoted context omitted.

This type of self-referencing and self-congratulatory comment is what makes this website worse and worse little by little. You don't add any meaningful information or knowledge and it is something shallow a kid would say to look cool in front of his friends. I am not attacking you, you can do better.

I disagree. The information "Goto has obviously horrible hiring tactics that select Programming-101-graduates for senior positions WHILE operating a security-sensitive product" is meaningful.

From 3 lines written by someone on some social media site you can infer something is true and a fact? ~Cool!~

Re: Lastpass Security Incident

#406

Earlier quoted context omitted.

Considering that 99% of web app password authentication reduces to email authentication via ‘forgot password’, a good first step would be dropping the password and just using emailed tokens (or links) directly.

When I was studying we had to use the computers in uni when presenting homework. It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells). Unfortunately google requires either their app or SMS. They dropp…

> Unfortunately google requires either their app or SMS. They dropped pure totp for some reason.

Gmail TOTP still works fine?

Re: Lastpass Security Incident

#407
post #226

I once started an interview process as a senior developer at Goto, the company behind LastPass. The contact was a first phone call where someone simply asked the number of experience I had in software development, Java programming, etc. I thought it was weird that basically all they got from the phone call was a bunch of numbers. The weirdest part tho what that they asked how many years of experience I had in... open…

Plot twist, you didn't know how to implement inheritance properly in Java therefore you withdrew your application.

Re: Lastpass Security Incident

#408

Earlier quoted context omitted.

I disagree. The information "Goto has obviously horrible hiring tactics that select Programming-101-graduates for senior positions WHILE operating a security-sensitive product" is meaningful.

From 3 lines written by someone on some social media site you can infer something is true and a fact? ~Cool!~

There are so much bad hiring practices in our industry that I indeed choose to trust the rare companies that do it right over the ones that cargo cult Google brain teaser questions, make you implement quicksort on a whiteboard, give you a take-home project that will take you forever but they will hardly glance at, will stop replying to you because ghosting is good, ...

That's the first impression I get from an unknown company and I decided to trust it.

Re: Lastpass Security Incident

#409

Earlier quoted context omitted.

This sub-thread was talking about "that specific coding task", not about binary tasks [edit: trees] in general. You might be very valuable building, say, a database application, while not being able to balance a binary tree, but if you can't do whatever we can all come up with as a small coding assessment (" little deck of cards"). It sounds to me like a good first filter, plus then a good talking piece to have a con…

Ya, my bad (and also to your sibling comment), I have trouble with HN comment depth sometimes. Although I experienced recently what you said exactly! I was asked to build a deck of cards for the screening interview. It was a fun back-and-forth and I felt really good about things. Then in the next steps, I was asked to implement Conway's Game of Life. So like, I've been programming professionally for 13 years, I'm wel…

Did they tell you to implement “Conway's Game of Life” in that many words, or they gave you the rules they wanted to implement?

If the first, that sounds like a terrible question. If the second, that sounds like a quite straightforward fizbuz style coding task.

> I'm well aware of GoL and maybe should know how to do it

What do you mean “should know how to do it”? I don’t think you should have memorised the rules, or an implementation. But I think if you are a software developer you should be able to turn human language into code. That is a key skill of the job.

Re: Lastpass Security Incident

#410
post #255
post #136

Earlier quoted context omitted.

Far better than the blog post, which leaves out crucial info.

Just read it looking for that extra info and not seeing it? the blog post and this article seem to have the identical information in them. The blog post is in a series, so for background on the "four days in august" you can scroll down. it's certainly not acceptable that all they are saying is "certain elements of our customers’ information." very unacceptable, if it's credit card numbers or home addresses, they have…

Nah, the blog post was eventually updated with all the missing information. The updates weren't there when I originally commented.
Post reply on HN