Live data from Hacker News

Lastpass Security Incident

blog.lastpass.com

491–500 of 587 posts

Re: Lastpass Security Incident

#491

Earlier quoted context omitted.

LastPass blog post on Sept 15 said the hack was accomplished with a compromised developer machine: > Our investigation determined that the threat actor gained access to the Development environment using a developer’s compromised endpoint. While the method used for the initial endpoint compromise is inconclusive, the threat actor utilized their persistent access to impersonate the developer once the developer had succ…

You're missing the point entirely. When you're on prem you only have to worry about your own employees opening sketchy PDFs. When you're not, you have to worry about everyone in your supply chain opening sketchy PDFs. Nevermind the fact that the next time a major world conflict occurs, the big 4 cloud providers will probably be destroyed, taking about 90% of the western economy with it.

> When you're not, you have to worry about everyone in your supply chain opening sketchy PDFs.

That's absolutely not correct. Besides, I have more respect for the security and operations procedures for AWS, GCP and Azure than I do for 99% of startups running their own infrastructure.

But my primary point is that you seem to be arguing that being on prem is inherently more secure, and more importantly, being in the cloud made LastPass less secure, despite the fact that the breach vector in this case would have been equally effective regardless of whether they were in cloud or on prem.

Re: Lastpass Security Incident

#492

Earlier quoted context omitted.

LastPass blog post on Sept 15 said the hack was accomplished with a compromised developer machine: > Our investigation determined that the threat actor gained access to the Development environment using a developer’s compromised endpoint. While the method used for the initial endpoint compromise is inconclusive, the threat actor utilized their persistent access to impersonate the developer once the developer had succ…

You're missing the point entirely. When you're on prem you only have to worry about your own employees opening sketchy PDFs. When you're not, you have to worry about everyone in your supply chain opening sketchy PDFs. Nevermind the fact that the next time a major world conflict occurs, the big 4 cloud providers will probably be destroyed, taking about 90% of the western economy with it.

You don't need to destroy the cloud providers. Missile hits on the major interconnection (interchange? peering?) nodes in each major country and most of the companies and people are offline. Or hit the power plants, see Ukraine.

Re: Lastpass Security Incident

#493
post #347
post #281

Earlier quoted context omitted.

From the same FAQ: > So in a sense, it makes your password stronger, but technically it doesn't qualify as a separate second factor, since this is not an authentication scheme and also because the expected response doesn't change every time you try to decrypt your database. I'd argue that the biggest threat against a (non-cloud-synced) password manager is a local database compromise, and the Yubikey does not meaningf…

If an attacker compromises your local machine, they don’t need any password: they just wait for you to enter all required credentials and read the passwords when the database is unlocked. Also, you omitted an important sentence at the end of the FAQ that you quoted. The response changes every time you save the database. Yubikey uses HMAC-SHA1, which is a hash of a shared key and a counter. The counter, and hence the…

I do see the point of adding more entropy, but against what type of attacker is the rotating password an improvement?

It seems to kick the attacker out of getting future database updates after a point-in-time compromise, but do users using a password manager frequently change their passwords stored in it? At least I don't.

Re: Lastpass Security Incident

#494

Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!

Man, outputting data to a CSV is a very difficult computing problem. /schadenfreude

Re: Lastpass Security Incident

#495
post #395

Earlier quoted context omitted.

Thanks to the GDPR a coverup is no longer an option.

How do you figure? If a company never reports an incident, how would the government regulator know about it?

They will at some point. A whistleblower, the attackers themselves, the leaked data showing up somewhere on a forum and getting picked up by reporters, etc. etc. At the scale at which any of the popular passwords managers operate, IMO it would be impossible to keep it a secret for long. So taking the risk of jail time only delaying the inevitable... doesn't make sense.

Re: Lastpass Security Incident

#496
I've been looking to migrate off LastPass to Bitwarden or KeePassXC, but can't decide:

1. First off, who's to say LastPass will actually delete my data when I delete my account? Could I in practice be increasing my exposure by starting to use something different?

2. Bitwarden: They look cool but "In September 2022, the company announced $100M series B financing". In my experience, usually, financing = bad.

3. KeePassXC: I'm afraid the UX will be worse. But hey it's in my operating system repos, so perhaps I should just give it a try?

Re: Lastpass Security Incident

#497

Earlier quoted context omitted.

Typically, because one has other opportunities that are no less compelling and where potential employers show respect for candidates' time. I have a GitHub profile with a lot of code on it and on my resume I highlight projects I've done a lot of work on. "What if faked tho?"--there's literally too much there to be worth faking . If a hiring manager looks at my resume, has the option of going to my GitHub profile, and…

Personally, I only ever ask people to solve coding/problem-solving questions live. The best experience IMO is when we talk through the problem together, since this approximates what collaborating with this person on real tasks will be like - not very well at all, but about as well as one can do in the amount of time available for a live interview. However, I do understand where the offline exercise idea comes from -…

I think this is a good analysis of where the offline idea started from, but in my experience the majority of interviewers who want you to do a "take home" thing are asking you to sign up for a multiple-hour mess of a project. That's where the lack of respect comes from, and the lack of acknowledgment of the market--most people you want to hire are already employed, after all, and time pressure from life is a thing.

Making it an option for somebody who would rather wouldn't be bad, but yeah, as you say, nobody's learning a lot about the other people that way, and they're probably more important.

(The OP's card deck problem is just faintly ridiculous and a bad allocation of the candidate's time, and I assume there are more hoops to jump through afterwards.)

Re: Lastpass Security Incident

#498
post #496

I've been looking to migrate off LastPass to Bitwarden or KeePassXC, but can't decide: 1. First off, who's to say LastPass will actually delete my data when I delete my account? Could I in practice be increasing my exposure by starting to use something different? 2. Bitwarden: They look cool but "In September 2022, the company announced $100M series B financing". In my experience, usually, financing = bad. 3. KeePass…

Why no 1Password on your list?

Re: Lastpass Security Incident

#499

Earlier quoted context omitted.

Also if you try to export multiple times it will start spitting out exports full of duplicates. Only safe way is to export right after a fresh session login.

Wow. Is LastPass generally just really bad software? These bugs mentioned in this subthread make it sound like amateur hour.

It’s the worst desktop software I’ve used in several years. The UX makes no sense, it’s full of bugs, it performs badly, they’ve had multiple breaches. I can’t think of a single thing it does that’s even approaching average, let alone good.

Re: Lastpass Security Incident

#500

Earlier quoted context omitted.

But shouldn't a blacksmith be able to make a nail before he makes me a suit of armor?

Making direct comparisons of software to trades generally needs to stop. I understand that it's merely an analogy, but it's not a good one. Nails are extremely well understood with little room for improvement while the smallest piece of software is not so well understood and has infinite room for improvement. There are a handful of traits about an engineer that can make them incredibly valuable to an org that you'll…

[deleted]
Post reply on HN