Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

131–140 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#131
post #81

Earlier quoted context omitted.

What about just using chrome’s saved passwords and syncing? It would be great if someone can succinctly destroy that idea :D

I use this and it's convenient but the fact that Google can wipe out my entire digital identity on a whim scares me.

Google nuked an old email address of mine which was using a custom domain (free Workspace account). That email contained all my correspondence for a period of about 10 years. No way to restore it, no way to flag it to anyone at Google. I have been slowly removing Google services from my life, one of the last transitions being to Kagi.

Re: What’s in a PR statement: LastPass breach explained

#132
post #92

Earlier quoted context omitted.

At least Bitwarden encrypts the whole vault as a blob. I don't bother self-hosting because I figure I know less about hosting a Bitwarden vault than they do so it's not much more secure. If I had a local server on my LAN I might consider it, because then at least I have a few firewalls between me and the internet. I've been a happy paying Bitwarden user for several years now, since just before the first "minor" Lastp…

Yeah, I’m definitely not trained in security like the password manager engineers are. But I keep wondering if being distributed offsets that risk. That is, I can spin up Bitwarden in my Unraid machine in like five minutes and behind a reverse proxy, nobody even knows it’s there to attack. Maybe I have some security vulnerability, but it seems significantly less likely to be tested than a centralized commercial servic…

I'm one of those software devs who don't do my own stuff, I happily pay services for good products, but I know it would be "better" security (probably) to have my own server in-home and all that. I don't just choose anything, but I don't want to deal with servers or technology debugging outside of my day job. I used to run my own servers and just got tired of having to maintain them; and even "fully automated" systems need maintenance.

Re: What’s in a PR statement: LastPass breach explained

#133
post #19

Earlier quoted context omitted.

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

That sounds like a huge anti-feature to me. The few services that a next-of-kin should realistically need access to (banking and... that's pretty much it) will already have a process in place for handling this. The rest of my accounts should die when I do.

Yes, most services have a “death process” that typically involves the next of kin sending the death certificate and some type of document confirming they are in charge of the deceased’s estate. They might then set you up with your own login, or send you paper copies of all the info you need to an email account or mailing address.

Re: What’s in a PR statement: LastPass breach explained

#134

I think we can do better in protecting vaults against offline brute force attacks. As written in the this post, 1Password uses a randomly generated "secret key" together with the user-chosen master password. This "secret key" is not stored on 1Password's servers, instead it should be printed on a piece of paper and stored safely. While this is a good starting point, it significantly reduces usability, since you need…

> This "secret key" is not stored on 1Password's servers, instead it should be printed on a piece of paper and stored safely. While this is a good starting point, it significantly reduces usability, since you need this piece of paper when re-installing 1Password. you can bootstrap from an existing installation too. you’re painting this to be more of a hassle than it actually is in practice.

maybe… I sort of agree it's not a huge hassle when recovering from another still functional 1Password installation. I still think that the initial flow of asking the user to print something that looks complicated is something that turns away users who are less IT-savvy.

Re: What’s in a PR statement: LastPass breach explained

#135
post #19

Earlier quoted context omitted.

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

With KeePass, the trivial solution for this situation could just be a second subset database of relevant accounts on a thumb drive, with the password known to family individuals. That seems easier than relying on a cloud provider and some sort of half-baked insecure emergency access mode.

FYI, thumb drives die. The longest I’ve hand one work was about 7 years, more recent thumb drives tend to only last 3-4 years.

For longevity a CD / DVD might last longer, but even then those are 30 years on average.

Re: What’s in a PR statement: LastPass breach explained

#136
post #89

Earlier quoted context omitted.

Then you're stuck with Chrome forever. Same with Firefox or Safari. I wish browser vendors would agree on one password sharing protocol that's just some end-to-end encrypted blob that you could download from any browser and unlock with your password. You login to your Firefox or Google account, add passwords, and if you want to use those from the other browser you just get some http link that points to the encrypted…

You can export your passwords as a CSV file and import to other browsers (obviously if one chooses to do this, they should delete this file securely after it's been imported). Firefox, Chrome, and Edge also allow you to import passwords between browsers natively. I'm not saying that I recommend relying on the browser-based password manager (personally I use KeePassX), but I wouldn't advise against it for the reason y…

Sure, but if I have a Macbook with Safari and a Linux workstation with Firefox and a Windows gaming PC with Chrome, then I have to use a 3rd party service, right? I don't mind that personally, I'm just an old man yelling "You should have better interoperability between similar competing software services!" at clouds (in the literal and figurative sense).

Re: What’s in a PR statement: LastPass breach explained

#137
post #39

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

Seems like a great product, but something about the URL is reminiscent of those scammy websites that try to trick you into downloading scamware.

I'm admittedly a hammer seeing everything as a nail, but as a designer, I see so many opportunities in FOSS lost to basic, unnecessary branding and usability oversights. Developers shouldn't expect themselves to be able to do good design work any more than designers should expect themselves to be able to make scalable, reliable, maintainable, production-ready code. It's a specialty for a reason! Incorporating designers into FOSS projects from the beginning seems like a no-brainer, but design is nearly universally considered a superficial matter to be considered once the real work of back-end development is done (which is generally never.) It's one of the reason that open source alternatives will remain the alternatives rather than the standards. Good design takes a lot of up-front work, and once you get ignored or bikeshedded into oblivion with one design proposal, the liklihood of doing it again is pretty much zero. Definitely my white whale, but it kills me to see so many great projects that could have so much more impact if they enfranchised specialists to design the look and feel.

Re: What’s in a PR statement: LastPass breach explained

#138
post #114

Earlier quoted context omitted.

Please change your domain, looks like a phishing website. I would never clic on that anywhere else on the internet.

Clicking on a 'phishing' link can't hurt, and it's not like this person's website is ever going to be presented to you in a sensitive context (e.g. "download/install software from this site"). You should trust that your browser is secure enough to render random webpages. Excuse the self-promotion, but I take it that you're also too wary to click on this link to read my blog: https://dangerous.link/virus.exe

Any URL on the web could host a browser exploit that requires no interaction beyond visiting, but if I had to guess which one were most likely to, I'd put phishing links up there.

> You should trust that your browser is secure enough to render random webpages.

I honestly don't. Is dangerous.link/virus.exe any more dangerous than nytimes.com? Probably not. However if some 0-day, no interaction browser exploit does exist, it's easier to put the exploit on the some lookalike phishing domain rather than additionally exploit some mainstream site.

Of course I can't possibly know what URLs are "safe" to click on and which ones aren't, but I'm going to guess that URLs that look like they're intended for a phishing campaign are less likely to be safe than any other.

If your blog is go0gle-com.net, and someone emails or messages it to me, I'm not clicking on it and deleting the message.

Most often what happens is I click some sketchy looking link on my phone and it attempts to hijack the browser with popups and history modifications and whatever other shit they do to let me know my Android iPhone is infected and must be cleaned immediately.

Re: What’s in a PR statement: LastPass breach explained

#139

Assuming I'm a LastPass user and I have a sufficiently long master password with hardware based 2FA do I have anything to worry about? The one weak link is mobile authentication which bypasses 2FA. I honestly forget how that's configured.

A long password doesn't mean much by itself. If it has been previously leaked in a different breach, reused, is relatively easily brute-forced - then yes, you need to worry about that.

The bigger problem is: even if you are safe right now, your vault is out there. If at any point your master password surfaces somewhere - all your accounts are instantly compromised. So the only sensible solution IMO is to start rotating all passwords and usernames today.

Re: What’s in a PR statement: LastPass breach explained

#140

I think we can do better in protecting vaults against offline brute force attacks. As written in the this post, 1Password uses a randomly generated "secret key" together with the user-chosen master password. This "secret key" is not stored on 1Password's servers, instead it should be printed on a piece of paper and stored safely. While this is a good starting point, it significantly reduces usability, since you need…

> since the e2ee does not depend on a user chosen master password. What's the story with "my phone went in the lake" using that setup?

Since i use Google Authenticator for numerous services this is going to happen to me one day. So what I did was set it up on more than one phone.
Post reply on HN