Live data from Hacker News

I Lost All Faith in LastPass

infosec.exchange

211–220 of 322 posts

Re: I Lost All Faith in LastPass

#211

Earlier quoted context omitted.

> 1Password claims are the same claims as LastPass And the whole post is about things other than the claims.

The part of the post about 1Password is basically "trust me, bro, a buddy of mine used to work there".

All the things about encryption don't fit that.

All the things about previous breaches and bug reports don't fit that.

You're describing about a tenth of the argument.

Re: I Lost All Faith in LastPass

#212
post #118
post #104

Earlier quoted context omitted.

Sure it is: an appeal to authority is not a valid step in a deductive logical argument, unless you have somehow established that the authority in question is literally infallible. Now, it's grounds for an (extremely) persuasive inference! And we know very little of what we consider known by strict deductive logic: we rely on weaker inferential reasoning the vast majority of the time. Grandparent's "means almost nothi…

If you want to go down this route, we know nothing of the real world from strict deductive reasoning because the axioms strict deduction flows from do not apply to the real world, but to mathematical universes where absolute truth is accessible to us. In reality, all statements we could use as premises are only probably true to a certain level of confidence, having themselves been constructed from inductive reasoning…

Absolutely we can't get very far with logic without relying on some axioms, and those axioms can't themselves be proven. But I don't think it follows that we need to accept every axiom someone proposes, such as what counts as a good enough authority. You and I probably agree on the basic existence and persistence of objects, for example, and we might as well pretend that we agreed to treat that as axiomatic ahead of time. I'm less sure that we'd have the same list of which people count as infallible-enough experts in which areas.

I'm really just here to stand up for the body of knowledge I learned in 9th grade Logic Camp. Good old classical Aristotelian logic is where the concept of a "logical fallacy" comes from; it really is all about deductive reasoning and not about inferences; and there really isn't a PhD-from-a-really-good-school exception to the fallacy of argument from authority. Just the same way that "X is false because George Santos said it" is simultaneously very persuasive, at least to me this week; and also a fallacy ad hominem.

Re: I Lost All Faith in LastPass

#213
post #3

Has LastPass always been this bad and nobody noticed or did the new owners change it?

I think the answers is yes, there has been grumbling about LastPass for years. Prior to them being owned by LogMeIn. They were hacked back in 2015 too: https://www.wired.com/2015/06/hack-brief-password-manager-la... > On Monday password manager service LastPass admitted it had been the target of a hack that accessed its users' email addresses, encrypted master passwords, and the reminder words and phrases that the se…

I switched to Bitwarden right after that hack and it’s been great

Re: I Lost All Faith in LastPass

#214

God damnit, but what doesn't. I am sure BitWarden has its own problems and it (seems?) not 100% FOSS but its core is. LP extension and web vault ARE pure garbage: 1. It can't even recognize sites correctly ?! WTF really. I usually get 10 or so (looks like random) hits for any site but not the one that I should. 2. It offers me to extend pro support 5 years after I stopped paying for it. What I need to do for it to st…

Which bit of bitwarden is not FOSS?

It looks like premium features are not foss, like SSO for example (but I might be wrong):

https://bitwarden.com/help/about-sso

> Login with SSO is available for all customers with an Enterprise organization

Re: I Lost All Faith in LastPass

#215
post #84

Earlier quoted context omitted.

Usually security nuts like to override the clear-text string with zeros or random characters before calling free() on it. This way, if this chunk of data stays in memory (which is most likely the case with libc's free()) it cannot be read by exploiting a buffer overflow. With garbage collected language, programmers don't know when their variable is "free()ed", since it could be held in multiple thread, and the last t…

> Usually security nuts like to override the clear-text string with zeros or random characters before calling free() on it. If you are worried, you can store the password in a byte array and zero that out. But further, a buffer overflow is practically impossible with a GCed language (especially a popular one). A programmer using a GCed language cannot write code which has a buffer overflow. That must come from a bug…

> If you are worried, you can store the password in a byte array and zero that out.

if it's a copying collector this is no guarantee of anything

but the same is true of general memory allocated with the OS (swap/THP/...), unless you use something like mlock()

Re: I Lost All Faith in LastPass

#216

I use a mix of pass(1) and LastPass, but this incident has convinced me to put everything on pass. But I don't really use it the "recommended" way, where you put the password on the first line. It's not a great fit for a consultant when half my customers want to give me my own Gmail/Atlassian/etc account. So I tend to keep big files of free-form text instead. But if I'm going to use it with a browser, the manual copy…

I’ve been using Keepass for a while, it’s great.

Re: I Lost All Faith in LastPass

#217
post #31

Use of 3rd party password trackers has been a periodic concern for our organization. We do B2B business with banks , so the temperature is increased somewhat. There are kinds of credentials we have access to that genuinely terrify me. I've been debating building an in-house solution for managing secrets, if for no other reason than to get all of this information off of 3rd party computers. No serious proposals have b…

Why not whichever Keepass client you prefer, and Syncthing (if it's even necessary for your use-case)? Open-Source, old enough to have a few revisions and be looked at pretty closely, completely off-line, and forgiving if updates are needed to passwords (with many clients having the option of merging changes with your open database). This way, you don't make the same mistake as Telegram as well; I.E., don't roll your…

> doubly so when those tools are battle-tested and looked over by actual experts.

The "actual experts" part is where I trip over this. What is the standard in this context?

I've written a lot of software that utilizes cryptographic primitives in a wide variety of business contexts. Does this make me an expert? Or, do I need some special piece of paper that says I have permission to conduct cryptographic implementation business? If so, where do I obtain this?

I thought this whole comment thread was a matter of the "actual experts" not being who they claimed to be.

Switching to Keepass, 1password, et. al. is just continuation of the same madness in my view.

Re: I Lost All Faith in LastPass

#218

I moved off of LastPass a while ago, but hadn't actually deleted my account because of laziness/inertia. This breach was finally the impetus to get me to full-on delete my vault and start the process of cleaning up my old accounts. Luckily I've been off of it long enough that I suspect most of my regularly used accounts are different anyways, but I'm still going through the process now of methodically rotating all of…

The scariest part was it was a backup of theirs that was stolen. So deleting all your info might not have even protected it. It could still be in an old backup and get stolen. :( I've deleted my stuff now anyway, it's all we can do. :(

> The scariest part was it was a backup of theirs that was stolen.

I knew it was a backup, but I don't recall seeing anywhere how old it was. Do we have any more information?

My data was confirmed deleted by them mid last year when I moved to BitWarden, and I'm hoping the backup was older. If not then I'm in the unfortunate position of being at greater risk than those who signed up more recently. I need to change everything anyway just in case, but knowing more would help with peace of mind. I used them for so many years I probably only had the 5,000 (or maybe even the 500) iteration config they never once mentioned.

Re: I Lost All Faith in LastPass

#219

Earlier quoted context omitted.

Depends on the type and language. For example, in Java strings are immutable. Therefore you can’t really write over it.

Then for sensitive strings you wouldn't use the built-in string and have to build your own? I'm not sure I see the issue, you just implement a memory-safe string class that manages arbitrary bytes, it's slower but that wasn't the goal.

I can’t remember off the top of my head which major Java library I was using a few years ago but that’s exactly how it took sensitive string params - via a char array instead of a String object. I was scratching my head why they would do that for a bit until I learned.

Re: I Lost All Faith in LastPass

#220
post #88

Earlier quoted context omitted.

I suppose it's a lot more difficult to wipe memory clean in a garbage collected language. For example: password = "my-secret-password"; // do stuff then remove the pass from memory password = "" or null or delete or unset We have no guarantee that the first string "my-secret-password" will be collected and removed any time soon whereas in C or C++ we could just memset it before freeing it. But that feels like a very…

That's only if you use immutable strings. In C# or js (and probably in others as well) you can use some form of byte arrays / buffers, and overwrite their content after use.

those references aren't real pointers though, the underlying runtime may have copied/moved around the underlying memory behind the scenes
Post reply on HN