Live data from Hacker News

Feds Link Cyberheist to 2022 LastPass Hacks

krebsonsecurity.com

131–140 of 266 posts

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#132

I switched away from LastPass after the 2nd major security breach sometime around 2013. Wikipedia only shows 3 total incidents, but I know I've seen reporting on _at least_ 5 between 2010 and today. In that time, I've continued to run into its use at companies, and it's honestly surprised me each time. Something something fool me 5x…

How come this is legal? By now this is a business practice. Why would the government close down a restaurant after food poisoning but do nothing here?this is much worse, considering all this money goes to the axis countries?

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#134
post #90

Earlier quoted context omitted.

> Bitwarden truly doesn’t get enough credit for being completely open source It’s their No. 1 selling point. > In 50 years time, who knows if any of these companies will be around 1Password has local clients. If you have the password, you should be able to unlock the vault locally.

Can you walk me through how to do this? I have installed the "1password-cli" package on my airgapped linux machine with no network access ('op --version' gives me 2.30.3). If I run 'op vault list', it tells me I have to add an account. When I run 'op account add' it tries to connect to 1password's servers and won't let me proceed without internet. I don't see how this "local client" is helping if all the auth infrast…

There might be alternatives that are better designed for that use case these days; pass and KeePassXC are popular ones, depending on the interface you want (pass is made for the cli as the primary interface).

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#135

1Password truly doesn’t get enough credit for the choice to encrypt every vault with a high entropy secret key passed device to device. It surely costs them in UX and support load, but it would have made a breach like this essentially inconsequential.

Bitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypt…

Proton Pass truly doesn’t get enough credit for being completely open source, more user friendly, and hosted outside the US (wouldn’t want to lose access to your vault [1]).

[1]: https://berthub.eu/articles/posts/you-can-no-longer-base-you...

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#136

In my opinion Karim Toubba is liable and shouldn't be allowed to have more than 69$ forever.

I don’t totally know what this comment is attempting to communicate, but Karim Toubba apparently had been CEO for 4 months at the time of the original breach:

https://www.cybersecuritydive.com/news/lastpass-ceo-reflects...

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#137

Earlier quoted context omitted.

Bitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypt…

Proton Pass truly doesn’t get enough credit for being completely open source, more user friendly, and hosted outside the US (wouldn’t want to lose access to your vault [1]). [1]: https://berthub.eu/articles/posts/you-can-no-longer-base-you...

How can I self host proton pass? I'm searching for the server source code and I can't find it. Should be available if it's completely open source.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#138
post #105

Earlier quoted context omitted.

> I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now. I know reading the docs is considered uncool for some reason, but it really does work.

To how many non-SWE members of your family could you say 'here is the Netflix password, you can decrypt it with gpg', and have them be like 'ah yes, let me just `man gpg` this will be no problem'?

If secretaries can learn Emacs, surely people can learn GPG. Underestimating others does no one any favors.

https://www.gnu.org/gnu/rms-lisp.en.html

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#139
post #105

Earlier quoted context omitted.

> I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now. I know reading the docs is considered uncool for some reason, but it really does work.

To how many non-SWE members of your family could you say 'here is the Netflix password, you can decrypt it with gpg', and have them be like 'ah yes, let me just `man gpg` this will be no problem'?

i would imagine if a lot of money, like millions, was on the line, people get really resourceful all of a sudden. of course, we're not talking Netflix passwords but usernames and passwords to brokerages, bank accounts, etc.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#140

Earlier quoted context omitted.

This is the kind of control that is really becoming a luxury. And I don't know how we get back to a simple state; Let's say you're a family of three with shared services and accounts: Keeping everything under Keepass means handling the file sync between all the devices and OSes, with potentially your credentials flying through third party sync services, thus negating most of the advantages of Keepass. Moving to somet…

I use Strongbox + iCloud Drive + KeepassXC.

As TheDong points out int he other comment, I also had Keepass working well when absolutely everything in the house was Apple.

It went down the drain when I switched to android and the kid to a Chromebook.

This is the proverbial strategy tax working out, where the strong ecosystem play is biting us hard enough. Moving to Windows+WSL actually made my life easier, even as the other member still have some Apple devices.

Post reply on HN