Live data from Hacker News

Feds Link Cyberheist to 2022 LastPass Hacks

krebsonsecurity.com

161–170 of 266 posts

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#161
Lastpass downplayed the breach and turned out they had not properly encrypted the data like notes section. They should have been sued to oblivion, but they were able weasel out of responsibility, so far.

Lastpass had one job and failed it. Unforgivable that they knew their users' master passwords are not secure enough, but chose not to be vocal or proactive about it.

If you're using Lastpass right now, move to more trustworthy options like 1Password, Bitwarden or Keepass. Do it today. And change all passwords, that are meaningful to you.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#162

Me, looking at my local KeepassXC, calm, sticking with it.

This is the kind of control that is really becoming a luxury. And I don't know how we get back to a simple state; Let's say you're a family of three with shared services and accounts: Keeping everything under Keepass means handling the file sync between all the devices and OSes, with potentially your credentials flying through third party sync services, thus negating most of the advantages of Keepass. Moving to somet…

Syncthing works great for this if you have an always on computer. If you don't you can use a server and add it as an untrusted recipient if you have to, though I would not bother since the database is encrypted with your password anyways, and is not vulnerable if you never reuse your db password and there is enough entropy.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#163
post #105

Earlier quoted context omitted.

To how many non-SWE members of your family could you say 'here is the Netflix password, you can decrypt it with gpg', and have them be like 'ah yes, let me just `man gpg` this will be no problem'?

i would imagine if a lot of money, like millions, was on the line, people get really resourceful all of a sudden. of course, we're not talking Netflix passwords but usernames and passwords to brokerages, bank accounts, etc.

Sure, but surely we're intending to leave them access, not a problem to solve.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#164
post #104

Earlier quoted context omitted.

This. 1p is polished and easy to use. Bitwarden is as functional as 1P but janky.

1P family sharing and 1P cli also work well. I check BW every so often but it always feels less polished UI wise. For all the complaints people had about 1P moving to electron, it’s UX is still the best out there.

> family sharing

Why would someone make a feature like this?

I'm confused why some companies (including Amazon and Steam) insist on family features. The mental model behind this is more prescriptive than descriptive - it doesn't match to how users and their families function; rather, it insists on some activities to a) exist in family, and b) be not allowed outside of family.

Or simply: how many people have actual family listed in their Steam / Amazon "family sharing"?

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#165
post #77

Earlier quoted context omitted.

I have similar gripes, but I still feel like on balance, randomizing passwords across accounts is more important. Selfhost vaultwarden ftw (or not — don’t f*ck it up)

> Selfhost vaultwarden ftw (or not — don’t f*ck it up) Right. Randomizing passwords doesn’t require centralization.

Truly the chain of decisions that got us here is baffling.

"Use random high entropy passwords for each account"

good

"Store them encrypted"

great

"In a computer publicly available on the internet"

wat

"Under an account that also handles your 2fa tokens"

c'mon now!

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#166

Earlier quoted context omitted.

> Selfhost vaultwarden ftw (or not — don’t f*ck it up) Right. Randomizing passwords doesn’t require centralization.

Truly the chain of decisions that got us here is baffling. "Use random high entropy passwords for each account" good "Store them encrypted" great "In a computer publicly available on the internet" wat "Under an account that also handles your 2fa tokens" c'mon now!

If you do e2ee correctly this is a non-issue. See 1Password for one way to do to it right.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#167
post #155

Earlier quoted context omitted.

I think we (or our descendants) will be surprised by the longevity of some of the file formats in use today. I would wager that it will be possible and not too unusual for regular users to open files in formats like PDF, zip or jpeg 100 years after their inception.

You think we will still have files? I wager in the long term we're going more towards a people focused than paper focused system.

100 years after their inception isn’t very far from now. There are plenty of people here who will be alive in the 2080s.

Everybody has a different idea of what long term means, but I think of it as millennia from now. The kind of time frame that the Long Now Foundation talks about.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#168

Earlier quoted context omitted.

Truly the chain of decisions that got us here is baffling. "Use random high entropy passwords for each account" good "Store them encrypted" great "In a computer publicly available on the internet" wat "Under an account that also handles your 2fa tokens" c'mon now!

If you do e2ee correctly this is a non-issue. See 1Password for one way to do to it right.

https://www.bleepingcomputer.com/news/security/1password-dis...

https://www.forbes.com/sites/daveywinder/2023/12/11/android-...

https://www.zdnet.com/article/hackers-stole-this-engineers-1...

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#169

I've repeated over and over that password manager services are a horrible idea. Trusting a single service with all your passwords is worse than using the same password for all services (of the same sensitivity level) IMO. The ideal solution is to come up with a secret heuristic to come up with different passwords for different services. I kept getting downvoted for this. Well, IMO, these people deserved to be hacked.…

I feel like anyone with a visceral reaction to password managers that sync/store on cloud storage do not really understand E2EE. LastPass is really the only exception that didn't implement it properly.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#170
post #84

Earlier quoted context omitted.

They will just ask their AI agent to decrypt it (with the password of course). No need of ability to run gpg.

No, you can't tell your non-SWE friends and family to "just ask an AI" when the potential consequences are them losing access to their vault or having it stolen. They need to know exactly what they're doing. Don't take security advice from an AI.

They're vastly more likely to lose everything they care about by following real security advice, or rather being forced to follow it. 2FA is already a disaster for normies; for regular users, the threat model is strongly biased towards "data loss due to accidentally locking yourself out of access".

In fact, if you consider the impact fully, the best way of managing passwords still seems to be writing them down on a post-it note and keeping it in your wallet - hell, even sticking it to your screen doesn't look so bad these days, compared to alternatives.

Modern infosecurity is absurdly counter-intuitive at high level. Consider that your Google account or your WhatsApp (or Signal) chats are much more secured than your medical data or bank accounts or anything that predates Google. For anything in the real world, there is always a recovery procedure, no matter how much bad luck you had or how badly you screwed up. In the worst case, you might end up needing to chase some documents to authorize or notarize other documents, or show up in court, but you can get your access back. It's insane to imagine the world, in which a single fuckup could wipe out your medical history, your bank account, or any proof of your existence in government systems - and yet, this is exactly what is the case with any modern SaaS that follows "best security practices".

There's literally nothing else in this world that's so easy to mishandle as security in commercial software services.

Post reply on HN