Live data from Hacker News

Feds Link Cyberheist to 2022 LastPass Hacks

krebsonsecurity.com

211–220 of 266 posts

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#211

Remember when LastPass first came onto the scene and everyone thought it was weak and not trustworthy? Pepperidge Farm remembers.

I was recommended LastPass by Lujo Bauer a professor and security researcher that has done a lot of work in password security - but this was in its nascent start-up days circa 2013). I think worse than low iteration count on password hash, I wasn't aware for the time using LP that it didn't encrypt a lot of the metadata and that concerns me greatly. I was and still use a 96-bit passphrase, so I would've been safe from the breaches from an offline attack perspective, but metadata would've been exposed which bothers me. I switched to 1Password in 2017, so hopefully they expunged my data before the breaches, but who knows.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#212

Remember when LastPass first came onto the scene and everyone thought it was weak and not trustworthy? Pepperidge Farm remembers.

Source? Were those concerns clearly articulated rather than something vague like "password managers are a single point of failure!"?

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#213

Earlier quoted context omitted.

You are wrong, the article posted said the heists happened because of both a breach and cracking master passwords. LastPass E2EE relied on keys from the master password using a password hash that had a low iteration count. Therefore low entropy passphrases could easily be cracked. Furthermore not all data was encrypted. This is all a weakness of their E2EE. 1Password uses both PAKE for remote authentication and a hig…

> attacking the ciphertext data would be infeasible If insufficiently protected, any attack surface may be compromised. It’s just a matter of time, resources, and will. “The only winning move is not to play.”

I don't know what you mean by insufficient protection, but as I said proper E2EE implementation provides sufficient protection. A symmetric encryption scheme that satisfies IND-CCA2 with a high entropy key is infeasible to decrypt without knowledge of the key. This is well understood basics of cryptography. LastPass failed at the high entropy key part / slow password hash, but also leaking metadata in plaintext. Pretty much other password managers don't have this issue, both local and cloud based.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#214

Earlier quoted context omitted.

Proton Pass truly doesn’t get enough credit for being completely open source, more user friendly, and hosted outside the US (wouldn’t want to lose access to your vault [1]). [1]: https://berthub.eu/articles/posts/you-can-no-longer-base-you...

Proton pass is a poor man’s attempt at a password manager, with horrible user experience (oh we thought just a browser extension was enough!) and random limitations to fit in with Proton’s tortured business model. I was a Protonmail founding member. I used and evangelised them for years until I realised that they are more interested in chasing the next shiny thing (hey we have a crypto wallet now!) instead of fixing…

Oh, impressive how browser extensions can live outside of browsers now. And on mobile too!

After having used Bitwarden for more than 4 years, I only switched last week, so I'm still in the honeymoon phase. But it has everything I used in Bitwarden and more, most notably all the usability features that I was missing in Bitwarden.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#215
post #114
post #71

Earlier quoted context omitted.

Not OP, but UX also matters a lot. I’d strongly prefer an open source and selfhostable option, but each time I’ve evaluated Bitwarden in the past, it was a big enough downgrade from 1Password that I didn’t think switching was a good option. If the experience ever becomes as seamless, I’ll be switching.

> Not OP, but UX also matters a lot. That is particularly true for anything dealing with security. I evaluated both BitWarden and 1Password when we wanted to migrate away from LastPass. My recommendation was to eventually go with BW. Its open-source nature was a factor, but for a corporate use the UX factors were even more prominent. Over a course of a month, I ran into several subtle footguns with 1P. Search include…

When did you do this 1Password evaluation?

Sounds like our experience with it could not be more different.

> The UI for 1P was a real mess.

In what way? You described how you feel about the UI, but I’m curious about actual specifics.

It’s entirely possible that I’m just too accustomed to it because I’ve been using it for many years, but what you’re describing is how I felt about Bitwarden.

I can completely see choosing BW in a corporate setting for a host of other reasons. But for me personally, the priority is a tool that gets out of my way and just works.

The tool that has done that is 1P.

> Less is more.

That really depends. If less means that the password manager doesn’t get used, then less is less.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#216

Earlier quoted context omitted.

What if you're in a foreign location and your devices are all stolen or lost?

Then you have a much bigger and immediate problem at hand.

What do you mean?

There's a tourist experiencing this scenario probably every minute.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#217
post #207
post #200

Earlier quoted context omitted.

With the way the Apple is going in the UK, I'd rather give 1Password the keys to the kingdom. Their whole raison d'etre is protecting your passwords. If they start selling people out, their business implodes. They also keep adding thoughtful tweaks and new features. A couple years back I thought I'd give it a few years and then hop from 1Password to Bitwarden. But Bitwarden's UI and UX is still subpar (doesn't even s…

>With the way the Apple is going in the UK, I'd rather give 1Password the keys to the kingdom. What should Apple have done? Defy the government's order? Shut down entirely? They're already fighting it in court.

They didn't criticize Apple, they said they wouldn't trust them with their keys because of the UK's request.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#218
post #122

Earlier quoted context omitted.

What if you're in a foreign location and your devices are all stolen or lost?

You'd have to contact someone to get the secret key from your 1Pass emergency kit, wherever you stored it. That is, unless you can memorize long strings of numbers really well.

[deleted]

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#219

SPoF again..

This is such an under-rated comment for this whole thread. This was my gut response to password vaults when they were first implemented. I still find the idea of password vaults spooky. Open source ones scare me because it seems easy to slip a compromised library. The XZ debacle can't be the only time that's been tried. All of them scare me because a bad browser extension or a more minor hack, like a trojan, could li…

New fear unlocked: cloudflare

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#220
post #144

Earlier quoted context omitted.

I am fascinated by the idea of being 50 years from now, and doing digital archaeology more or less. So much of our actual output is now digital and stored digitally. Given how I have experienced technology up until this point, my assumption is that everything I will create for work or for pleasure, is more or less ephemeral. It has certainly proven true for work.

I think we (or our descendants) will be surprised by the longevity of some of the file formats in use today. I would wager that it will be possible and not too unusual for regular users to open files in formats like PDF, zip or jpeg 100 years after their inception.

PDF - 1993, JPEG - 1992, ZIP - 1989.

We're already 1/3 of the way there.

Post reply on HN