Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

421–430 of 587 posts

Re: Lastpass Security Incident

#421

> was able to gain access to certain elements of our customers’ information This is frustratingly vague. This incident started 4 months ago, and you can't provide any details? If it wasn't such a PITA to move off LastPass, I would do so. They got me.

How is it a PITA to move off lastpass? I switched to Bitwarden and it was a piece of cake. Exported all passwords. Imported all passwords. Pretty much all password managers can import/export as a CSV or similar.

Just check your data after re-importing the passwords. LastPass sometimes has issues with the export (see elsewhere in this thread) and does not export attachments at all. You have to move attachments manually.

Re: Lastpass Security Incident

#424

Earlier quoted context omitted.

These probably won't replace password managers, just result in passkey managers... Dashlane already supports passkeys & 1password just announced intent to support soon.

How do they "manage" passkeys? There's nothing to manage except your fingerprint/face authentication.

You get some form of cross-platform sync. Apple, Google, and so on each have syncing, but in their ecosystem only. You can break out with the QR codes, but this might not be the preferred solution to some.

Re: Lastpass Security Incident

#425

> We recently detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo. We immediately launched an investigation, engaged Mandiant, a leading security firm, and alerted law enforcement. EXACTLY why so many companies opt to stay on-prem, to the amazement and bewilderment of every vendor sales rep that calls on the phone. Go ahead and ask t…

This was the immediate and exact same thought I had the moment I read the first sentence of the post. Then I stopped reading. Clearly this was not an engineering decision, and passwords should be trusted to no one but competent engineers and cryptographers.

Re: Lastpass Security Incident

#427
post #368

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

I'm curious what did people migrate to, and is there any feature disparities?

I've tried LastPass, 1password, and Bitwarden. Bitwarden has been my favorite as I can selfhost it if I want (open source fork with feature parity)

Re: Lastpass Security Incident

#428
post #317

Earlier quoted context omitted.

Isn’t this a yubikey? Except a yubikey can also do a lot more, primarily sign tokens without private key ever leaving the device. Which, as someone else explained below, is far superior to plain text passwords.

Yubikey is really great, but it's for 2FA, not password storage. My thought was to replace cloud password managers.

You can set static password for yubikey double click. But then it is only a single factor - something you own and just doubleclick to input that key. https://www.yubico.com/resources/glossary/static-password/

Re: Lastpass Security Incident

#429

Earlier quoted context omitted.

Considering that 99% of web app password authentication reduces to email authentication via ‘forgot password’, a good first step would be dropping the password and just using emailed tokens (or links) directly.

When I was studying we had to use the computers in uni when presenting homework. It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells). Unfortunately google requires either their app or SMS. They dropp…

If you first enable app or sms then you can add totp (that was my experience at least)

Re: Lastpass Security Incident

#430
post #55

Earlier quoted context omitted.

You store the answers in your password manager and treat them like passwords

Yup. You pretty much have to do this. I love signing into my bank's bill payment system. "You appear to know your password and possess your second factor. But what's your favorite book? WRONG YOUR FAVORITE BOOK IS ACTUALLY NOW YOUR ACCOUNT IS LOCKED." Even if you're using real answers, you will be locked out of your account if you don't treat them like passwords. Eventually.

Worse yet, real answers are just weaker passwords. Mother's maiden name? Childhood friend? Elementary / high school? For a targeted attack, against most people, this is very insecure in the all information online age. Nobody needs to know your 20 character password if they have your social media page.
Post reply on HN