Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

101–110 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#101
post #55

It would be interesting to hear people’s life philosophy in this area. For me, lastpass always seemed like a bad idea as passwords are very important to me and giving someone else a copy of my passwords seems like a bad idea. Similarly, I don’t let any services know my bank passwords even if they super promise to protect them and not misuse them. Another similar seeming task that I can’t delegate is to read my bank s…

> and giving someone else a copy of my passwords

Except you're not doing that. You're giving someone else an encrypted blob.

The screwup here is that LastPass also stored a bunch of unencrypted metadata.

Re: What’s in a PR statement: LastPass breach explained

#102

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

Please change your domain, looks like a phishing website. I would never clic on that anywhere else on the internet.

+1. The URL is a huge red flag since it's exactly how scammers create fake links online.

Re: What’s in a PR statement: LastPass breach explained

#103
post #19
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

With KeePass, the trivial solution for this situation could just be a second subset database of relevant accounts on a thumb drive, with the password known to family individuals. That seems easier than relying on a cloud provider and some sort of half-baked insecure emergency access mode.

Re: What’s in a PR statement: LastPass breach explained

#106
post #81
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

What about just using chrome’s saved passwords and syncing? It would be great if someone can succinctly destroy that idea :D

I use this and it's convenient but the fact that Google can wipe out my entire digital identity on a whim scares me.

Re: What’s in a PR statement: LastPass breach explained

#107

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

I would second the change in the url. Good job though.

Re: What’s in a PR statement: LastPass breach explained

#108

Catastrophic breach after catastrophic breach since 2011. Lastpass has failed their fiduciary duty as a steward of sensitive information and IMO exhibited gross negligence in not encrypting URI data, ostensibly as a trade off for consumer functionality. not to be overly vindictive, as I understand the near impossibility of running a perfectly secure service at absolutely enormous scale…but does anyone else feel LastP…

More interesting to me is that this shouldn't be an issue, they should just lose out to the competition organically. And yet here we are.

Duopoly. Plus cost of switching away once you sign up.

Network effects and monopolistic (anti-competitive) features allow bad companies to survive today. Monopolistic practices are probably a worse problem today than in the 1920s.

In the 1920s governments used regulation to break up huge firms and defeat advantages due to cost of capital (hard to start a new railroad in the 20s because the cost of trains and tracks was just so high.) Today, cost of capital is relatively less important, and things like switching cost and bundling and people valuing their time and convenience are bigger factors. We need anti-trust/government regulation to address those.

(For example, in the case of password managers, imagine if there were laws requiring publicized security audits and seamless migration to a new service of customer's choice. A competitor to Lastpass might have arrived by now.

Re: What’s in a PR statement: LastPass breach explained

#109

Earlier quoted context omitted.

I don't see any mention of local vaults on the page. Is there any password manager out there besides keepass that isn't cloud based?

There’s also Enpass ( https://www.enpass.io/ ) which markets itself as an offline password manager.

I just installed Enpass and it's exactly what I was looking for, thanks!

Re: What’s in a PR statement: LastPass breach explained

#110
post #29

Earlier quoted context omitted.

Have to plan ahead and have the keypass password in an envelope in the safe deposit box.

Something to be aware of regarding safe deposit boxes: possession of the key does not automatically grant access to the box. The bank I use maintains a list of people I allow to access my box along with their physical signature. When I needed to access my box, I had to sign in with a pen, on paper and show my ID. They compared that signature with the one I gave when I first obtained the box. I was granted access if t…

To add to this: if someone is not on that access list but is instead listed in a will, my understanding is that the will has to go through probate before access to the box is granted. It's quite likely that people would want/need access to passwords before that.
Post reply on HN