Earlier quoted context omitted.
I'm on the opposite side: I don't understand how a password manager can be compromised. Your passwords are encrypted and decrypted OFFLINE, on your device. You only ever send the ENCRYPTED vault. Your key never transits. How is that complicated? And how did LastPass fuck this up anyway?
Yeah, I don't consider my encrypted vault to be particularly sensitive. I guess someone could key log my master password on my device, copy my vault and pwn me everywhere. Also, when quantum computing becomes practical enough we password manager users might be in trouble, but surely in that case major changes in infosec would be needed regardless.
Lastpass setting the delete account div to display: none
121–130 of 210 posts
Re: Lastpass setting the delete account div to display: none
#122In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…
Because it’s less bad than the alternatives. I can’t remember a unique password for every account I have. > I believe there are alternatives that are more secure such as using a mental algorithm that generates a unique password per site. I’m going to forget it. Either I use a centralized password keeper or the real login process is the reset password flow. Using a password manager is probably more secure and convenie…
Re: Lastpass setting the delete account div to display: none
#123Re: Lastpass setting the delete account div to display: none
#124In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…
The info LastPass and most other password managers I'd use have is useless even someone got it... sure they might get my email and what sites I stored passwords for, but the passwords themselves are not just sitting there in plain text or decreeable format able to be used.
Congratulations, you are now a high value identity theft or kidnapping target.
How about a married man who had a secret account on a dating site?
Or the URL of a medical results portal at a specialist institution? Now your medical history is out in the open.
Re: Lastpass setting the delete account div to display: none
#125any password manager can be hacked, i had my master password for 20 characters with numbers, characters and special characters. It will take years to brute force and can i assume i have couple of months to change all of my 200 passwords? am i missing something
Note: secure notes is not the same as the “notes” field. Secure notes are encrypted.
Edit: Also it is unclear whether records like Bank Accounts, Social Security Numbers, etc have been fully encrypted.
Re: Lastpass setting the delete account div to display: none
#126In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…
The average person, when not allowed to use a convenient password manager, will either use the same password for every site or come up with a predictable pattern. Encouraging a password manager helps make sure they don't get destroyed completely when a blog they signed up on 5 years ago is hacked. This is partly because so many things want an account now. I have over 500 passwords saved, it would be straight up impos…
Re: Lastpass setting the delete account div to display: none
#127Re: Lastpass setting the delete account div to display: none
#128I switched off of LastPass 2 years ago and convinced my brother to do the same because some things in LastPass apps started to feel very old, especially their 2FA implementation, which signals to me that either their stack is inflexible or there's a lot of churn in their dev teams. When those things are true, that means they're probably just maintaining old code instead of evolving it. Or even more terrifying: they don't know what needs to evolve.
Not regretting it so far.
Re: Lastpass setting the delete account div to display: none
#129In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…
Reusing passwords or having low entropy passwords is a larger risk. The thing is... Your password manager should be offline, not a cloud service.
The part I don't get about these discussions is that Firefox saves passwords offline for me just fine, and I have to trust my browser to handle my passwords already anyway. Sure, I have to manually copy a password between devices sometimes. Happens maybe three or four times a year, big f'ing deal.
There's absolutely no reason to add more attack surface by using a password manager.
Re: Lastpass setting the delete account div to display: none
#130I'm not seeing a lot of clarity on what I should do as a LastPass user? Nothing? Move to 1Password? I can't use iCloud keychain because I use Chrome on Mac.