Live data from Hacker News

Lastpass setting the delete account div to display: none

infosec.exchange

131–140 of 210 posts

Re: Lastpass setting the delete account div to display: none

#131

Is LastPass one of those password managers that only encrypt passwords and leave other data as is? I always cringe when password managers do that. This is a funny joke for anyone who understands even a little about cryptography.

1Password and Mac OS X Keychain used to do that.[1] They'd leave the URL and title in plain text, amongst some other metadata. I think both no longer do, but the fact that they once did was very surprising to me. [1]: https://1password.community/discussion/12237/metadata-is-not...

In their defense, the treat model was way different back when they were using local vaults; I suspect the old "cloud storage" model they used placed each individual user who chose to sync opvault to the cloud at some risk, but short of Dropbox or OneDrive themselves getting popped, the cloud attack against 1P vaults was very limited

It doesn't escape me that their threat model could still be that, if they'd relent the cloud-only licensing choice

Re: Lastpass setting the delete account div to display: none

#132

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

No one has mentioned this to you yet, from what I can see, but Master Password[0] is basically what you're asking for. It is well worth it to switch to an implementation of that instead of your mental calculus.

> I believe there are alternatives that are more secure such as using a mental algorithm that generates a unique password per site.

Being completely honest, I consider this a terrible strategy. I seriously doubt your "algorithm" is anywhere close to as secure as you think it is. Humans suck at coming up with passwords, period, no matter how clever they think they are, and then memorizing those passwords is at least as difficult. Any algorithm that would actually be secure would take far too long to mentally apply to each website each time you visit it.

Fully featured password managers like 1Password can include much more than just usernames and passwords, which increases their value significantly. Otherwise, users absolutely store that incredibly important information in completely unencrypted places, often synced with the cloud, because it is important information that they need access to, and they want to make sure it doesn't get lost. There is tremendous value in having a user-friendly encrypted vault.

Since the entire vault is fully end to end encrypted with any decent password manager (like 1Password), the weaknesses that repeatedly affect LastPass do not ever apply here. The only thing that matters is having a strong password on your vault, and keeping that password secure. It doesn't matter if 1Password gets hacked, no one will even know what websites you have accounts on. Coincidentally, 1Password also doesn't have the same history of breaches that LastPass does.

The only other security risk beyond a weak password is a supply chain attack, where 1Password ships a compromised version of the 1Password client that steals your vault password, but this is significantly harder for a malicious actor to pull off than the breaches LastPass has dealt with, and any software vendor that you trust could be compromised and install a keylogger on your device, which would achieve the same outcome, so this is not specific to 1Password, and therefore I don't consider it very relevant to the discussion beyond mentioning that other people might bring it up.

> That's my personal approach and I think it's a better way to go.

It's really not, but someone who comes to the internet to rant about this stuff is so strongly convicted of their belief that I don't think I'm going to be able to change it, so I'll just leave it at that. I have cared a lot about cybersecurity for a long time, even before I worked in the cybersecurity industry for a few years, which gave me lots of additional exposure to experienced people and current events.

I have never recommended LastPass to anyone, and I would never recommend it to anyone. 1Password is a completely different story. There are valid open source alternatives, which you can self host, but most people (outside of this forum) are not going to succeed at hosting their own password manager, so it's important to find a trustworthy hosted option.

[0]: https://en.wikipedia.org/wiki/Master_Password_(algorithm)

Re: Lastpass setting the delete account div to display: none

#133
post #127

I'm not seeing a lot of clarity on what I should do as a LastPass user? Nothing? Move to 1Password? I can't use iCloud keychain because I use Chrome on Mac.

FWIW, I did this exact migration a few years ago (to 1Password Family), and am generally very happy with 1Password.

https://support.1password.com/import-lastpass/

Re: Lastpass setting the delete account div to display: none

#134
post #127

I'm not seeing a lot of clarity on what I should do as a LastPass user? Nothing? Move to 1Password? I can't use iCloud keychain because I use Chrome on Mac.

Doesn't Chrome have a built-in password storage? Firefox does, which is what I use and recommend.

Re: Lastpass setting the delete account div to display: none

#135

Earlier quoted context omitted.

Bitwarden migration was flawless for me. Impressive given how mangled the csv export i got from lastpass was! I really dig the 2FA auto-copy to clipboard feature in bitwarden.

Does Bitwarden support a keyword shortcut that brings up the password search? (outside of browser preferably), couldn't find one.

It appears not, since there's a feature request for it: https://community.bitwarden.com/t/global-keyboard-shortcut/3... (and their keyboard shortcuts doc doesn't mention any such thing)

Yet another fine reason to use 1Password, which puts a lot of time and attention into user experience stuff like this. I know Bitwarden is the Internet's darling, but holy hell the user experience is so aggressively bad

Re: Lastpass setting the delete account div to display: none

#136

So what's the best alternative?

Use your browser's built-in password storage. You already trust your browser with your passwords, and it's always better to keep your attack surface small.

Offline-only is an additional attack surface reducing move. Sure, you may have to copy passwords manually between devices sometimes, but in practice it happens rarely enough not to matter.

Re: Lastpass setting the delete account div to display: none

#137

So I've been happily using LastPass for a long time, but it looks like it's time to migrate off this dumpster fire. What's the HN consensus on the best replacement (which must be usable by my entire family) and, at least as importantly, is there a reasonably painless migration path?

1Password is my personal choice. I can easily share passwords with my family and create separate vaults.

There's a nice migration guide here: https://support.1password.com/import-lastpass/

Re: Lastpass setting the delete account div to display: none

#138

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

Use an offline password manager, avoid SaaS. Make sure it's secured with Argon2 and burns a a few seconds of compute to unlock. Use hardware MFA tokens for your most critical accounts. You could also tie individual copies of the database to the machine's TPM and only sync after decrypting (yet another factor).

> I believe there are alternatives that are more secure such as using a mental algorithm that generates a unique password per site.

That gets tedious when you also have to conform to stupid, different password policies on various sites.

If you want to compartmentalize things you could use multiple password databases with different master passwords? The master password is still something you have in your head.

Re: Lastpass setting the delete account div to display: none

#139
I wonder if they checked this with the compliance department regarding their obligations to delete data under GDPR. I hope their Data Protection Officers have the time to respond to all of the thousands of relevant manual email requests and delete all of the data in a timely manner, if people are made aware they are legally required to honor those.

Re: Lastpass setting the delete account div to display: none

#140

In light of this breach, can someone explain to me why it's not stupid to keep all your passwords in one place? I've never used a pw manager because it seems absolutely inevitable that these sorts of leaks happen. It just seems like an incredibly put all your eggs in one basket cargo cult type move. I just can't stomach single points of failure like that for anything worth protecting. Using a password manager is one…

You could just tell users to write down their unique passwords physically and store them somewhere safe instead of reusing the same password, but that wouldn't fit the narrative of being able to sell services for password management and no doubt another thing the "security" community seems to be highly against. I agree it's 100% stupid --- "all your eggs in one basket" is exactly the phrase that comes to mind for me…

At the scale of present-day secured-systems use, this becomes fairly cumbersome quickly.

The typical person, as long ago as 2015, had around (and possibly over) 100 accounts. I'm seeing people referring to many hundreds managed by LastPass or other password-management systems.

Using, say, a paper-based system whether in a bound journal or a set of index or Rolodex cards, a 500-account archive would take up most of a journal, or a pretty hefty chunk of cards, and that archive itself would require physical security (though at least data exfiltration would be slower than from a digital archive). It's not the sort of thing you could easily carry around with you, or access from multiple locations, should you need to do so.

In corporate use, the problem is compounded by:

- Multiple people requiring access to systems.

- Both shared-account and multi-account systems (e.g., a shared root to servers, master DBA account, or embedded / appliance devices with a single account).

- Multi-office (or remote / home office) access.

- Multi-device access (as in people are accessing systems from multiple devices).

This doesn't necessarily mean that a third-party service is your best or only option, but it strongly tends toward a managed third-party system being convenient where "convenient" means "our business which lacks a true CISO role would be dead in the water without it".

Mind: I'm not defending LastPass here, and I don't use it. The solutions I've seen in the past which have impressed me most were based on managed SSH keys with SSH access to critical systems, and the bare minimum of shared accounts.

I'd also like to see:

1) Far fewer authenticated services where that authentication is not necessary. For the most part, if I can avoid creating a new account, I do. (My circumstances leave me considerable latitude that many people wouldn't have, in this regard.) Systems based on asserted identity through PGP seem to me one option (e.g., rather than logging in and posting content, you'd post PGP-signed content, which the remote system would vet. Similarly, reading private content would be encrypted against your keys. This doesn't address all account-based interactions, but it does cover a large bit of landscape.

2) Physical-token based security particularly based on NFC or Yubikey-type devices. Keep in mind that an earlier widely-used technology, RSA keyfobs which would generate one-time PINs as a 2FA, turned out to have a nasty vuln some years back.

But fewer accounts, PKI-based auth, and physical 2FA ... seem increasingly necessary changes.

As numerous others apparently do: I use a local, encrypted, password keystore that is not managed by a third-party service.

(And don't even get me started on third-party data privacy doctrines.)

Post reply on HN