Live data from Hacker News

Feds Link Cyberheist to 2022 LastPass Hacks

krebsonsecurity.com

1–10 of 266 posts

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#7
post #3

The way LastPass had handled the incident back in 2022 is so disappointing. I don’t even how anyone could even recommend using them again.

After my experience with LastPass (and trying to report cryptographic weaknesses), my answer to people considering switching is "RUN DON'T WALK"

https://soatok.blog/2023/01/21/how-you-respond-to-security-r...

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#8

Me, looking at my local KeepassXC, calm, sticking with it.

They can pry my offline key file from my cold dead hard drive. Some things shouldn't be on the internet.

How do you make sure that file does not end up corrupt?

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#9
post #3

The way LastPass had handled the incident back in 2022 is so disappointing. I don’t even how anyone could even recommend using them again.

And still is disappointing:

> Reached for comment, LastPass said it has seen no definitive proof — from federal investigators or others — that the cyberheists in question were linked to the LastPass breaches. “Since we initially disclosed this incident back in 2022, LastPass has worked in close cooperation with multiple representatives from law enforcement,” LastPass said in a written statement. “To date, our law enforcement partners have not made us aware of any conclusive evidence that connects any crypto thefts to our incident. In the meantime, we have been investing heavily in enhancing our security measures and will continue to do so.”

So, there's slightly less than conclusive evidence, and how much evidence should you need anyway, given the alternative hypotheses?

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#10
post #3

The way LastPass had handled the incident back in 2022 is so disappointing. I don’t even how anyone could even recommend using them again.

Horrible, and waiting until Christmas week to disclose it while weak master passwords (no min length reqs) and a laughable PBKDF2-HMAC-SHA256 with 5,000 iterations (this was set to 100,100 for new accounts after Feb 2018) let the attackers brute-force their way in…
Post reply on HN