Earlier quoted context omitted.
If you wish to understand, all you have to do is ask someone outside the hn-tech-bubble.
"someone outside the hn-tech-bubble" saves their passwords in excel sheet without protection.
Lastpass Security Incident
431–440 of 587 posts
Re: Lastpass Security Incident
#432Will never understand why people use managed password management services when things like the KeePass KDBX format exist.
when you have an employee leave your company can you reroll or disable all their work account passwords in keepass? (no; this is good for the user and not useful for the org, but that’s the use case.)
Re: Lastpass Security Incident
#433Earlier quoted context omitted.
Considering that 99% of web app password authentication reduces to email authentication via ‘forgot password’, a good first step would be dropping the password and just using emailed tokens (or links) directly.
When I was studying we had to use the computers in uni when presenting homework. It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells). Unfortunately google requires either their app or SMS. They dropp…
Re: Lastpass Security Incident
#434Re: Lastpass Security Incident
#435Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!
One issue I ran into: the CSV file that "downloaded" in the browser didn't have all of my passwords, only about ~20 of ~400. I had to copy and paste the CSV text in the browser to a new CSV file with a text editor. But upon reviewing that, the format of the passwords was fine.
Re: Lastpass Security Incident
#436Earlier quoted context omitted.
I hate password managers. They sign you out way too often and god forbid you’re on another PC.
My work provides me with a 1Password subscription (for both work personal use) that I take advantage of that is pretty good. I think they only require you to reauthenticate with your master password once every two weeks or something. I use a PIN, biometrics, or my Apple Watch to unlock it when it timeouts in between that two week period, and I've had no problems syncing between several of my devices.
Re: Lastpass Security Incident
#437Earlier quoted context omitted.
When I was studying we had to use the computers in uni when presenting homework. It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells). Unfortunately google requires either their app or SMS. They dropp…
> Unfortunately google requires either their app or SMS. They dropped pure totp for some reason. Gmail TOTP still works fine?
Re: Lastpass Security Incident
#438Earlier quoted context omitted.
Considering that 99% of web app password authentication reduces to email authentication via ‘forgot password’, a good first step would be dropping the password and just using emailed tokens (or links) directly.
When I was studying we had to use the computers in uni when presenting homework. It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells). Unfortunately google requires either their app or SMS. They dropp…
I use TOTP with my Google Account all the time. If you have a phone registered with that Google Account it will default to the push notification system first (it might even be possible to make this no longer the default, I'm not sure), but you can always click the button to switch to alternative 2FA options.
Re: Lastpass Security Incident
#439Earlier quoted context omitted.
That is especially surprising, considering that passwords are more than likely going to contain special characters.
Avoid such trouble is why I want to avoid using symbols for password. Just use more alphanum characters for strength.
Re: Lastpass Security Incident
#440Earlier quoted context omitted.
> password that's just "password1234" it's even worse than that. The world's most common password is... password.
I'm not sure about that. According to The Plague, the four most common passwords were God, love, sex and secret.
What's interesting on these lists is the presence of Dragon and Monkey - am I mistaken or is it due to CJK users entering a Chinese character that got translated somehow? Wouldn't that mean some of the most popular passwords out there are single unicode characters? Surely not...
[1] https://en.wikipedia.org/wiki/List_of_the_most_common_passwo...