Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

111–120 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#112
post #89
post #81

Earlier quoted context omitted.

What about just using chrome’s saved passwords and syncing? It would be great if someone can succinctly destroy that idea :D

Then you're stuck with Chrome forever. Same with Firefox or Safari. I wish browser vendors would agree on one password sharing protocol that's just some end-to-end encrypted blob that you could download from any browser and unlock with your password. You login to your Firefox or Google account, add passwords, and if you want to use those from the other browser you just get some http link that points to the encrypted…

You can export your passwords as a CSV file and import to other browsers (obviously if one chooses to do this, they should delete this file securely after it's been imported).

Firefox, Chrome, and Edge also allow you to import passwords between browsers natively. I'm not saying that I recommend relying on the browser-based password manager (personally I use KeePassX), but I wouldn't advise against it for the reason you're describing. Just sharing some info! Please let me know if I'm mistaken on any of this.

Re: What’s in a PR statement: LastPass breach explained

#113
post #92
post #57

Earlier quoted context omitted.

Same, I held onto Lastpass much longer than I would have put up with any less-essential SaaS product. Finally moved to Bitwarden and couldn't be happier. Still trying to decide if I want to self-host it or not, but more breaches of cloud-based password managers like this one may push me in that direction.

At least Bitwarden encrypts the whole vault as a blob. I don't bother self-hosting because I figure I know less about hosting a Bitwarden vault than they do so it's not much more secure. If I had a local server on my LAN I might consider it, because then at least I have a few firewalls between me and the internet. I've been a happy paying Bitwarden user for several years now, since just before the first "minor" Lastp…

Yeah, I’m definitely not trained in security like the password manager engineers are. But I keep wondering if being distributed offsets that risk. That is, I can spin up Bitwarden in my Unraid machine in like five minutes and behind a reverse proxy, nobody even knows it’s there to attack. Maybe I have some security vulnerability, but it seems significantly less likely to be tested than a centralized commercial service. Curious if others have thoughts. I’d happily pay Bitwarden for whatever.

Re: What’s in a PR statement: LastPass breach explained

#114

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

Please change your domain, looks like a phishing website. I would never clic on that anywhere else on the internet.

Clicking on a 'phishing' link can't hurt, and it's not like this person's website is ever going to be presented to you in a sensitive context (e.g. "download/install software from this site"). You should trust that your browser is secure enough to render random webpages.

Excuse the self-promotion, but I take it that you're also too wary to click on this link to read my blog: https://dangerous.link/virus.exe

Re: What’s in a PR statement: LastPass breach explained

#115
I think we can do better in protecting vaults against offline brute force attacks.

As written in the this post, 1Password uses a randomly generated "secret key" together with the user-chosen master password. This "secret key" is not stored on 1Password's servers, instead it should be printed on a piece of paper and stored safely. While this is a good starting point, it significantly reduces usability, since you need this piece of paper when re-installing 1Password.

At heylogin, we are rethinking this cryptographic design. In our case, a random secret is generated inside the smartphone's security chip. From this secret, all keys for encryption are derived. The smartphone app and the browser extension is end-to-end encrypted and authenticated using an out-of-band QR code. This results in the following UX: To log into a website in the browser, the user needs to confirm on the phone. The app now provides the extension with temporary access to the passwords etc (a little bit more complicated to explain here).

Thus, if the same breach would happen to us, the vaults would still be secure, since the e2ee does not depend on a user chosen master password.

It's not easy to get a foot in this market, but I am confident, we can do it.

Re: What’s in a PR statement: LastPass breach explained

#116
post #14

Shows the need for true multi factor. We should not have a bunch of virtual MFAs and passwords in one service even if said service make it convenient. Password managers should be held to a high standard but we should also never depend just on a password for protection of anything of value.

Maybe before I die multiple YubiKey support can be considered a standard. Even AWS doesn’t support it which is just unfathomable. They support one, so you can’t have a backup, so they may as well not have the feature.

Re: What’s in a PR statement: LastPass breach explained

#117

Earlier quoted context omitted.

I use and like it

Two questions: 1) How's it do at syncing / conflicts? 2) In the Android app, do you know if there's a way to use the fingerprint feature without storing your master password or an encrypted derivative of it to non-volatile memory? For those scratching their heads at #2, it's motivated by my lukewarm trust of vendor-implemented components of Android Keystore. Some competing apps address it by making you authenticate w…

Which apps handle this better? I'm not supremely concerned about my password being pulled from memory, from an attack surface perspective, but I am curious which apps address this best and how.

Re: What’s in a PR statement: LastPass breach explained

#118
post #4

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

I don't think 1Password has any free tier, at least pretty sure it doesn't have free syncing across devices anymore or even ever.

It depends on how one views "free tier," since if one doesn't pay when requested (whether from the end of a trial, just normal expiry, or if there's a separation event from the "free family for business") the vault remains yours and active, but goes read only.

I don't know what would lead you to believe there's any syncing restriction from 1Password, but if that is your experience it's almost certainly a bug, since to the very best of my knowledge 1Password doesn't engage in hostage-taking like that

Re: What’s in a PR statement: LastPass breach explained

#119

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

One of the major features I'm looking for is the ability to easily list passwords by age.

The use case is "I want an easy access "todo list" of all passwords to update that are older than (x months|specific date)"

I would use this after notification of a breach or on my own schedule. Having to manually inspect each item is not acceptable.

Bonus points if I can specify a "policy" for items (using tags and groups is acceptable if they can be incorporated into the search without too much effort). Super bonus points if the tool generates notifications and todo list automatically.

Why these features are not standard boggles the mind. LastPass used to have this feature but removed it for who-know-why reasons.

Re: What’s in a PR statement: LastPass breach explained

#120
post #69

I'm not sure about the insight. But i hate the UI, UX of Lastpass. Why it's so hard to change for simplicty and ease of use ? Is it dark pattern, is it technically impossible due to technical architectural complexity, or tech debt,.. ? At least the UI tells me something about the internal.

No idea what you're talking about. I manage LastPass for 200 not very tech savvy users and no one has any problems using it.

The login text input button overlay is often obscured by other elements with click triggers, in some cases making it unusable. Many sites don’t populate with the input button so you have to get the password using context menus.

I’ve trained 3-4 non-technical users on LastPass and none of them found it intuitive or easy.

I’ve managed it in a corporate environment for dozens of users who were younger and more tech savvy, for them it was mostly okay.

Post reply on HN