Is LastPass one of those password managers that only encrypt passwords and leave other data as is? I always cringe when password managers do that. This is a funny joke for anyone who understands even a little about cryptography.
Lastpass setting the delete account div to display: none
31–40 of 210 posts
Re: Lastpass setting the delete account div to display: none
#32Re: Lastpass setting the delete account div to display: none
#33Using a password manager is one of those infosec memes that gets oft repeated but doesn't make a lot of sense to me as being "more secure". To me it seems like your passwords existing outside of your head in any way is a risk, and to have them all in one place (even encrypted) seems way worse than having to go through the reset dance every once in a while because you forgot one.
EDIT: I was being a bit snarky and I apologize. As some commenters have rightly pointed out for the average person this is better than the uneducated alternative of using the same PW everywhere, and as method for reducing a random person's risk exposure it is extremely transmissible vs the alternatives.
That being said (as a commenter pointed out I should have included this in the post originally) I believe there are alternatives that are more secure such as using a mental algorithm that generates a unique password per site. I don't think that these sorts of things are prohibitively complicated, and I think never storing passwords outside of your head has a lot of benefits. That's my personal approach and I think it's a better way to go.
P.S. A lot of the fault lies with requiring accounts for things that don't actually require an account. Another problem that comes out of the SaaS model which can be completely avoided by just not making SaaS.
Re: Lastpass setting the delete account div to display: none
#34So I've been happily using LastPass for a long time, but it looks like it's time to migrate off this dumpster fire. What's the HN consensus on the best replacement (which must be usable by my entire family) and, at least as importantly, is there a reasonably painless migration path?
I really dig the 2FA auto-copy to clipboard feature in bitwarden.
Re: Lastpass setting the delete account div to display: none
#35In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…
Re: Lastpass setting the delete account div to display: none
#36Re: Lastpass setting the delete account div to display: none
#37So I've been happily using LastPass for a long time, but it looks like it's time to migrate off this dumpster fire. What's the HN consensus on the best replacement (which must be usable by my entire family) and, at least as importantly, is there a reasonably painless migration path?
Re: Lastpass setting the delete account div to display: none
#38I work at a large company and against the opinion of many engineers and infosec folks, lastpass was picked as our preferred corporate password storage. I'm just waiting for a call from infosec asking me to log on and to rotate a bunch of creds. Happy Holidays.
Our new parent company -- that works in a security-sensitive industry -- rolled out LastPass over the last few months. I sent a warning letter to the CISO listing the previous hacks and vulnerabilities in LastPass. Then this new hack happened, and the CISO sent out a letter saying that there is nothing to be concerned about and that all is well. When the news broke that the breach was worse than predicted, I sent ano…
The only thing possible would be something like "reevaluating the situation due to new informations" or an otherwise heroic element, that shows how important CISO is will change the situation. This must come from outside channels: "The prophet has no honor - or at least, little - in his own country" ;)
Re: Lastpass setting the delete account div to display: none
#39In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…
Re: Lastpass setting the delete account div to display: none
#40In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…