Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

271–280 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#271
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

Doesn't this create the same problem, albeit on a different pain point? Now the service/methods you use to sync and store your DBs are a problem without much benefit? I've seen people use keepass and then google drive, which just seems silly at that point if you're going to negate keepass' benefit (local management) just to attempt to gain some of the benefits of managed services like bitwarden in very clunky ways.

unlike the others where your only option is a single database, some keepass apps allows you to have multiple databases open at a time which means you can split up your sites/passwords depending on how important they are and have a different levels of security for each one.

i have 1 vault with any important things and the other one just has everything else and i don't need to worry as much about the security of it or worry about where its stored and if that's secure.

its also great not having to type in a long master password just to get the login details for some small forum where it really wouldnt be a huge deal if somebody got access that vault. half of passwords in that vault are there mainly because i want them to be autofilled, not because i need to keep them secure

Re: What’s in a PR statement: LastPass breach explained

#272

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

One of the major features I'm looking for is the ability to easily list passwords by age. The use case is "I want an easy access "todo list" of all passwords to update that are older than (x months|specific date)" I would use this after notification of a breach or on my own schedule. Having to manually inspect each item is not acceptable. Bonus points if I can specify a "policy" for items (using tags and groups is ac…

KeepassXC does this, probably other keepass clients too. There are columns for creation, modification, expiration, and last-access, all of which can be sorted on. Each entry can have an expiration date/age.

Re: What’s in a PR statement: LastPass breach explained

#273
post #193

Earlier quoted context omitted.

I think the whole LastPass fiasco just shows why everyone wants to get into the SaaS business so bad - subscription revenue is the gift that keeps on giving. LastPass has proven they have no business safekeeping anyone else's credentials. Anyone who cares a modicum about their security will have migrated off. But migrating off is a HUGE pain (people will need hours to update hundreds of passwords), and LastPass's ann…

Migrating from LastPass to another password manager is actually a pretty easy process. Many password managers can import passwords from LastPass.

Actually, it's a very hard process since the easy process doesn't migrate all the data

Re: What’s in a PR statement: LastPass breach explained

#274

My LastPass account literally had ONE iteration of pbkdf2 ( https://i.imgur.com/34aIOzO.png ) and it seems I'm not the only one: https://snabelen.no/@vegardlarsen/109575002998425618 Absolutely amateurish. I hope no one trusts LastPass ever again.. I know I won't. My account was registered 2010 if anyone is interested.

Thank you for this confirmation. I already suspected that LastPass failed upgrading people’s security settings for each change of defaults they made. But so far I’ve only seen one person who found an account with one iteration (that was their very first default). Now you gave me two more.

Re: What’s in a PR statement: LastPass breach explained

#275

Earlier quoted context omitted.

I use and like it

Two questions: 1) How's it do at syncing / conflicts? 2) In the Android app, do you know if there's a way to use the fingerprint feature without storing your master password or an encrypted derivative of it to non-volatile memory? For those scratching their heads at #2, it's motivated by my lukewarm trust of vendor-implemented components of Android Keystore. Some competing apps address it by making you authenticate w…

Never had a conflict so far, using on mobile and multiple OS, so I guess it just works I host the vault on the cloud

Regarding 2), no I don't know but good question. Using the same master password is annoying as you don't type the same on mobile

Re: What’s in a PR statement: LastPass breach explained

#276

Earlier quoted context omitted.

With KeePass, the trivial solution for this situation could just be a second subset database of relevant accounts on a thumb drive, with the password known to family individuals. That seems easier than relying on a cloud provider and some sort of half-baked insecure emergency access mode.

FYI, thumb drives die. The longest I’ve hand one work was about 7 years, more recent thumb drives tend to only last 3-4 years. For longevity a CD / DVD might last longer, but even then those are 30 years on average.

7 years continuously plugged? All pen-drives that I use sporadically still work.

Re: What’s in a PR statement: LastPass breach explained

#277

Earlier quoted context omitted.

I use this and it's convenient but the fact that Google can wipe out my entire digital identity on a whim scares me.

Google nuked an old email address of mine which was using a custom domain (free Workspace account). That email contained all my correspondence for a period of about 10 years. No way to restore it, no way to flag it to anyone at Google. I have been slowly removing Google services from my life, one of the last transitions being to Kagi.

You're telling like they didn't send tons of notifications emails before they did so, eh? And after they "nuked" (you lost your access), you still had months of time to pay and restore access.

And besides, if it was your private domain, you could submit that to google (I didn't follow up, but perhaps they spared the nuke for regular folks who just used their custom domain with gmail)

I am more worried not having access to my REGULAR Gmail account, with none to contact with, rather than G Workspace.

Re: What’s in a PR statement: LastPass breach explained

#278

Earlier quoted context omitted.

Since i use Google Authenticator for numerous services this is going to happen to me one day. So what I did was set it up on more than one phone.

You can back the secrets up to a text file, print them out, etc. too. They're short Base32 strings and TOTP is a standardized protocol with an RFC (6238) and everything.

Except it is cumbersome to doo on Google Authenticator. You must press export to get shown a giant QR code. You can't screenshot it. Must photo with different phone and print on a piece of paper for offline storage.

Re: What’s in a PR statement: LastPass breach explained

#279

This vaguely reminds me of Rackspace's catastrophic failure a few weeks ago. Both companies were owned by private equity firms.

I would love to have a service that cataloged all private equity takeovers so that I could migrate away from them. Every time they milk the brand and slowly atrophy.

This would be very useful!

Re: What’s in a PR statement: LastPass breach explained

#280

Earlier quoted context omitted.

What else is in your self deposit box? I thought only rich people with gold and jewels and spies with fake passports and ready currency used safe deposit boxes.

I'm middle class. We have a safe deposit box where I keep stuff that would be a pain in my ass to replace in the event of a fire/flood/etc. Said items are titles to my vehicles and home, my marriage license, the will of a family member I've been entrusted with, birth certificates for my self and family members, and a couple of keepsakes for the kids that I'm very long on. It only costs me about $80 per year, and it b…

A local bank near us provides a free one as long as you keep $100 min balance. So ends up being very cheap offsite backup to store important documents, a backup hard drive of most precious data, etc.
Post reply on HN