Live data from Hacker News

LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

krebsonsecurity.com

1–10 of 77 posts

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#2
Choosing a good key derivation function has always been critical to making passwords work. I guess lastpass didn't do that.

I have not benchmarked these recently, but I fear that they had to compromise # of iterations to give "2012 low-end Android device" some chance of ever being able to unlock their vault. As a result, everyone else is vulnerable. Adding icing on the cake is leaking everyone's encrypted vault. Whoops!

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#4
>>> KrebsOnSecurity last month interviewed a victim who recently saw more than three million dollars worth of cryptocurrency siphoned from his account. That user signed up with LastPass nearly a decade ago, stored their cryptocurrency seed phrase there, and yet never changed his master password — which was just eight characters. Nor was he ever forced to improve his master password.

This does fascinate me. How many people who have won the crypto-lottery like that still keep invested? Is most of the crypto gain unrealised so far? Or most of it been drained out?

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#5
The first paragraph very nearly lost me – irrational, rage bait, directly contradicts later stated facts – but there’s some good content later. The chief complaint seems to be that LastPass is not forcing this upgrade, they are just blast emailing unaffected people that they “forced” it while not actually doing so. And they’ve pulled similar stunts in the past, and in current communication seem to clearly be blaming users for their weak settings and passwords while erasing the fact that LastPass chose the settings, ok’d the passwords, botched the upgrade, and still hasn’t fixed most of their mistakes.

Everybody with a clue knows LastPass is a lost cause, but what’s more interesting to me is how we can generalize the lessons we’re learning here. I’d propose that user blaming in general is evidence of bad tech and magical thinking around it, and that points a finger at some very interesting targets.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#7

>>> KrebsOnSecurity last month interviewed a victim who recently saw more than three million dollars worth of cryptocurrency siphoned from his account. That user signed up with LastPass nearly a decade ago, stored their cryptocurrency seed phrase there, and yet never changed his master password — which was just eight characters. Nor was he ever forced to improve his master password. This does fascinate me. How many p…

Or not realize they have a terrible password. The thing I notice is not all services allow spaces. A sentence of regular dictionary words has proven a good password for a long while otherwise.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#8

>>> KrebsOnSecurity last month interviewed a victim who recently saw more than three million dollars worth of cryptocurrency siphoned from his account. That user signed up with LastPass nearly a decade ago, stored their cryptocurrency seed phrase there, and yet never changed his master password — which was just eight characters. Nor was he ever forced to improve his master password. This does fascinate me. How many p…

The more early someone was in mining or buying Bitcoin, the greater the possibility that they believe in Bitcoin in and of itself.

I.e. to someone who was early into Bitcoin, they might wish to never sell off all of their BTC.

And besides, even if you wanted to sell off your Bitcoins, there are a number of things to consider:

- Taxes. Why sell millions of USD worth of Bitcoin now, and pay taxes on all of it today? Possibly better in some situations to sell enough to live comfortably for a few years, and then sell more later when you need to again.

- What are you gonna do with the money instead? Put it in stocks? Buy a bunch of houses?

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#9
post #6

“For example, another important default setting in LastPass is the number of “iterations,” or how many times your master password is run through the company’s encryption routines” How does this help?

If you are complaining about the idea of iterating a hash multiple times, this is actually a fairly standard construction to increase the cpu cost of brute forcing hashes.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#10
post #6

“For example, another important default setting in LastPass is the number of “iterations,” or how many times your master password is run through the company’s encryption routines” How does this help?

Ok I googled. I guess it makes sense as it helps to protect against pre-hashed rainbow tables or dictionary attacks by making them more computationally expensive.
Post reply on HN