Live data from Hacker News

Feds Link Cyberheist to 2022 LastPass Hacks

krebsonsecurity.com

101–110 of 266 posts

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#101
post #89

Sharing a short post I posted a year ago with some thoughts on password managers. ## The password-management promise > I don't buy the promise behind 1Password or LastPass. > You only need to remember one password. The last password you'd need to remember. > They don't tell you that you're also building a one-stop shop for hackers to steal it all at once. > The solution? > Store hints, not passwords. > Don't reuse pa…

I used to be really skeptical of online password vaults. I thought they were an obvious Honeypot begging to be hacked. But if I understand the technology behind 1password correctly, there is literally no way for a hacker to sign into my account on a new device without having one of my other devices or my secret key (the actual 34 digit encryption key used to verify my account and set up new devices). So even if they…

> So even if they know my 1password username and password they still can't really do anything with it. And if they steal my device, they would need to know my login password. Or cut off a finger, I guess, but I've got bigger issues if that happens.

https://xkcd.com/538/

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#102

Earlier quoted context omitted.

I used to be really skeptical of online password vaults. I thought they were an obvious Honeypot begging to be hacked. But if I understand the technology behind 1password correctly, there is literally no way for a hacker to sign into my account on a new device without having one of my other devices or my secret key (the actual 34 digit encryption key used to verify my account and set up new devices). So even if they…

> So even if they know my 1password username and password they still can't really do anything with it. And if they steal my device, they would need to know my login password. Or cut off a finger, I guess, but I've got bigger issues if that happens. https://xkcd.com/538/

Yeah pretty much.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#103

Earlier quoted context omitted.

Is bitwarden’s only differentiator being open source and self hostable? Im looking at other services and thus far see no reason to leave 1Password.

That, and it's better in most functional and polish regards than LastPass. I haven't used 1Password, so I can't compare those two directly, but I'd strongly recommend BitWarden over LastPass as far as those two are considered.

1Password is also significantly more polished and easy to use than LastPass.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#104
post #71

Earlier quoted context omitted.

is that not enough? It's also inexpensive and works very well on all platforms.

Not OP, but UX also matters a lot. I’d strongly prefer an open source and selfhostable option, but each time I’ve evaluated Bitwarden in the past, it was a big enough downgrade from 1Password that I didn’t think switching was a good option. If the experience ever becomes as seamless, I’ll be switching.

This. 1p is polished and easy to use. Bitwarden is as functional as 1P but janky.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#105
post #30

Earlier quoted context omitted.

>But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypted gzipped file (with the passphrase I’ll leave them) containing my passwords in a csv file. technical possibilities aside, do you presume your grandchildren will be technically apt? I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now.

> I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now. I know reading the docs is considered uncool for some reason, but it really does work.

To how many non-SWE members of your family could you say 'here is the Netflix password, you can decrypt it with gpg', and have them be like 'ah yes, let me just `man gpg` this will be no problem'?

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#106
post #90

Earlier quoted context omitted.

> Bitwarden truly doesn’t get enough credit for being completely open source It’s their No. 1 selling point. > In 50 years time, who knows if any of these companies will be around 1Password has local clients. If you have the password, you should be able to unlock the vault locally.

Can you walk me through how to do this? I have installed the "1password-cli" package on my airgapped linux machine with no network access ('op --version' gives me 2.30.3). If I run 'op vault list', it tells me I have to add an account. When I run 'op account add' it tries to connect to 1password's servers and won't let me proceed without internet. I don't see how this "local client" is helping if all the auth infrast…

You need to authenticate once. You will get your vaults locally and you will be able to access them without an internet connection

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#107
I've repeated over and over that password manager services are a horrible idea. Trusting a single service with all your passwords is worse than using the same password for all services (of the same sensitivity level) IMO. The ideal solution is to come up with a secret heuristic to come up with different passwords for different services. I kept getting downvoted for this. Well, IMO, these people deserved to be hacked.

I've never been hacked, never been locked out of any accounts.

I'm getting tired of being proven right about everything over and over after being downvoted. It's a very common pattern for me.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#108
post #105

Earlier quoted context omitted.

> I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now. I know reading the docs is considered uncool for some reason, but it really does work.

To how many non-SWE members of your family could you say 'here is the Netflix password, you can decrypt it with gpg', and have them be like 'ah yes, let me just `man gpg` this will be no problem'?

Probably zero. And strike the non-SWE part. gpg isn't really easy to use.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#110

Me, looking at my local KeepassXC, calm, sticking with it.

This is the kind of control that is really becoming a luxury. And I don't know how we get back to a simple state; Let's say you're a family of three with shared services and accounts: Keeping everything under Keepass means handling the file sync between all the devices and OSes, with potentially your credentials flying through third party sync services, thus negating most of the advantages of Keepass. Moving to somet…

I use Strongbox + iCloud Drive + KeepassXC.
Post reply on HN