Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

471–480 of 587 posts

Re: Lastpass Security Incident

#472
post #184

The best is to use something like Keepassxc, synced peer to peer by Synchting or Resilio. Nobody will be involved with your passwords. Keepassxc supports Yubikey, so you can lock it down strongly!

Databases: Keepass on pc and keepassdroid on android (saved as not kdbx files, stenographically passworded inside a jpg renamed as a wav, manually backed up between pc and phone, suits me. Its a pain, but not as painful as being lastpassed!

Re: Lastpass Security Incident

#473

Earlier quoted context omitted.

This really hurt me last year, when I migrated away. I didn't realize at the time how much didn't come with, so I've been playing the reset / recovery game since.

I feel your pain. I switched to KeePassXC, and will never use an online password manager again. For a password management company, they can't even be bothered to fuzz their export functionality. QuickCheck works unreasonably well on `import(export(a)) == a`. But maybe it's intended to be buggy, in order to keep you in their walled garden. Clearly the sync between devices works, so they have solved this problem.

> Clearly the sync between devices works, so they have solved this problem.

Presumably they don't use CSV to sync, they're using a saner json/etc. data structure that they're not letting us export ourselves. Seriously, being limited to CSV in this day and age...

Re: Lastpass Security Incident

#474
post #368

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

I'm curious what did people migrate to, and is there any feature disparities?

My wife and I switched from Lastpass to Bitwarden early this year. Glad we did, considering all the news! Password sharing is different, since you have to make a group/organization and share the password in there. But once that was figured out, it's been a better experience with less bugs. It doesn't look slick, but it's more functional.

Re: Lastpass Security Incident

#475
post #20

Someday one of these password managers is going to be hacked wide open and it is NOT going to be pretty.

I don't use them, but my conclusion is that at least one major cloud password manager has been hacked already without any disclosure. If they disclose it, the company should logically be dead. Thus, the incentive would just be to cover it up.

Totally agree, this is why I don't trust any of them. Massive targets with extremely strong incentives to stay quiet about security issues.

Re: Lastpass Security Incident

#476
post #297

Earlier quoted context omitted.

No offense, but this is such a hacker solution. :) And as mentioned, already exists in many forms. Passwords and login credentials are dead. No user wants to deal with them. Password managers are a solution to somewhat sanely and securely manage this complexity, and not something that the average user wants to think about. In that sense, they don't improve security overall, and introduce many other issues (a centrali…

Considering that 99% of web app password authentication reduces to email authentication via ‘forgot password’, a good first step would be dropping the password and just using emailed tokens (or links) directly.

This does seem to be the latest trend - passswordless authentication or "magic links."

Re: Lastpass Security Incident

#477

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

What would be considered a good alternative?

Bitwarden is great. There is even an opensource implementation of bitwarden server you can self-host that includes premium features for free.

Re: Lastpass Security Incident

#478
post #184

The best is to use something like Keepassxc, synced peer to peer by Synchting or Resilio. Nobody will be involved with your passwords. Keepassxc supports Yubikey, so you can lock it down strongly!

Do you not suggest using Dropbox to sync KeePassXC? Their FAQ on site seems to support (and encourage?) the use of Dropbox for syncing.

Nextcloud. OG keepass works well syncing, XC I've had issues.

Re: Lastpass Security Incident

#479

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

Maybe I lucked out? I migrated to Bitwarden early this year and so far all of my passwords have worked. I also made sure to compare the site entries in both. One thing that can't transfer were attachments in LastPass secure notes. So I had to download each one individually and upload them to Bitwarden.

Re: Lastpass Security Incident

#480

Earlier quoted context omitted.

Also if you try to export multiple times it will start spitting out exports full of duplicates. Only safe way is to export right after a fresh session login.

Wow. Is LastPass generally just really bad software? These bugs mentioned in this subthread make it sound like amateur hour.

The UX is surprisingly bad, and has been for a long time.
Post reply on HN