Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

161–170 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#161

Assuming I'm a LastPass user and I have a sufficiently long master password with hardware based 2FA do I have anything to worry about? The one weak link is mobile authentication which bypasses 2FA. I honestly forget how that's configured.

I initially assumed I would be safe because of 2FA. Sadly it looks like this is not the case, the second factor is used to access the encrypted data, not decrypt the data. As the attacker already has the encrypted data, they have bypassed the stage where 2FA is providing protection. This appears to also be the case for 1password and bitwarden, so not specifically a lastpass failure.

Re: What’s in a PR statement: LastPass breach explained

#162

A (perhaps) unconventional approach to password management, which I recommend to anyone. If you enjoy complexity, this is too simple for you. No one can steal something that's not written down Just like the Navajo code talkers in WW II had a system that was memorized, so even if the Japanese captured another Navajo and tortured him (which they did), he couldn't reveal the code. Have some hints to yourself, and store…

[deleted]

Re: What’s in a PR statement: LastPass breach explained

#163
post #130
post #129

Earlier quoted context omitted.

For some reason "MacOS" appears twice for me in the "options" section. I'd love for some more options. - Doesn't require a subscription - Doesn't require a web login - Allows local vaults

gnu-pass and bitwarden tick those boxes at least- any other requirements that maybe you simply assume should be available (like browser extensions)

Thanks, I'll remember those when my current 1Password 7 setup becomes unviable.

Re: What’s in a PR statement: LastPass breach explained

#164
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

Doesn't this create the same problem, albeit on a different pain point? Now the service/methods you use to sync and store your DBs are a problem without much benefit? I've seen people use keepass and then google drive, which just seems silly at that point if you're going to negate keepass' benefit (local management) just to attempt to gain some of the benefits of managed services like bitwarden in very clunky ways.

Re: What’s in a PR statement: LastPass breach explained

#165
Can someone point out a big flaw in my password management system? I have always felt kinda dumb for not using a PW manager but my system has worked for the last ~10+ years and I have never had any issues.

I memorized a small function that takes the product name as input and spits out a password. it achieves the goal of having a unique pw for every service without having to write anything down (in software or on paper). I had to amend it to account for some services that require you to reset your password to a new one and for sites with annoyingly specific password formats (i.e. 3 special chars).

Re: What’s in a PR statement: LastPass breach explained

#166

Catastrophic breach after catastrophic breach since 2011. Lastpass has failed their fiduciary duty as a steward of sensitive information and IMO exhibited gross negligence in not encrypting URI data, ostensibly as a trade off for consumer functionality. not to be overly vindictive, as I understand the near impossibility of running a perfectly secure service at absolutely enormous scale…but does anyone else feel LastP…

in one regard i'm with this and i do want them to have a fiduciary like responsibility

on the other hand i almost see this as similar to the groups of people who swarm towards televangelists, who sign up to donate their last dollar to a millionaire who's scamming them for everything they're worth

if you trust it, then maybe falling for it is the best thing for you, to learn this lesson the hard way :/

Re: What’s in a PR statement: LastPass breach explained

#167

Can someone point out a big flaw in my password management system? I have always felt kinda dumb for not using a PW manager but my system has worked for the last ~10+ years and I have never had any issues. I memorized a small function that takes the product name as input and spits out a password. it achieves the goal of having a unique pw for every service without having to write anything down (in software or on pape…

[deleted]

Re: What’s in a PR statement: LastPass breach explained

#168

Can someone point out a big flaw in my password management system? I have always felt kinda dumb for not using a PW manager but my system has worked for the last ~10+ years and I have never had any issues. I memorized a small function that takes the product name as input and spits out a password. it achieves the goal of having a unique pw for every service without having to write anything down (in software or on pape…

Not necessarily a huge flaw and indeed it’s a method I used for a long time too - but what it doesn’t really help with is when there’s a breach and one of your passwords is in a leak. What do you do: make (and remember) an exception and the second choice function? Or change all your passwords so an amended function still holds true for all sites? With a password manager you just change the breached one and that’s it.

Re: What’s in a PR statement: LastPass breach explained

#169

Can someone point out a big flaw in my password management system? I have always felt kinda dumb for not using a PW manager but my system has worked for the last ~10+ years and I have never had any issues. I memorized a small function that takes the product name as input and spits out a password. it achieves the goal of having a unique pw for every service without having to write anything down (in software or on pape…

This is pretty cool, and could even make a great "no storage" type product here. Hmm 1 problem could be forced password changes? I've noticed some sites at times require password changes.

Re: What’s in a PR statement: LastPass breach explained

#170

Earlier quoted context omitted.

> since the e2ee does not depend on a user chosen master password. What's the story with "my phone went in the lake" using that setup?

Since i use Google Authenticator for numerous services this is going to happen to me one day. So what I did was set it up on more than one phone.

I also have two phones with Google Authenticator. Is that a bad idea?
Post reply on HN