Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

461–470 of 587 posts

Re: Lastpass Security Incident

#461
post #367

Earlier quoted context omitted.

Because it is not exposed to the internet and not under control of incompetent companies like lastpass.

I use 1Password. If it's end-to-end encrypted, like it is for 1Password, I don't see what the issue is.

It's about root of trust.

Generally it seems that there are two types of people - those that trust encryption and those that trust themselves just a little bit more.

In lots of threads like these the same statements repeat, pretty much similar to this exact thread.

Some people place encryption as the root of trust and so trust that any local encryption is good enough - because if it's encrypted then it's safe to go anywhere...right?

Some prefer to only trust local encryption that doesn't go anywhere, e.g. not synced non-locally to a cloud service. They do trust encryption, but their own stewardship of it they trust a little bit more.

Logically, both must trust encryption of they wouldn't both use it, but one trusts the implementation a little less. That person generally trusts their own systems, setup, skills and self to provide an additional layer of 'feel good' security. They trust the security of their setup and its supply chain over that of a third party. They trust their own 'defence in depth'.

Functionally the two approaches are more similar than either will admit, because unless you can secure the entire 'system' from transistor to human, all the 'prefer local' user is doing is shifting the point of attack and not necessarily understanding their 'defence in depth' might not be as deep as they think.

Most 'prefer local' users will usually point out that the shift of the point of attack makes it harder to achieve. That may have some truth, it may also not. It may actually be that a third party security focused service with many dedicated employees who are paid well and operate round to the clock to monitor activity might have a greater 'defence in depth' and a subsequently greater chance of spotting or preventing a supply chain attack over a single individual spread across many tasks (such as living a normal life and administering their systems in spare time).

The discussion usually then descends into opinion and there it stays, like a plant in the shade, never producing any useful fruit to it's keepers.

Re: Lastpass Security Incident

#462
post #226

I once started an interview process as a senior developer at Goto, the company behind LastPass. The contact was a first phone call where someone simply asked the number of experience I had in software development, Java programming, etc. I thought it was weird that basically all they got from the phone call was a bunch of numbers. The weirdest part tho what that they asked how many years of experience I had in... open…

Sounds silly, it’s a shame you didn’t get past the initial screen. It’s a process that has to be humored and you could have added a lot of value just by joining and then patching their hiring process. When I was teaching in high school the deck-modelling thing is one that the kids come up with a lot especially when it came to doing their term project. I love the idea of being asked to implement a deck of cards using…

Some other things you could do with a deck of cards to add useful functions.

Shuffle

Draw

Deal

Cut

Pile

Turn

Now imagine you have pinocle uno and cribbage as games. they each start with a different set of cards, but can use the functions above. The fact that it’s a 52 card deck with suits and ranks isn’t stated by GP, and there’s also the optional jokers.

For a real game, you’d probably need the back of cards as well for animation, and maybe you implement card designs to give the game some customization - now the deck needs some more properties or methods.

After all of that, think of whether the generic deck could be used to play magic or pokemon by using inheritance.

For lastpass, the closest parallel they might have to a deck is a password generator. Implementing that would seem like work. The deck stuff is all premature optimization for a single game, but they are checking your knowledge of inheritance, so just go along with it.

Re: Lastpass Security Incident

#464
post #340

Product idea! A little e-ink display (let's call it a Password Storage Device or PSD) with a tiny processor and enough memory to store all your passwords. Make them cheap enough that you can have a few redundant copies in various places. - OS sees the device as a keyboard - Two versions. One with bluetooth, and one with only USB for a little more security. - Open source software package to sync your collection of PSD…

The Precursor should tick your boxes, and with an FPGA-based SOC. https://www.crowdsupply.com/sutajio-kosagi/precursor/updates...

By bunnie too, so you know it'll be good :)

Re: Lastpass Security Incident

#465

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

This really hurt me last year, when I migrated away. I didn't realize at the time how much didn't come with, so I've been playing the reset / recovery game since.

I feel your pain. I switched to KeePassXC, and will never use an online password manager again.

For a password management company, they can't even be bothered to fuzz their export functionality. QuickCheck works unreasonably well on `import(export(a)) == a`.

But maybe it's intended to be buggy, in order to keep you in their walled garden. Clearly the sync between devices works, so they have solved this problem.

Re: Lastpass Security Incident

#466
post #175

Earlier quoted context omitted.

Bitwarden is better, but Vaultwarden (the self-hosted version written in Rust) is the absolute best option. Host it yourself on a free tier VM in one of the clouds, configure a backup solution, and never worry about it again. And you don't need to trust anyone with your passwords. Use tailscale if you want to get fancy and keep it off the public internet or go the easy route and install fail2ban and expose it via pub…

Can you give some idea why Bitwarden is better?

Fully end to end encrypted. The other side to that is there is no account recovery.

Re: Lastpass Security Incident

#468

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

I just exported my own vault with the latest version, it was ok for me. I have plenty of passwords with all kinds of special characters. Still, be sure to review the CSV file. If anything looks weird, double check that the password is the same in your LastPass vault. As with all backups/exports, you should always do a sanity check of the data. One issue I ran into: the CSV file that "downloaded" in the browser didn't…

I had a problem not with the password data but with the content of some notes (or whatever it is called in LastPass)

I have been a paying customer of Lastpass for about 15 years. I moved to Bitwarden for all sorts of reasons. I work in technical information security so it was also for that teason (but not only)

Re: Lastpass Security Incident

#470
Oh come on guys, what's the problem? Just keep delegating all your sensitive stuff to the cloud instead of the unbearable chore of storing it locally! They'll definitely fix their shit together and everything will be okay, until someone hacks them again.
Post reply on HN