Live data from Hacker News

I Lost All Faith in LastPass

infosec.exchange

31–40 of 322 posts

Re: I Lost All Faith in LastPass

#31
Use of 3rd party password trackers has been a periodic concern for our organization. We do B2B business with banks, so the temperature is increased somewhat. There are kinds of credentials we have access to that genuinely terrify me.

I've been debating building an in-house solution for managing secrets, if for no other reason than to get all of this information off of 3rd party computers. No serious proposals have been put forth, but I don't think this stuff is exactly rocket science either. Our requirements are functionally-equivalent to a copy of passwords.xlsx on a network share.

Re: I Lost All Faith in LastPass

#32

After reading this, I acted on a decision I was on the fence about. I already have moved to Bitwarden and like it a lot better, but this post prompted me to go into LastPass and actively delete my account. The next thing to do will be to start changing passwords. As with most of us, that's a project of serious scope that I do not look forward to.

> As with most of us, that's a project of serious scope that I do not look forward to. I've spent the better part of the past three days doing just this. Get some good music and some good coffee, and it can actually be pretty cathartic. I enjoyed the hygiene exercise much more than I thought I would.

Some accounts I'm just deep sixing by changing the password with the online service but then not recording it anywhere. Buhbyeeeee!

Re: I Lost All Faith in LastPass

#33

God damnit, but what doesn't. I am sure BitWarden has its own problems and it (seems?) not 100% FOSS but its core is. LP extension and web vault ARE pure garbage: 1. It can't even recognize sites correctly ?! WTF really. I usually get 10 or so (looks like random) hits for any site but not the one that I should. 2. It offers me to extend pro support 5 years after I stopped paying for it. What I need to do for it to st…

I moved to Bitwarden from KeePass and haven't looked back.

The UIX of Bitwarden can be a bit meh at times but it's also boring, predictable, and solid. I'm just saying this as someone who hates save buttons in the upper-right hand corner of things - just... small nitpicky stuff like that. Sometimes I have to look for a button or their use of iconography confuses me a bit.

I would do my own hosting for a distributed password database but the older I get the less I trust myself to keep that stuff locked down and patched. Given the number of users I feel Bitwarden has more skin in the game to keep their solutions tight.

If you're not looking to self-host I can't recommend Bitwarden enough!

Re: I Lost All Faith in LastPass

#34
post #3

Has LastPass always been this bad and nobody noticed or did the new owners change it?

Yes. But prior to this breach it was easy to look the other way due to the extremely large amount of inertia associated with changing a manager and all your passwords. I know this was the case for me. In August we thought it was simply another "simple" breach. E.g. they got hold of some information that would be useful to spearphish or whatever but not the vaults themselves. No big deal, just be on the lookout for em…

I think it's a lesser breach than the 2011 RSA hack. That doesn't make it insignificant, however.

https://www.wired.com/story/the-full-story-of-the-stunning-r...

Re: I Lost All Faith in LastPass

#35

Earlier quoted context omitted.

Still doesn't explain why it's all not at least source-available. I'm not going to complain if they don't use open-source licenses such as MIT or (A)GPL, but straight up not making the source code publicly readable at all is a big strike against it.

There is good insight into this from this comment from them in 2014: https://1password.community/discussion/comment/114870/#Comme...

That seems to be about transitioning to an open-source model. I don't mean that. I mean simply having their git repo publicly accesible in a read-only fashion. No external contributions, no license, etc.

I see no reason not to do this, especially for such a security-oriented service. You should be striving for as much transparency as possible.

Re: I Lost All Faith in LastPass

#36

How do we know 1Password doesn't have similar glaring oversights like LP? We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word. Granted, if I had to chose today, I would instantly pick 1Passw…

There is a white paper on 1passwords design: https://1passwordstatic.com/files/security/1password-white-p... They also regularly have audits and pen tests, with the reports pushed publicly: https://support.1password.com/security-assessments/ Finally, it's been built by people who are respected in the security industry.

> Finally, it's been built by people who are respected in the security industry.

Source for this?

To me, the celebrity endorsement makes me doubt it's a serious business.

Re: I Lost All Faith in LastPass

#37

After reading this, I acted on a decision I was on the fence about. I already have moved to Bitwarden and like it a lot better, but this post prompted me to go into LastPass and actively delete my account. The next thing to do will be to start changing passwords. As with most of us, that's a project of serious scope that I do not look forward to.

So I've been doing this and I strongly recommend keeping LastPass (LP) until you've deleted all your credentials from there.

My workflow is to launch the login from LP (using the app), use those credentials, and change the passwords using Bitwarden. Otherwise, you might accidentally set a new password that doesn't actually work and have to go through painful password reset processes.

Re: I Lost All Faith in LastPass

#39
I used to be a LastPass user and also used to use their GoTo services for work. Shortly before all of this was revealed, I noticed a problem with their API and sent their customer service team message about how their API is not working correctly and is simply responding with wrong data and they basically said "too bad" and said they weren't gonna fix it due to time constraints. I even tried their forums but they deleted the Thread, marking it as "Spam".

I then stopped using my account on LastPass and literally a few weeks later they revealed the "security incident". Had to change all my passwords but I'll never get near this company ever again.

Post reply on HN