Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

11–20 of 246 posts

Re: LastPass notifies users of yet another data breach

#11
post #3

Using a password manager has 2 main tradeoffs and mistakes: 1- Tradeoff individual account risk, for systemic risk. You may argue password managers are safe, but few would argue that the risk model reduces the risk of individual password leaks more than the risk of all your passwords leaking. It's a tradeoff. 2- Cat and mouse security: There's a class of security decisions that work because they are new and different…

The article is about a marketing data breach, not passwords.

Re: LastPass notifies users of yet another data breach

#12
I'm sure this is worse than using lastpass in some way

but for the past couple years I've just generated and forgotten 90% of my passwords. the final 10% I keep in a password manager. But if the service isn't really that important I just use the 'forgot my password' to change and generate a new password every time I need to login

Re: LastPass notifies users of yet another data breach

#13
https://blog.lastpass.com/posts/klue-supply-chain-incident-a...

> The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.

Re: LastPass notifies users of yet another data breach

#14
post #4
post #2

https://news.ycombinator.com/item?id=48657784 https://news.ycombinator.com/item?id=48647272 Third time's the charm

>“On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams, which integrates with our Salesforce and Gong systems,” The specific dependency that gets companies infected, and the optics that result, are so important. There have been sillier examples, but you can see how in this case, the priority of sales and pr…

“ the priority of sales and profits has resulted in the sacrifice of the main quality measure of their main and only product”

What do you mean exactly here What do you think LastPass could have done to prevent this specific issue?

Re: LastPass notifies users of yet another data breach

#15
post #8
post #3

Using a password manager has 2 main tradeoffs and mistakes: 1- Tradeoff individual account risk, for systemic risk. You may argue password managers are safe, but few would argue that the risk model reduces the risk of individual password leaks more than the risk of all your passwords leaking. It's a tradeoff. 2- Cat and mouse security: There's a class of security decisions that work because they are new and different…

"Password manager" used to mean a program that runs locally on your computer. At some point people started making it into a SaaS, because that's more profitable. I do think there are some cases where an online password manager makes sense, e.g. for businesses, but for individuals it's better to just stick with an offline password manager, at least for the high value accounts.

You can and should have the best of both worlds. Using Enpass, the program _is_ local, it just backs up the entire database (encrypted SQLite3) to a cloud.

But if even that is too much then f.ex. `keepass` + a scheduled script to periodically backup to your own servers is also perfectly viable.

Re: LastPass notifies users of yet another data breach

#16

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

Re: LastPass notifies users of yet another data breach

#18

So... you business plan is to secure peoples personal data by handing some of that data to a third party. Got it.

the Achilles heel of a "secrets vault" is it becomes a defacto priority target. I still dont see how any reasonable person was convinced a cloud service was the best place to put all their secrets.

Gmail is at least as large a target, and they don’t keep having breaches.

Re: LastPass notifies users of yet another data breach

#20
post #14
post #4

Earlier quoted context omitted.

>“On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams, which integrates with our Salesforce and Gong systems,” The specific dependency that gets companies infected, and the optics that result, are so important. There have been sillier examples, but you can see how in this case, the priority of sales and pr…

“ the priority of sales and profits has resulted in the sacrifice of the main quality measure of their main and only product” What do you mean exactly here What do you think LastPass could have done to prevent this specific issue?

Did they need to give them all of this?

customer names, phone numbers, email addresses, physical addresses, support case data, sales-related data.

Post reply on HN