Earlier quoted context omitted.
Bitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypt…
>But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypted gzipped file (with the passphrase I’ll leave them) containing my passwords in a csv file. technical possibilities aside, do you presume your grandchildren will be technically apt? I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now.
Feds Link Cyberheist to 2022 LastPass Hacks
41–50 of 266 posts
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#42I'm a bit confused on how the LastPass hack enabled the loss of passwords. I assume it works the way that I understand 1Password to work which should mean this would still be very difficult to impossible to do. Can anyone explain what I'm wrong about in terms of how the password managers work or how LastPass works differently? So the way that I understand 1Password to work is that the decryption key is split in two:…
See a vault with just a facebook.com and google.com login? Skip it. See a vault with coinbase and 10 other crypto sites in it? Spend a few thousand trying to crack it.
Source: https://github.com/cfbao/lastpass-vault-parser/wiki/LastPass...
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#43Re: Feds Link Cyberheist to 2022 LastPass Hacks
#44Earlier quoted context omitted.
Bitcoin has never been hacked. The victims did not practice proper key management. The victims got hacked because of their own insecure key management, not because of any vulnerability in Bitcoin. To claim otherwise is like claiming that because people can steal improperly secured code signing or TLS certificate private keys, all code signing and TLS certificates are inherently, fundamentally, and automatically broke…
You know what every other online money transfer mechanism has? An ability to reverse transactions in the case or error or fraud. Because those things happen all of the time.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#45Me, looking at my local KeepassXC, calm, sticking with it.
How do you sync it between devices like your phone? What about family sharing or access for emergencies or other such features?
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#46Earlier quoted context omitted.
>But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypted gzipped file (with the passphrase I’ll leave them) containing my passwords in a csv file. technical possibilities aside, do you presume your grandchildren will be technically apt? I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now.
An LLM entity named gpgchat will assist them.
LLM entities have bills to pay too.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#47Earlier quoted context omitted.
Horrible, and waiting until Christmas week to disclose it while weak master passwords (no min length reqs) and a laughable PBKDF2-HMAC-SHA256 with 5,000 iterations (this was set to 100,100 for new accounts after Feb 2018) let the attackers brute-force their way in…
I think in some cases the iteration count was like 5000.
So despite the messaging from LastPass about improving iteration count for existing users it wasn't always accurate.
[1] https://news.ycombinator.com/item?id=34152779
[2] https://www.reddit.com/r/Lastpass/comments/zuve7t/cracking_e...
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#48It also feels like there's a convenience tradeoff with a lot of solutions. I could keep a physical binder full of passwords in my home office but that would be a pain to look up and enter things every time (and a big risk for anyone with physical access to my place).
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#49What do security minded people do about passwords? It seems like you either use the same password for everything, or you need some kind of password manager, but then I'm always worried about having all my passwords in one place meaning they all get compromised instead of just one. It also feels like there's a convenience tradeoff with a lot of solutions. I could keep a physical binder full of passwords in my home off…
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#50What do security minded people do about passwords? It seems like you either use the same password for everything, or you need some kind of password manager, but then I'm always worried about having all my passwords in one place meaning they all get compromised instead of just one. It also feels like there's a convenience tradeoff with a lot of solutions. I could keep a physical binder full of passwords in my home off…
Ensure all your passwords get reset at some point after vaulting, long randomly generated from Bitwarden extension/app is easy enough. Ensure you enable strong 2FA at each service you have an account at too.
https://bitwarden.com/help/setup-two-step-login/ https://bitwarden.com/resources/guide-how-to-create-and-stor...