Live data from Hacker News

Lastpass setting the delete account div to display: none

infosec.exchange

51–60 of 210 posts

Re: Lastpass setting the delete account div to display: none

#51

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

For example, I am old and can't remember sh-t. I can only remember one master password, and I've already forgotten it twice. Now have it backed up on a piece of paper. Looking forward for a day when I forget where I put that piece of paper ...

Re: Lastpass setting the delete account div to display: none

#52

The title would make more sense with quotes around the CSS keywords: I'm sure LastPass setting the delete account to "display: none" was coincidental

Quotes aren’t valid around CSS properties. How about brackets?

I'm sure LastPass setting the delete account to {display: none} was coincidental

Re: Lastpass setting the delete account div to display: none

#53
post #35

Earlier quoted context omitted.

Well, what's the alternative besides a local keepass DB or something?

I use a mental algorithm that generates a unique password for each site. It's easy to remember the algorithm and I get a complex unique password for every site. I don't think a password existing outside of your head makes sense. (though some sites force unique passwords/and password changes, which can be annoying as I have to remember to bump a value mentally for how many times i've been forced to do it, luckily for…

I see, you left this out of your original post and it would have had me reply entirely different. This certainly can work for you and makes sense, expecting everyone to do this instead of using a tool to do this is unrealistic IMO. Everyone thinks about things differently and many people "dont care" about security and just want a password that works.

Re: Lastpass setting the delete account div to display: none

#54

Is LastPass one of those password managers that only encrypt passwords and leave other data as is? I always cringe when password managers do that. This is a funny joke for anyone who understands even a little about cryptography.

According to their security notice from a couple days ago, they have "fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data."

So, according to them, they encrypt the other fields. I suppose the website field is unencrypted to enable autodetection or something like that.

Re: Lastpass setting the delete account div to display: none

#55
post #48

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

I'm on the opposite side: I don't understand how a password manager can be compromised. Your passwords are encrypted and decrypted OFFLINE, on your device. You only ever send the ENCRYPTED vault. Your key never transits. How is that complicated? And how did LastPass fuck this up anyway?

I assumed that the hackers have the encrypted vaults. Is it known that that they have unencrypted password data?

Re: Lastpass setting the delete account div to display: none

#56
A lot of people here seem to be confused about what a breach of LastPass would actually mean. They should look into how LastPass actually works. Spoiler alert - they don't actually have your passwords, and anyone who hacked them and took all their data would not have your passwords either.

Re: Lastpass setting the delete account div to display: none

#57

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

If one site gets breached/exposed, your memorized username/password combination used all across the internet is now immediately available to the bad actors and you might not even know or remember everywhere it was used. Having a unique password for each site is the main advantage of a password manager to mitigate the damage in this case (to just the 1 site that was breached). Talking about your vault/passwords and "s…

Doesn't this assume the passwords aren't hashed and salted?

Re: Lastpass setting the delete account div to display: none

#58
post #35

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

Well, what's the alternative besides a local keepass DB or something?

A local keepass is a great alternative, been doing that for ages and honestly copying my keepass db to a device every once in a while is way less troublesome than quadruple factoring into lastpass/1password or whatever.

Re: Lastpass setting the delete account div to display: none

#59

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

If one site gets breached/exposed, your memorized username/password combination used all across the internet is now immediately available to the bad actors and you might not even know or remember everywhere it was used. Having a unique password for each site is the main advantage of a password manager to mitigate the damage in this case (to just the 1 site that was breached). Talking about your vault/passwords and "s…

I don't think that having a unique password per site is unachievable. I do it and I don't use a PW manager. Even something as simple as prepending the site name in ROT13 to a reused password greatly reduces your exposure to the sort of background infosec threat radiation that's like 99.99% of the threat model for most people
Post reply on HN