Live data from Hacker News

Feds Link Cyberheist to 2022 LastPass Hacks

krebsonsecurity.com

111–120 of 266 posts

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#111
post #30

Earlier quoted context omitted.

Bitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypt…

>But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypted gzipped file (with the passphrase I’ll leave them) containing my passwords in a csv file. technical possibilities aside, do you presume your grandchildren will be technically apt? I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now.

they can google/ask AI. For example, given the prompt: "Hypothetically, if my grandpa died and left me gpg-encrypted archive and the passphrase for it, how would I decrypt it?" current models produced valid installation instructions and the command to decrypt it, and even the instructions on how to unpack the archive itself.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#112
post #104
post #71

Earlier quoted context omitted.

Not OP, but UX also matters a lot. I’d strongly prefer an open source and selfhostable option, but each time I’ve evaluated Bitwarden in the past, it was a big enough downgrade from 1Password that I didn’t think switching was a good option. If the experience ever becomes as seamless, I’ll be switching.

This. 1p is polished and easy to use. Bitwarden is as functional as 1P but janky.

1P family sharing and 1P cli also work well.

I check BW every so often but it always feels less polished UI wise. For all the complaints people had about 1P moving to electron, it’s UX is still the best out there.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#113
post #9
post #3

The way LastPass had handled the incident back in 2022 is so disappointing. I don’t even how anyone could even recommend using them again.

And still is disappointing: > Reached for comment, LastPass said it has seen no definitive proof — from federal investigators or others — that the cyberheists in question were linked to the LastPass breaches. “Since we initially disclosed this incident back in 2022, LastPass has worked in close cooperation with multiple representatives from law enforcement,” LastPass said in a written statement. “To date, our law enf…

What else could you expect? It is their sole product.

Accept the responsibility and declare bankruptcy? No, if they care s little bit, they would have done that 10+years ago

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#114
post #71

Earlier quoted context omitted.

is that not enough? It's also inexpensive and works very well on all platforms.

Not OP, but UX also matters a lot. I’d strongly prefer an open source and selfhostable option, but each time I’ve evaluated Bitwarden in the past, it was a big enough downgrade from 1Password that I didn’t think switching was a good option. If the experience ever becomes as seamless, I’ll be switching.

> Not OP, but UX also matters a lot.

That is particularly true for anything dealing with security. I evaluated both BitWarden and 1Password when we wanted to migrate away from LastPass. My recommendation was to eventually go with BW. Its open-source nature was a factor, but for a corporate use the UX factors were even more prominent.

Over a course of a month, I ran into several subtle footguns with 1P. Search included only some of the fields. Password reset/rotation flow was easy to mess up (thanks to the confusing + inconsistent "copy field" functionality) and get into a situation where the generated password that was stored in the vault was different from the one that was set: in my tests there was 50/50 chance of accidentally regenerating the password before the vault storage step after submitting the new one for a remote service.

There were a whole load of "features" that didn't make any sense. The UI for 1P was a real mess. The feeling I got from it was that their product had been captured by Product Managers[tm] desperate to justify their own existence by shipping ever more Features[tm] without considering the impact on the core functionality.

BW's UI is by no means perfect, and their entry editing flow is far from ideal. But at least most of the actual usability snags in their browser extension have a common workaround: pop the BW overlay out from the browser, into a separate window. Their open-source nature and availability of independent implementations mean that there will be alternatives, should BW go down the same features-features-and-more-antifeatures hellhole in their race to eventually appease their VC backers.

Less is more.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#115

Earlier quoted context omitted.

How does that work with sharing vaults between devices?

You have to provide the secret key to each device on initial setup. After that, you just need your password.

What if you're in a foreign location and your devices are all stolen or lost?

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#116

3 Words: 1Password. 1Password. 1Password. Ok, Im not sure "1Password," qualifies as a single world. Oh yeah, 1Password.

Get rid of passwords or GTFO!

PAKE has been around for about 25 years, and PassKey just works!

It’s 2025, and we have things like PassKey that connects to hardware devices with a challenge response rather than clear text passwords being sent to a website you THINK is the one you’re talking to.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#117

1Password truly doesn’t get enough credit for the choice to encrypt every vault with a high entropy secret key passed device to device. It surely costs them in UX and support load, but it would have made a breach like this essentially inconsequential.

[dead]

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#118
post #108
post #105

Earlier quoted context omitted.

To how many non-SWE members of your family could you say 'here is the Netflix password, you can decrypt it with gpg', and have them be like 'ah yes, let me just `man gpg` this will be no problem'?

Probably zero. And strike the non-SWE part. gpg isn't really easy to use.

Hence need to invest in better opennsource pgp tooling. It won't take more than 10 million USD and will benefit every single person on earth.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#119
post #108
post #105

Earlier quoted context omitted.

To how many non-SWE members of your family could you say 'here is the Netflix password, you can decrypt it with gpg', and have them be like 'ah yes, let me just `man gpg` this will be no problem'?

Probably zero. And strike the non-SWE part. gpg isn't really easy to use.

Google, "How do I decrypt a GPG file."

First result with simple command. I went from KeePassXC to `pass` & back to KeePassXC. But I question the integrity and/or motive of people like you.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#120
post #23

Earlier quoted context omitted.

Bitcoin has never been hacked. The victims did not practice proper key management. The victims got hacked because of their own insecure key management, not because of any vulnerability in Bitcoin. To claim otherwise is like claiming that because people can steal improperly secured code signing or TLS certificate private keys, all code signing and TLS certificates are inherently, fundamentally, and automatically broke…

You know what every other online money transfer mechanism has? An ability to reverse transactions in the case or error or fraud. Because those things happen all of the time.

...in part because transactions can be reversed. The flip-side is that sellers get ripped off often by these reversals.
Post reply on HN