> was able to gain access to certain elements of our customers’ information This is frustratingly vague. This incident started 4 months ago, and you can't provide any details? If it wasn't such a PITA to move off LastPass, I would do so. They got me.
How is it a PITA to move off lastpass? I switched to Bitwarden and it was a piece of cake. Exported all passwords. Imported all passwords. Pretty much all password managers can import/export as a CSV or similar.
Lastpass Security Incident
421–430 of 587 posts
Re: Lastpass Security Incident
#422Re: Lastpass Security Incident
#423Re: Lastpass Security Incident
#424Earlier quoted context omitted.
These probably won't replace password managers, just result in passkey managers... Dashlane already supports passkeys & 1password just announced intent to support soon.
How do they "manage" passkeys? There's nothing to manage except your fingerprint/face authentication.
Re: Lastpass Security Incident
#425> We recently detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo. We immediately launched an investigation, engaged Mandiant, a leading security firm, and alerted law enforcement. EXACTLY why so many companies opt to stay on-prem, to the amazement and bewilderment of every vendor sales rep that calls on the phone. Go ahead and ask t…
Re: Lastpass Security Incident
#426Re: Lastpass Security Incident
#427Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!
I'm curious what did people migrate to, and is there any feature disparities?
Re: Lastpass Security Incident
#428Earlier quoted context omitted.
Isn’t this a yubikey? Except a yubikey can also do a lot more, primarily sign tokens without private key ever leaving the device. Which, as someone else explained below, is far superior to plain text passwords.
Yubikey is really great, but it's for 2FA, not password storage. My thought was to replace cloud password managers.
Re: Lastpass Security Incident
#429Earlier quoted context omitted.
Considering that 99% of web app password authentication reduces to email authentication via ‘forgot password’, a good first step would be dropping the password and just using emailed tokens (or links) directly.
When I was studying we had to use the computers in uni when presenting homework. It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells). Unfortunately google requires either their app or SMS. They dropp…
Re: Lastpass Security Incident
#430Earlier quoted context omitted.
You store the answers in your password manager and treat them like passwords
Yup. You pretty much have to do this. I love signing into my bank's bill payment system. "You appear to know your password and possess your second factor. But what's your favorite book? WRONG YOUR FAVORITE BOOK IS ACTUALLY NOW YOUR ACCOUNT IS LOCKED." Even if you're using real answers, you will be locked out of your account if you don't treat them like passwords. Eventually.