Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

411–420 of 587 posts

Re: Lastpass Security Incident

#411

Earlier quoted context omitted.

Sounds silly, it’s a shame you didn’t get past the initial screen. It’s a process that has to be humored and you could have added a lot of value just by joining and then patching their hiring process. When I was teaching in high school the deck-modelling thing is one that the kids come up with a lot especially when it came to doing their term project. I love the idea of being asked to implement a deck of cards using…

Unfortunately you have been rejected due to: a 'SyntaxError: invalid character in identifier'. Better luck at your next interview ;-)

This interview is for Goto, not Google I believe.

Re: Lastpass Security Incident

#412

Earlier quoted context omitted.

From 3 lines written by someone on some social media site you can infer something is true and a fact? ~Cool!~

There are so much bad hiring practices in our industry that I indeed choose to trust the rare companies that do it right over the ones that cargo cult Google brain teaser questions, make you implement quicksort on a whiteboard, give you a take-home project that will take you forever but they will hardly glance at, will stop replying to you because ghosting is good, ... That's the first impression I get from an unknow…

Most things are cargo cults anyway, I wouldn't worry too much.

This company doesn't seem to follow the ways of the cult though, that's the concern.

Re: Lastpass Security Incident

#413

Earlier quoted context omitted.

Wow. Is LastPass generally just really bad software? These bugs mentioned in this subthread make it sound like amateur hour.

It's packed with enormous amount of bugs that make the day to day experience terrible. I want to move but I'm terrified of the export process

I moved to BitWarden a year ago after a billing problem with LastPass that their support handled badly. I haven't had any problems with the migrated data and I finally deleted my LastPass account last month.

Re: Lastpass Security Incident

#414

Earlier quoted context omitted.

FizzBuzz interview questions are fair game[0] , especially if you're not networking in via referrals and are 1/5000 online applicants like the parent. [0] https://www.joelonsoftware.com/2006/10/25/the-guerrilla-guid...

Pretty much. I hold the record for our coding question in my company - 3 minutes and 54 seconds. Granted, I'm one of the two people that put the question together, but still. We've had candidates with "20 years of experience" completely unable to do what amounts to "call a web service, deserialize some json, write a couple for loops and if statements, and post back some json to a web service" in over an hour, or in a…

To be fair: it might be they have never done this before.

At my previous company, we had a technical assessment - this was about ten years ago now. It boiled down to: read XML, do some math / business logic, and build a REST API to do so.

Interestingly, ten years ago, at least half the applicants said they found it interesting because they had never worked with REST or JSON before. A lot were Java developers, so the XML part wasn't a problem, and they would often add some SQL database as a bonus.

But 5-10 years later, as development switched to (Node)JS and web, it became the inverse and people said they had never done anything with XML before.

Re: Lastpass Security Incident

#415

Earlier quoted context omitted.

That is especially surprising, considering that passwords are more than likely going to contain special characters.

Avoid such trouble is why I want to avoid using symbols for password. Just use more alphanum characters for strength.

Or just use proper tools that work.

Re: Lastpass Security Incident

#416
post #226

I once started an interview process as a senior developer at Goto, the company behind LastPass. The contact was a first phone call where someone simply asked the number of experience I had in software development, Java programming, etc. I thought it was weird that basically all they got from the phone call was a bunch of numbers. The weirdest part tho what that they asked how many years of experience I had in... open…

This type of self-referencing and self-congratulatory comment is what makes this website worse and worse little by little. You don't add any meaningful information or knowledge and it is something shallow a kid would say to look cool in front of his friends. I am not attacking you, you can do better.

What would be better, given the info in their comment is correct?

It’s arguable whether a simple senior filter and “HR stuff” is a red flag or not, but how does it make this site worse?

Re: Lastpass Security Incident

#417

> We recently detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo. We immediately launched an investigation, engaged Mandiant, a leading security firm, and alerted law enforcement. EXACTLY why so many companies opt to stay on-prem, to the amazement and bewilderment of every vendor sales rep that calls on the phone. Go ahead and ask t…

This + the fact that privacy regulations are on the rise will make SaaS providers adapt to a world where customers data cannot be kept on the SaaS prem.

I would suggest to split this problem into two different problems - the processing ("data in use") vs data on rest. Each of these problems should be tackle with a different solution/approach.

I'm working on the tackling the second approach and if anyone want to talk just reach out (reply/mail/link/whatever you prefer)

Re: Lastpass Security Incident

#418
post #226

I once started an interview process as a senior developer at Goto, the company behind LastPass. The contact was a first phone call where someone simply asked the number of experience I had in software development, Java programming, etc. I thought it was weird that basically all they got from the phone call was a bunch of numbers. The weirdest part tho what that they asked how many years of experience I had in... open…

[deleted]

Re: Lastpass Security Incident

#419
post #226

I once started an interview process as a senior developer at Goto, the company behind LastPass. The contact was a first phone call where someone simply asked the number of experience I had in software development, Java programming, etc. I thought it was weird that basically all they got from the phone call was a bunch of numbers. The weirdest part tho what that they asked how many years of experience I had in... open…

This type of self-referencing and self-congratulatory comment is what makes this website worse and worse little by little. You don't add any meaningful information or knowledge and it is something shallow a kid would say to look cool in front of his friends. I am not attacking you, you can do better.

Honestly his account was helpful. Lax hiring practices seem quite relevant to the security issues being revealed.

However, your comment comes across as an attack intended to maybe silence his experience.

Re: Lastpass Security Incident

#420

Earlier quoted context omitted.

It's packed with enormous amount of bugs that make the day to day experience terrible. I want to move but I'm terrified of the export process

I moved to 1password a few years ago and haven't regretted it for a second. I still have Lastpass installed, but it's probably getting to the point I can delete it.

OK, wait, you still are using some other cloud password provider?
Post reply on HN