Incredibly pathetic. I am so disappointed in LastPass. I was willing to forgive their subpar UX because hey, at least my passwords were safe. I've moved over to Bitwarden and am happy for now, but man what a shitshow.
I love BitWarden, but coincidentally yesterday I saw a problem pop up on Reddit that was terrifying: There is a known issue where changing your master password can cause you to lose all your data: https://bitwarden.com/help/account-encryption-key/#rotate-yo... What?! Of course, if you are careful and follow all the instructions, in theory you could avoid this. But why allow such a foot-gun?
What’s in a PR statement: LastPass breach explained
191–200 of 292 posts
Re: What’s in a PR statement: LastPass breach explained
#192Catastrophic breach after catastrophic breach since 2011. Lastpass has failed their fiduciary duty as a steward of sensitive information and IMO exhibited gross negligence in not encrypting URI data, ostensibly as a trade off for consumer functionality. not to be overly vindictive, as I understand the near impossibility of running a perfectly secure service at absolutely enormous scale…but does anyone else feel LastP…
I think the whole LastPass fiasco just shows why everyone wants to get into the SaaS business so bad - subscription revenue is the gift that keeps on giving. LastPass has proven they have no business safekeeping anyone else's credentials. Anyone who cares a modicum about their security will have migrated off. But migrating off is a HUGE pain (people will need hours to update hundreds of passwords), and LastPass's ann…
It took less than 10mn to migrate to Bitwarden. What do you mean by migrate?
Re: What’s in a PR statement: LastPass breach explained
#193Catastrophic breach after catastrophic breach since 2011. Lastpass has failed their fiduciary duty as a steward of sensitive information and IMO exhibited gross negligence in not encrypting URI data, ostensibly as a trade off for consumer functionality. not to be overly vindictive, as I understand the near impossibility of running a perfectly secure service at absolutely enormous scale…but does anyone else feel LastP…
I think the whole LastPass fiasco just shows why everyone wants to get into the SaaS business so bad - subscription revenue is the gift that keeps on giving. LastPass has proven they have no business safekeeping anyone else's credentials. Anyone who cares a modicum about their security will have migrated off. But migrating off is a HUGE pain (people will need hours to update hundreds of passwords), and LastPass's ann…
Re: What’s in a PR statement: LastPass breach explained
#194Earlier quoted context omitted.
FYI, thumb drives die. The longest I’ve hand one work was about 7 years, more recent thumb drives tend to only last 3-4 years. For longevity a CD / DVD might last longer, but even then those are 30 years on average.
I still have my first 128MB thumb drive, bought in 2001 or so. Works fine. Holds a kdbx file fine :)
Just to offer a counter anecdote, I had a flash drive fail with my kdbx file on it and it was a monumental pain in the ass to recover from because I didn't have backups. Have backups. Especially for critical passwords that lock you out of everything. Flash drives do fail. Statistical failures SPECIFICALLY mean that some people will not fail, but that doesn't mean failures don't happen or that they're unlikely/uncommon.
Re: What’s in a PR statement: LastPass breach explained
#195Incredibly pathetic. I am so disappointed in LastPass. I was willing to forgive their subpar UX because hey, at least my passwords were safe. I've moved over to Bitwarden and am happy for now, but man what a shitshow.
I love BitWarden, but coincidentally yesterday I saw a problem pop up on Reddit that was terrifying: There is a known issue where changing your master password can cause you to lose all your data: https://bitwarden.com/help/account-encryption-key/#rotate-yo... What?! Of course, if you are careful and follow all the instructions, in theory you could avoid this. But why allow such a foot-gun?
> Making changes in a session with a "stale" encryption key will cause data corruption that will make your data unrecoverable.
I love Bitwarden but this is just… borderline hilarious. Laughing nervously. God damn it, don’t write a damn “help” article about it, create a P0 bug, fix it asap and write a post-mortem.
Field report: I tried to see this UX in action and while it is indeed bad, there are some redeeming factors:
- By default, you don’t rotate encryption key when you change master password. This is opt-in. I’m not qualified to say whether this is a good default or not.
- If you do, a full modal warning pops up explaining to log out or wait an hour:
- They invalidate the sessions automatically, but this is delayed.
AIUI you have to tick the box, not read the warning, hurry to a different device and modify the vault, and have pissed off the cache invalidation gods all at the same time to reach corruption.
Re: What’s in a PR statement: LastPass breach explained
#196Earlier quoted context omitted.
Have to plan ahead and have the keypass password in an envelope in the safe deposit box.
What else is in your self deposit box? I thought only rich people with gold and jewels and spies with fake passports and ready currency used safe deposit boxes.
Re: What’s in a PR statement: LastPass breach explained
#197I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…
Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…
Re: What’s in a PR statement: LastPass breach explained
#198Earlier quoted context omitted.
I think the whole LastPass fiasco just shows why everyone wants to get into the SaaS business so bad - subscription revenue is the gift that keeps on giving. LastPass has proven they have no business safekeeping anyone else's credentials. Anyone who cares a modicum about their security will have migrated off. But migrating off is a HUGE pain (people will need hours to update hundreds of passwords), and LastPass's ann…
> But migrating off is a HUGE pain It took less than 10mn to migrate to Bitwarden. What do you mean by migrate?
Re: What’s in a PR statement: LastPass breach explained
#199When there is a problem, how helpful is the customer service? If not then a person stands to be locked out of critical aspects of their digital life
Re: What’s in a PR statement: LastPass breach explained
#200Earlier quoted context omitted.
More interesting to me is that this shouldn't be an issue, they should just lose out to the competition organically. And yet here we are.
Most economic models of equilibrium explicitly state that they model outcomes “in the long run” for precisely this type of a circumstance. Should a firm with a history of these types of problems lose out to competition organically? Sure, but there is no binary “losing out tot he competition” switch that just gets flipped one day. This is part of the reason why I get so frustrated with the laissez faire mindset/meme.
Crucially, these models don't actually state that the companies that do the best job will win out, but that the most profitable ones do.
The problem arises when screwing over the user is more profitable than doing it properly.
That's why the tech industry is so ethically corrupt today. There's very little regulation to make dark patterns and sloppy security practices more costly than they are profitable.