Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

431–440 of 587 posts

Re: Lastpass Security Incident

#431

Earlier quoted context omitted.

If you wish to understand, all you have to do is ask someone outside the hn-tech-bubble.

"someone outside the hn-tech-bubble" saves their passwords in excel sheet without protection.

That's not far enough outside the bubble. People just reuse passwords, or add a suffix to a base password, or forget their passwords and email reset each login.

Re: Lastpass Security Incident

#432

Will never understand why people use managed password management services when things like the KeePass KDBX format exist.

when you have an employee leave your company can you reroll or disable all their work account passwords in keepass? (no; this is good for the user and not useful for the org, but that’s the use case.)

Yes. Because their passwords should be linked only to their own work accounts and not be shared passwords. Even if you used lastpass at work, nothing stops an employee from storing it again somewhere else.

Re: Lastpass Security Incident

#433

Earlier quoted context omitted.

Considering that 99% of web app password authentication reduces to email authentication via ‘forgot password’, a good first step would be dropping the password and just using emailed tokens (or links) directly.

When I was studying we had to use the computers in uni when presenting homework. It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells). Unfortunately google requires either their app or SMS. They dropp…

Also hardware keys work just fine with Google.

Re: Lastpass Security Incident

#434
post #25

it's so baffling to me that people give ALL their password to a third party, commercial, organization...

It's supposed to be E2E encrypted with your master password plus an additional key.

Supposed. But few do research, even fewer do audits.

Re: Lastpass Security Incident

#435

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

I just exported my own vault with the latest version, it was ok for me. I have plenty of passwords with all kinds of special characters. Still, be sure to review the CSV file. If anything looks weird, double check that the password is the same in your LastPass vault. As with all backups/exports, you should always do a sanity check of the data.

One issue I ran into: the CSV file that "downloaded" in the browser didn't have all of my passwords, only about ~20 of ~400. I had to copy and paste the CSV text in the browser to a new CSV file with a text editor. But upon reviewing that, the format of the passwords was fine.

Re: Lastpass Security Incident

#436
post #111

Earlier quoted context omitted.

I hate password managers. They sign you out way too often and god forbid you’re on another PC.

My work provides me with a 1Password subscription (for both work personal use) that I take advantage of that is pretty good. I think they only require you to reauthenticate with your master password once every two weeks or something. I use a PIN, biometrics, or my Apple Watch to unlock it when it timeouts in between that two week period, and I've had no problems syncing between several of my devices.

1Password on my Mac lets me set it to never require re-authentication with my master password, though it does seem to keep switching back to 30 days.

Re: Lastpass Security Incident

#437
post #406

Earlier quoted context omitted.

When I was studying we had to use the computers in uni when presenting homework. It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells). Unfortunately google requires either their app or SMS. They dropp…

> Unfortunately google requires either their app or SMS. They dropped pure totp for some reason. Gmail TOTP still works fine?

Yup, but it seems it will default to "click the notification on your phone" as soon as you've signed in on a phone. You need to click "try another way", even if you've explicitly told them that TOTP is your preferred default.

Re: Lastpass Security Incident

#438

Earlier quoted context omitted.

Considering that 99% of web app password authentication reduces to email authentication via ‘forgot password’, a good first step would be dropping the password and just using emailed tokens (or links) directly.

When I was studying we had to use the computers in uni when presenting homework. It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells). Unfortunately google requires either their app or SMS. They dropp…

> Unfortunately google requires either their app or SMS. They dropped pure totp for some reason.

I use TOTP with my Google Account all the time. If you have a phone registered with that Google Account it will default to the push notification system first (it might even be possible to make this no longer the default, I'm not sure), but you can always click the button to switch to alternative 2FA options.

Re: Lastpass Security Incident

#439

Earlier quoted context omitted.

That is especially surprising, considering that passwords are more than likely going to contain special characters.

Avoid such trouble is why I want to avoid using symbols for password. Just use more alphanum characters for strength.

I want to as well, but annoyingly there are many sites that insist on a "special" character because their strength measure says "low" for the 20 character alphanumeric string I generated %-}

Re: Lastpass Security Incident

#440

Earlier quoted context omitted.

> password that's just "password1234" it's even worse than that. The world's most common password is... password.

I'm not sure about that. According to The Plague, the four most common passwords were God, love, sex and secret.

Wiki says that some companies agree[1] that "123456" and "qwerty" are the most popular. "password" seems to generally be in the top 10.

What's interesting on these lists is the presence of Dragon and Monkey - am I mistaken or is it due to CJK users entering a Chinese character that got translated somehow? Wouldn't that mean some of the most popular passwords out there are single unicode characters? Surely not...

[1] https://en.wikipedia.org/wiki/List_of_the_most_common_passwo...

Post reply on HN