Live data from Hacker News

Lastpass setting the delete account div to display: none

infosec.exchange

41–50 of 210 posts

Re: Lastpass setting the delete account div to display: none

#41

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

The alternative is:

- Password re-use

- Formulaic passwords

- Simple passwords that are easy to type on a phone

That are easily crackable

Or performing password recovery every time you want to login.

Re: Lastpass setting the delete account div to display: none

#42

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

The alternative is repeating passwords which is a worse version of putting all your eggs in one basket.

Re: Lastpass setting the delete account div to display: none

#43

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

The average person, when not allowed to use a convenient password manager, will either use the same password for every site or come up with a predictable pattern. Encouraging a password manager helps make sure they don't get destroyed completely when a blog they signed up on 5 years ago is hacked.

This is partly because so many things want an account now. I have over 500 passwords saved, it would be straight up impossible to remember unique strings for each site.

Re: Lastpass setting the delete account div to display: none

#45
post #35

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

Well, what's the alternative besides a local keepass DB or something?

I use a mental algorithm that generates a unique password for each site. It's easy to remember the algorithm and I get a complex unique password for every site. I don't think a password existing outside of your head makes sense.

(though some sites force unique passwords/and password changes, which can be annoying as I have to remember to bump a value mentally for how many times i've been forced to do it, luckily for the most part it's not an issue)

Re: Lastpass setting the delete account div to display: none

#46

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

If one site gets breached/exposed, your memorized username/password combination used all across the internet is now immediately available to the bad actors and you might not even know or remember everywhere it was used. Having a unique password for each site is the main advantage of a password manager to mitigate the damage in this case (to just the 1 site that was breached). Talking about your vault/passwords and "single basket" being obtained is relevant when using a password manager, especially with articles/news like this but just a different attack vector.

Re: Lastpass setting the delete account div to display: none

#47
post #39

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

The alternative to a password manager is to set all your passwords the same then that master password gets leaked.

Probably much safer these days to just write them down in a notebook

Re: Lastpass setting the delete account div to display: none

#48

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

I'm on the opposite side: I don't understand how a password manager can be compromised. Your passwords are encrypted and decrypted OFFLINE, on your device. You only ever send the ENCRYPTED vault. Your key never transits. How is that complicated?

And how did LastPass fuck this up anyway?

Re: Lastpass setting the delete account div to display: none

#49

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

The info LastPass and most other password managers I'd use have is useless even someone got it... sure they might get my email and what sites I stored passwords for, but the passwords themselves are not just sitting there in plain text or decreeable format able to be used.

Re: Lastpass setting the delete account div to display: none

#50

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

Because it is better than the alternative.

Pick two:

  (1) memorizable passwords
  (2) bruteforce-resistant passwords
  (3) account-unique passwords.
The best tradeoff for me is (2)+(3) sacrificing (1), so I use a local password manager (named 'pass'). That said, I would never trust a 3rd party like LastPass.
Post reply on HN