Me, looking at my local KeepassXC, calm, sticking with it.
They can pry my offline key file from my cold dead hard drive. Some things shouldn't be on the internet.
Feds Link Cyberheist to 2022 LastPass Hacks
21–30 of 266 posts
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#22I'm a bit confused on how the LastPass hack enabled the loss of passwords. I assume it works the way that I understand 1Password to work which should mean this would still be very difficult to impossible to do. Can anyone explain what I'm wrong about in terms of how the password managers work or how LastPass works differently? So the way that I understand 1Password to work is that the decryption key is split in two:…
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#23“Bitcoin has never been hacked” Don’t have to hack crypto to steal all the crypto.
Bitcoin has never been hacked. The victims did not practice proper key management. The victims got hacked because of their own insecure key management, not because of any vulnerability in Bitcoin. To claim otherwise is like claiming that because people can steal improperly secured code signing or TLS certificate private keys, all code signing and TLS certificates are inherently, fundamentally, and automatically broke…
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#24But what's also hard to believe is that people storing millions of dollars of "collectables" would not change their passwords on at least a yearly basis.
I know that password rotation for its own sake is no longer best practice, but in this case it still seems quite prudent. No?
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#25Stick your passwords in the cloud, they said, nothing could go wrong they said.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#261Password truly doesn’t get enough credit for the choice to encrypt every vault with a high entropy secret key passed device to device. It surely costs them in UX and support load, but it would have made a breach like this essentially inconsequential.
In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypted gzipped file (with the passphrase I’ll leave them) containing my passwords in a csv file.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#27Earlier quoted context omitted.
How do you make sure that file does not end up corrupt?
So what if it does? Worst case you just go through the account recovery process at each institution. Password managers are a convenience. Data integrity isn’t critical but security is.
Well, worst case is your account with Google, which you can kiss goodbye.
But as we all know, that’s security. If the account recovery is the weakest link, it gets attacked.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#28Me, looking at my local KeepassXC, calm, sticking with it.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#29I'm a bit confused on how the LastPass hack enabled the loss of passwords. I assume it works the way that I understand 1Password to work which should mean this would still be very difficult to impossible to do. Can anyone explain what I'm wrong about in terms of how the password managers work or how LastPass works differently? So the way that I understand 1Password to work is that the decryption key is split in two:…
I was under the impression that basically lastpass knew your password, 1password does not. Lastpass owned the whole key. With enterprise organizations though we can still reset a users password if they forget so 1password might “know” your password too. Maybe older versions or individual versions are more secure.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#301Password truly doesn’t get enough credit for the choice to encrypt every vault with a high entropy secret key passed device to device. It surely costs them in UX and support load, but it would have made a breach like this essentially inconsequential.
Bitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypt…
technical possibilities aside, do you presume your grandchildren will be technically apt?
I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now.