Live data from Hacker News

LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

krebsonsecurity.com

41–50 of 77 posts

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#41
> Since then, a steady trickle of six-figure cryptocurrency heists targeting security-conscious people

Such as…

> That user signed up with LastPass nearly a decade ago, stored their cryptocurrency seed phrase there, and yet never changed his master password — which was just eight characters.

I don’t want to victim blame and I agree with the anti-LastPass sentiments. I just find it amusing that Krebs keeps trotting out the “security conscious“ victims with 8 character master passwords.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#42
1Password does it right: Everyone's master password is augmented with a big randomly generated "Secret Key" that is stored (only) on their machine.

Even if their entire database was leaked, the Secret Key guarantees a good minimum password strength.

(The main drawback is that the user now needs to save this Secret Key or get locked out forever. But it's less sensitive than the master passphrase, since it's mainly designed to protect against this mass-leak scenario.)

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#43

The first paragraph very nearly lost me – irrational, rage bait, directly contradicts later stated facts – but there’s some good content later. The chief complaint seems to be that LastPass is not forcing this upgrade, they are just blast emailing unaffected people that they “forced” it while not actually doing so. And they’ve pulled similar stunts in the past, and in current communication seem to clearly be blaming…

Can someone explain to me what is the advantage of using something like LastPass over simply the in-built password manager that Firefox or other browsers have? I know that LastPass can be used for desktop applications too, but if you are only using a password for the web, is LastPass offering anything more than the in-built browser password manager?

Syncing to my phone apps is my big reason.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#44
post #10
post #6

“For example, another important default setting in LastPass is the number of “iterations,” or how many times your master password is run through the company’s encryption routines” How does this help?

Ok I googled. I guess it makes sense as it helps to protect against pre-hashed rainbow tables or dictionary attacks by making them more computationally expensive.

Usually people use salt to protect against rainbow tables.

Iterating a hash function (e.g . PBKDF2) is most just a way to make hashing take longer. Since attackers have to make very many gueses (while legit users only have to hash the password once), increasing each guess by a few seconds can really slow things down.

However in modern apps they usually try to use more complex constructions like argon2 to make it so you cant use GPUs to do lots of guesses at once.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#45

As somebody that has been using lastpass for many years and continues to do so… I just do not understand how people who pick weak master passwords complain about this. The lastpass documentation makes clear over and over that your entire DB can be compromised but as long as they don’t have the master password, you are safe. How people do not think one step past this and realize they need a very secure master password…

You are overestimating the technical ability of users by orders of magnitude. Even people who are nominally "experts" in one technical area at least adjacent to computing who are completely useless outside of the most basic thing. Running a business or a project implies dealing with people as they actually are not as we might hope they could be.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#46
post #41

> Since then, a steady trickle of six-figure cryptocurrency heists targeting security-conscious people Such as… > That user signed up with LastPass nearly a decade ago, stored their cryptocurrency seed phrase there, and yet never changed his master password — which was just eight characters. I don’t want to victim blame and I agree with the anti-LastPass sentiments. I just find it amusing that Krebs keeps trotting ou…

[deleted]

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#47

The first paragraph very nearly lost me – irrational, rage bait, directly contradicts later stated facts – but there’s some good content later. The chief complaint seems to be that LastPass is not forcing this upgrade, they are just blast emailing unaffected people that they “forced” it while not actually doing so. And they’ve pulled similar stunts in the past, and in current communication seem to clearly be blaming…

Can someone explain to me what is the advantage of using something like LastPass over simply the in-built password manager that Firefox or other browsers have? I know that LastPass can be used for desktop applications too, but if you are only using a password for the web, is LastPass offering anything more than the in-built browser password manager?

Safari's built-in pw manager:

- until recently, didn't have 2fa

- doesn't support multiple domains under the same account (e.g., the stackexchange network is considered one site per subdomain)

- doesn't support generating complex passwords (it'll generate passwords but I'd hardly call them complex…)

- doesn't support credentials not associated with websites (e.g., an SSH login, a bank pin…)

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#48
post #9
post #6

“For example, another important default setting in LastPass is the number of “iterations,” or how many times your master password is run through the company’s encryption routines” How does this help?

If you are complaining about the idea of iterating a hash multiple times, this is actually a fairly standard construction to increase the cpu cost of brute forcing hashes.

Asking a question isn’t complaining.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#49
post #21

Earlier quoted context omitted.

The more early someone was in mining or buying Bitcoin, the greater the possibility that they believe in Bitcoin in and of itself. I.e. to someone who was early into Bitcoin, they might wish to never sell off all of their BTC. And besides, even if you wanted to sell off your Bitcoins, there are a number of things to consider: - Taxes. Why sell millions of USD worth of Bitcoin now, and pay taxes on all of it today? Po…

This is a classic issue with money. What do you do if you're Taylor Swift? You're a 750 millionaire, with the next couple 100 on the way from this tour. Whelp, spent the first 50 on a house all humans will drool over. Got the compulsory car. Got the compulsory jet. Got the compulsory yacht (not quite as large as Bezos' (ehmm, banana?) that could not leave its construction port). [1] And with the other 600 million? Pr…

Use it to give people jobs. Open up restaurants and build schools and hospitals. Help friends start their own businesses, stimulate the economy. Tony Hseih, RIP, didn't have a private air force, but he made downtown Vegas. Someone's already started an electric car company, and built a rocket company to go to Mars, so that's been done, but there's just so much out there. Rhianna's got her clothing line for people who aren't models. Cars and mansions are boring.

Re: LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password

#50

>>> KrebsOnSecurity last month interviewed a victim who recently saw more than three million dollars worth of cryptocurrency siphoned from his account. That user signed up with LastPass nearly a decade ago, stored their cryptocurrency seed phrase there, and yet never changed his master password — which was just eight characters. Nor was he ever forced to improve his master password. This does fascinate me. How many p…

I still hold ~1M US worth of crypto all together, which is roughly the majority of my net worth. Been in since early days. If I'd guess I've probably "realized" (sold/used for payment for non-crypto goods or services) ~20~30k$ or so over the years? I still donate here and there and use it for payment for goods and services when I can.

I probably lost at least another ~1M$ worth (not projected: at the time. it sucks but you move on) through completely preventable ways when acting agains my own better knowledge. Check. Your. Backups. 3-2-1.

I made great "second-order-gains" from my dabbling in crypto I guess you can say, since I made a decent career in the crypto industry. Most people I know in the industry personally who have been around for as long are still invested to various degrees and defi people gonna defi.

I'd probably balance my portfolio more towards real-estate, commodities and maybe stocks if I'd be smart about it but I have enough of anxiety around taxes that I'm postponing doing anything that means having to file paperwork or that may be illegal. No accounts on exchanges. If it really comes down to it I guess I'd had to consider changing countries if my country of residence becomes hostile enough that using my crypto becomess untenable. I'm still very much a "true believer".

(throwaway for obvious reasons)

Post reply on HN