Remember when LastPass first came onto the scene and everyone thought it was weak and not trustworthy? Pepperidge Farm remembers.
Feds Link Cyberheist to 2022 LastPass Hacks
211–220 of 266 posts
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#212Remember when LastPass first came onto the scene and everyone thought it was weak and not trustworthy? Pepperidge Farm remembers.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#213Earlier quoted context omitted.
You are wrong, the article posted said the heists happened because of both a breach and cracking master passwords. LastPass E2EE relied on keys from the master password using a password hash that had a low iteration count. Therefore low entropy passphrases could easily be cracked. Furthermore not all data was encrypted. This is all a weakness of their E2EE. 1Password uses both PAKE for remote authentication and a hig…
> attacking the ciphertext data would be infeasible If insufficiently protected, any attack surface may be compromised. It’s just a matter of time, resources, and will. “The only winning move is not to play.”
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#214Earlier quoted context omitted.
Proton Pass truly doesn’t get enough credit for being completely open source, more user friendly, and hosted outside the US (wouldn’t want to lose access to your vault [1]). [1]: https://berthub.eu/articles/posts/you-can-no-longer-base-you...
Proton pass is a poor man’s attempt at a password manager, with horrible user experience (oh we thought just a browser extension was enough!) and random limitations to fit in with Proton’s tortured business model. I was a Protonmail founding member. I used and evangelised them for years until I realised that they are more interested in chasing the next shiny thing (hey we have a crypto wallet now!) instead of fixing…
After having used Bitwarden for more than 4 years, I only switched last week, so I'm still in the honeymoon phase. But it has everything I used in Bitwarden and more, most notably all the usability features that I was missing in Bitwarden.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#215Earlier quoted context omitted.
Not OP, but UX also matters a lot. I’d strongly prefer an open source and selfhostable option, but each time I’ve evaluated Bitwarden in the past, it was a big enough downgrade from 1Password that I didn’t think switching was a good option. If the experience ever becomes as seamless, I’ll be switching.
> Not OP, but UX also matters a lot. That is particularly true for anything dealing with security. I evaluated both BitWarden and 1Password when we wanted to migrate away from LastPass. My recommendation was to eventually go with BW. Its open-source nature was a factor, but for a corporate use the UX factors were even more prominent. Over a course of a month, I ran into several subtle footguns with 1P. Search include…
Sounds like our experience with it could not be more different.
> The UI for 1P was a real mess.
In what way? You described how you feel about the UI, but I’m curious about actual specifics.
It’s entirely possible that I’m just too accustomed to it because I’ve been using it for many years, but what you’re describing is how I felt about Bitwarden.
I can completely see choosing BW in a corporate setting for a host of other reasons. But for me personally, the priority is a tool that gets out of my way and just works.
The tool that has done that is 1P.
> Less is more.
That really depends. If less means that the password manager doesn’t get used, then less is less.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#216Re: Feds Link Cyberheist to 2022 LastPass Hacks
#217Earlier quoted context omitted.
With the way the Apple is going in the UK, I'd rather give 1Password the keys to the kingdom. Their whole raison d'etre is protecting your passwords. If they start selling people out, their business implodes. They also keep adding thoughtful tweaks and new features. A couple years back I thought I'd give it a few years and then hop from 1Password to Bitwarden. But Bitwarden's UI and UX is still subpar (doesn't even s…
>With the way the Apple is going in the UK, I'd rather give 1Password the keys to the kingdom. What should Apple have done? Defy the government's order? Shut down entirely? They're already fighting it in court.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#218Earlier quoted context omitted.
What if you're in a foreign location and your devices are all stolen or lost?
You'd have to contact someone to get the secret key from your 1Pass emergency kit, wherever you stored it. That is, unless you can memorize long strings of numbers really well.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#219SPoF again..
This is such an under-rated comment for this whole thread. This was my gut response to password vaults when they were first implemented. I still find the idea of password vaults spooky. Open source ones scare me because it seems easy to slip a compromised library. The XZ debacle can't be the only time that's been tried. All of them scare me because a bad browser extension or a more minor hack, like a trojan, could li…
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#220Earlier quoted context omitted.
I am fascinated by the idea of being 50 years from now, and doing digital archaeology more or less. So much of our actual output is now digital and stored digitally. Given how I have experienced technology up until this point, my assumption is that everything I will create for work or for pleasure, is more or less ephemeral. It has certainly proven true for work.
I think we (or our descendants) will be surprised by the longevity of some of the file formats in use today. I would wager that it will be possible and not too unusual for regular users to open files in formats like PDF, zip or jpeg 100 years after their inception.
We're already 1/3 of the way there.