Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

31–40 of 246 posts

Re: LastPass notifies users of yet another data breach

#31

Sitting here with my KeepassX and being happy, again.

For folks new to the KeePass ecosystem, it’s KeePassXC[0] now. The original KeePass is still developed as well, however KeePassXC is a cross-platform updated version.

[0] https://keepassxc.org/

Re: LastPass notifies users of yet another data breach

#32

So... you business plan is to secure peoples personal data by handing some of that data to a third party. Got it.

the Achilles heel of a "secrets vault" is it becomes a defacto priority target. I still dont see how any reasonable person was convinced a cloud service was the best place to put all their secrets.

The problem is not the secrets vault. It's the casual acceptance of giving peoples data to third party processors. What value do last pass customers get from having their details passed on to a marketing firm? None. For all the talk of privacy and putting customers first they are acting like any other company in any other field.

Re: LastPass notifies users of yet another data breach

#33
post #16

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

Moving to another solution involves some expense and operational risk (changing procedures, increased human error rates, locking yourself out). Even though the risk of staying with the existing solution goes from "unlikely" to "possible" (so maybe from yellow/amber to red), a lot of companies rationalize it as "but now the provider will be extra careful so the likelihood is actually lower".

Crowdstrike had a famous incident and is still probably #2 in the cybersecurity world. Sometimes assessing risk is a funny business.

Re: LastPass notifies users of yet another data breach

#35
post #14
post #4

Earlier quoted context omitted.

>“On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams, which integrates with our Salesforce and Gong systems,” The specific dependency that gets companies infected, and the optics that result, are so important. There have been sillier examples, but you can see how in this case, the priority of sales and pr…

“ the priority of sales and profits has resulted in the sacrifice of the main quality measure of their main and only product” What do you mean exactly here What do you think LastPass could have done to prevent this specific issue?

Bitwarden doesn't redirect you to a third party if you visit their support page:

https://bitwarden.com/help/

But LastPass does (Salesforce CNAME):

https://support.lastpass.com/s/?language=en_US

So this couldn't have happened to bitwarden, you own the reputation loss if any of your suppliers get owned. Though it really doesn't matter anymore for LastPass they leaked their customers vaults before, I have no idea how they can still be in business.

Re: LastPass notifies users of yet another data breach

#36
post #16

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

This.

If you want to be a security vendor reseller, just make sure to sell to orgs that have a compliance requirement, either by law or similar.

Do you sell firewalls? sell them to banks or something. Anti-malware endpoints? Insurances too. SIEMs? payment gateways for their PCI DSS environments.

Price it just below what would be the fine for not complying, that way you maximize the invoice.

I stopped playing the security vendor reseller game because it got too boring this way to make money.

Re: LastPass notifies users of yet another data breach

#37

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

The one that amazes me is Okta. OK their Mac UX is great, but given their rate of incidents how can you trust it? Clearly this stuff is not actually bought based on track record.

As someone that is not really in the game, does Okta have such a bad track record, and are there alternatives that are considered solid? From the outside, it seemed like EntraID is a bit of a burning dumpster fire, while Okta seemed expensive, but usable and decent (from comments I read)

Re: LastPass notifies users of yet another data breach

#38

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

What's the risk, and does that change by moving to an alternative? Companies deal with leaked secrets a lot. A company already using a password manager is ahead of the game. Suppose they move to a competitor. That's a migration and training that someone has to drive. What do they gain? Another company that can also have exploits? Or they self-host, and now have to fund that, and still potentially get exploits? Ultima…

Compare https://hn.algolia.com/?q=lastpass to basically any other password manager, like https://hn.algolia.com/?q=1password or https://hn.algolia.com/?q=bitwarden

Those companies do not have the same number and severity of security incidents. lastpass is truly in a category of its own

Re: LastPass notifies users of yet another data breach

#39

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

> They were using LP immediately following a previous LP security incident

“Yeah, but they fixed that!”

Normies don’t pull the historical list of breaches and vulns.

They just read headlines.

Re: LastPass notifies users of yet another data breach

#40
post #14
post #4

Earlier quoted context omitted.

>“On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams, which integrates with our Salesforce and Gong systems,” The specific dependency that gets companies infected, and the optics that result, are so important. There have been sillier examples, but you can see how in this case, the priority of sales and pr…

“ the priority of sales and profits has resulted in the sacrifice of the main quality measure of their main and only product” What do you mean exactly here What do you think LastPass could have done to prevent this specific issue?

Not supply the information to any other company.
Post reply on HN