Live data from Hacker News

Feds Link Cyberheist to 2022 LastPass Hacks

krebsonsecurity.com

181–190 of 266 posts

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#181
post #155

Earlier quoted context omitted.

I think we (or our descendants) will be surprised by the longevity of some of the file formats in use today. I would wager that it will be possible and not too unusual for regular users to open files in formats like PDF, zip or jpeg 100 years after their inception.

You think we will still have files? I wager in the long term we're going more towards a people focused than paper focused system.

Yes I do think we will still have files (whatever they will be called) at some level for some purposes.

I.e, we will still be able to store and transfer sequences of bytes conforming to some specification (file format), and we will be able to attach names to those blobs in some namespace. The concept is too general to ever lose its usefulness.

There are a few key things I have learned in the third of a century that I've been working with data: Data lives longer than apps and longer than people. We will always need units of data that have their own life cycle and are reasonably self describing and self contained (i.e meaningful without resolving external references).

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#182
post #27
post #14

Earlier quoted context omitted.

So what if it does? Worst case you just go through the account recovery process at each institution. Password managers are a convenience. Data integrity isn’t critical but security is.

> Worst case you just go through the account recovery process at each institution Well, worst case is your account with Google, which you can kiss goodbye. But as we all know, that’s security. If the account recovery is the weakest link, it gets attacked.

That's insanity of cybersecurity.

In the real world, there's always a recovery procedure. It might involve visiting a court or some local administrative offices, but you can always recover access to anything that's important.

Not so with Google, or other on-line services that came from the tech industry side. Cybersecurity "best practices" is basically giving you a razor blade, and kicking you out if you hurt yourself with it.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#183
post #173

Earlier quoted context omitted.

Wouldn't it also make you lose everything in a recovery scenario? If all your computers are lost in a fire or flood, you would lose the recovery key, and having your password would not be enough to recover your database. I use keepassxc with a somewhat long password with a high PBKDF iterations count, which would not require having any devices in the event of a loss.

Except for crypto, losing your passwords is annoying but not irreversible

Depending on your usage, loosing your password can be irreversible. That'd lock you out of your encrypted email and storage and will take you months to recover your account on some platforms.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#184
post #144

Earlier quoted context omitted.

I am fascinated by the idea of being 50 years from now, and doing digital archaeology more or less. So much of our actual output is now digital and stored digitally. Given how I have experienced technology up until this point, my assumption is that everything I will create for work or for pleasure, is more or less ephemeral. It has certainly proven true for work.

I think we (or our descendants) will be surprised by the longevity of some of the file formats in use today. I would wager that it will be possible and not too unusual for regular users to open files in formats like PDF, zip or jpeg 100 years after their inception.

I'm not sure whether these file formats will still be in common use, but I'm fairly sure it will be trivial to find software that can read them.

Just like it's fairly easy for us to even run software from 50 years ago thanks to emulation. As long as your software run on a platform popular enough to have a good emulator. But for PDF and zip and jpeg reading software that will definitely be the case.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#185

Lastpass downplayed the breach and turned out they had not properly encrypted the data like notes section. They should have been sued to oblivion, but they were able weasel out of responsibility, so far. Lastpass had one job and failed it. Unforgivable that they knew their users' master passwords are not secure enough, but chose not to be vocal or proactive about it. If you're using Lastpass right now, move to more t…

1password is a good choice.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#186
post #127

Earlier quoted context omitted.

What does "You will get your vaults locally" mean? Is it possible to export as a file, take that with you on whatever medium (eg. USB key, CD-ROM, future isolinear chip), put it on a brand new PC you built from scratch and never connected to the internet, and open it in some kind of standalone viewer?

That’s how 1Password used to work. Not sure how much of that is still left in the system these days. Originally it was an app with no remote component. The vault was yours to look after. Most people kept it in Dropbox to make it accessible anywhere. The vault itself actually had an html file in it that you could open in a pinch that was able to decrypt secrets (only for reading, from memory). 1Password as a service c…

Actually, 1Password had local syncing where you synced the vaults between devices on a local connection (I think it was point to point WiFi, so your internet dropped off, Bluetooth was less common then). So it was bucket brigade syncing.

Dropbox came later and security minded folks were wary. Honestly, I trust 1Password sync more than an encrypted db on a general purpose cloud file sync, but maybe that’s naive.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#187

Earlier quoted context omitted.

Bitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypt…

Proton Pass truly doesn’t get enough credit for being completely open source, more user friendly, and hosted outside the US (wouldn’t want to lose access to your vault [1]). [1]: https://berthub.eu/articles/posts/you-can-no-longer-base-you...

Proton pass is a poor man’s attempt at a password manager, with horrible user experience (oh we thought just a browser extension was enough!) and random limitations to fit in with Proton’s tortured business model.

I was a Protonmail founding member. I used and evangelised them for years until I realised that they are more interested in chasing the next shiny thing (hey we have a crypto wallet now!) instead of fixing longstanding bugs and performance issues in their mail client.

As for hosted outside the US, I’m pretty sure the vaultvarden instance running under my desk is also hosted outside the US (unless I’ve somehow been magically transported to the US). Plus, I get to physically lock the door when I leave the house and my cat usually sleeps on top of the sever which adds a level of furry protection which proton pass could never achieve

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#188

1Password truly doesn’t get enough credit for the choice to encrypt every vault with a high entropy secret key passed device to device. It surely costs them in UX and support load, but it would have made a breach like this essentially inconsequential.

Wouldn't it also make you lose everything in a recovery scenario? If all your computers are lost in a fire or flood, you would lose the recovery key, and having your password would not be enough to recover your database. I use keepassxc with a somewhat long password with a high PBKDF iterations count, which would not require having any devices in the event of a loss.

Loosing everything if you don’t have a key is part of the appeal.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#189

Earlier quoted context omitted.

https://www.bleepingcomputer.com/news/security/1password-dis... https://www.forbes.com/sites/daveywinder/2023/12/11/android-... https://www.zdnet.com/article/hackers-stole-this-engineers-1...

How is any of this a threat to 1Password E2EE? The point is if they even have access to my encrypted data, they wouldn't be able to access the plaintext without the key (and yes the passphrase is not sufficient). This is just lazy scaremongering.

The point you're trying to make is a trivial one: in the absence of errors, there are no problems.

LastPass e2ee was never the problem in the original story either.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#190

1Password truly doesn’t get enough credit for the choice to encrypt every vault with a high entropy secret key passed device to device. It surely costs them in UX and support load, but it would have made a breach like this essentially inconsequential.

Bitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypt…

I backup some what similarly.

Curious, how is Excel encryption? That may be a more approachable format than CSV GPG, and though technically the CSV GPG is more simpler, it may be less familiar to users in 100 years. Excel will still be around ;)

Post reply on HN