Live data from Hacker News

Feds Link Cyberheist to 2022 LastPass Hacks

krebsonsecurity.com

231–240 of 266 posts

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#231

1Password truly doesn’t get enough credit for the choice to encrypt every vault with a high entropy secret key passed device to device. It surely costs them in UX and support load, but it would have made a breach like this essentially inconsequential.

Wouldn't it also make you lose everything in a recovery scenario? If all your computers are lost in a fire or flood, you would lose the recovery key, and having your password would not be enough to recover your database. I use keepassxc with a somewhat long password with a high PBKDF iterations count, which would not require having any devices in the event of a loss.

Your phone also has the recovery key. Having a copy on your person does lessen the chance of losing all your copies at once.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#232

Lastpass downplayed the breach and turned out they had not properly encrypted the data like notes section. They should have been sued to oblivion, but they were able weasel out of responsibility, so far. Lastpass had one job and failed it. Unforgivable that they knew their users' master passwords are not secure enough, but chose not to be vocal or proactive about it. If you're using Lastpass right now, move to more t…

Just for the record, they are being sued to oblivion:

https://www.courtlistener.com/docket/66607916/debt-cleanse-g...

You'd have to go study the case, but it's a class action case, so it'll hurt if they lose (and even if they don't). The court appears to be consolidating cases into this one, because LastPass has been sued in federal court 15 times so far:

https://www.courtlistener.com/?q=lastpass%20AND%20(caseName%...

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#233

Earlier quoted context omitted.

Is bitwarden’s only differentiator being open source and self hostable? Im looking at other services and thus far see no reason to leave 1Password.

That, and it's better in most functional and polish regards than LastPass. I haven't used 1Password, so I can't compare those two directly, but I'd strongly recommend BitWarden over LastPass as far as those two are considered.

I have my own beef with 1Password, but having used both Bitwarden and 1Password, I still find 1Password to be the better UX and more secure solution. Bitwarden is also worse at filling with their browser extension, rather significantly. That said, 1Password's Safari support with multiple profiles is... frustrating... at best.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#234
post #39

Earlier quoted context omitted.

It's such a pity that bitwarden's client doesn't work offline for modifying vaults (need to be online to be able to access the server implementation). I would switch from my old local vault 1password in an instant.

I just have KeePass in a syncthing folder with a trigger to sync on open. Technically I think I could drop the trigger if the desktop app would open by making a temporary file copy and syncing back (ironically Keepass2Android is very good at this).

Can you expand why the trigger is necessary?

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#235

Earlier quoted context omitted.

I think "family" is just the humane, user-friendly, non-corporate word for "group" in this context.

Yeah, but "group" is also a humane, user-friendly, non-corporate word for "group" and happens to not carry any confusing connotations.

On the scale of humaneness, "family" will always score higher than "group".

But yeah, it's a content and positioning call for the product and marketing teams to make.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#236
post #221

Earlier quoted context omitted.

> except for the fact that they basically forced users to use their cloud offering Yeah that's when I left 1P after having bought hundreds of dollars of licenses for myself and my family (for multiple OS). The other big thing was self hosting the vault. You used to be able to sync the vault with Dropbox and access it from a browser but at some point Dropbox killed public folders. It would have cost 1P pennies to stor…

Does bitwarden when importing support all data types of 1p ie file attachments and various fields of various entry types?

No. I used both of them when migrating from LastPass, and found that Bitwarden only supports four or five types of entries, which ultimately drove me away from the product.

The rich entry types from 1P and LP are nearly all converted to Notes in Bitwarden. Great product otherwise.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#237

I've repeated over and over that password manager services are a horrible idea. Trusting a single service with all your passwords is worse than using the same password for all services (of the same sensitivity level) IMO. The ideal solution is to come up with a secret heuristic to come up with different passwords for different services. I kept getting downvoted for this. Well, IMO, these people deserved to be hacked.…

What if you used a password service, but modified the password it puts in manually (and didn't let it update when you log in)? Would an attacker try variations, or just move on when your password manager-provided login doesn't work?

This would probably help a little bit in terms of security but you would still depend fully on your password manager for access to various services. Personally, I don't like the dependency aspect of password managers.

I hate having to log into my password manager first before I can log into the service... And I don't like having to adhere to the whims of the password manager about things like changing my password every 6 months or using certain characters... It's really none of their business to determine what level of security is appropriate for me when trying to access my Instagram account which I barely care about anyway. I'm not some billionaire with teams of hackers trying to crack into my account 24/7.

I hate it when I can't use certain passwords because the password manager thinks it should contain certain characters which I simply won't remember.

I hate when trying to log into LastPass with my master password and I can't remember my password and have to try like 10 permutations to find the one in the format that it forced me to use last time that it forced me to change my password.

I hate getting locked out of LastPass and having to go through its 'Forgot my password' flow only to find out that the password for my email account which receives the email password reset link is also controlled by LastPass... And it's only by the grace of god that I had not trusted LastPass to generate my email password for me and I was able to guess it and didn't end up fully locked out of all my services which I need for my work.

That last experience was so scary, I actually wrote down my LastPass master password on a piece of paper and put it in my desk drawers so that I would not forget it. I know this is insecure but that sort of risk profile is aligned with my current non-billionaire status. Somehow, I don't think North Korea is going to send spies to my house to peak into my desk drawers to break into my work accounts...

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#238

Earlier quoted context omitted.

Then you have a much bigger and immediate problem at hand.

What do you mean? There's a tourist experiencing this scenario probably every minute.

This is why 1Password provides an emergency kit where you can record your secret key and store it securely.

How you choose to safeguard it depends on your preferences and your "threat level".

For example, you can keep it in a bank vault or print multiple copies to store it under your pillow, taking a picture, or save it in your email, etc.

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#239

Earlier quoted context omitted.

> family sharing Why would someone make a feature like this? I'm confused why some companies (including Amazon and Steam) insist on family features. The mental model behind this is more prescriptive than descriptive - it doesn't match to how users and their families function; rather, it insists on some activities to a) exist in family, and b) be not allowed outside of family. Or simply: how many people have actual fa…

I don’t have amazon or steam so don’t know how any of that works. But for a password manager, family sharing is extremely useful. Bitwarden doesn’t have families per se, it’s got “organisations”. You can setup unlimited number of organisations and users can get invited and join them. Which is very handy for example my wife and I can login and order our groceries from the supermarket using the same account. Or that we…

I have nothing against sharing per se. My issue is with the family nomenclature. In your case it might align perfectly, but for myself and most people I know, it's not the case. That is, the set of people to share a Netflix subscription with, share Steam library with, share Kindle library with, share passwords to various web services, including utility companies, are only partially overlapping, and do not align perfectly with the idea of "family" or "household".

Re: Feds Link Cyberheist to 2022 LastPass Hacks

#240

Earlier quoted context omitted.

I don’t have amazon or steam so don’t know how any of that works. But for a password manager, family sharing is extremely useful. Bitwarden doesn’t have families per se, it’s got “organisations”. You can setup unlimited number of organisations and users can get invited and join them. Which is very handy for example my wife and I can login and order our groceries from the supermarket using the same account. Or that we…

I have nothing against sharing per se. My issue is with the family nomenclature. In your case it might align perfectly, but for myself and most people I know, it's not the case. That is, the set of people to share a Netflix subscription with, share Steam library with, share Kindle library with, share passwords to various web services, including utility companies, are only partially overlapping, and do not align perfe…

Ah ok gotcha. Your issue is with the ‘family’ nomenclature not the functionality, and I fully agree with you.

For what it’s worth Bitwarden doesn’t use that term, they call it Organisation. Personally I feel like ‘Group’ is actually the better term.

Post reply on HN