Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

41–50 of 246 posts

Re: LastPass notifies users of yet another data breach

#41
post #3

Using a password manager has 2 main tradeoffs and mistakes: 1- Tradeoff individual account risk, for systemic risk. You may argue password managers are safe, but few would argue that the risk model reduces the risk of individual password leaks more than the risk of all your passwords leaking. It's a tradeoff. 2- Cat and mouse security: There's a class of security decisions that work because they are new and different…

It's not just about long vs. short passwords. IMO the greatest benefit of having a password manager -- whether it's a bloated Electron app or just a text file on your computer -- is that it enables you to juggle hundreds of different passwords, randomly generated for each site. It's the best way we know of to limit the blast radius when (not if!) some of those sites inevitably get hacked.

Re: LastPass notifies users of yet another data breach

#43
post #33
post #16

Earlier quoted context omitted.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

Moving to another solution involves some expense and operational risk (changing procedures, increased human error rates, locking yourself out). Even though the risk of staying with the existing solution goes from "unlikely" to "possible" (so maybe from yellow/amber to red), a lot of companies rationalize it as "but now the provider will be extra careful so the likelihood is actually lower". Crowdstrike had a famous i…

True, but how come such risks are addressable when adding AI or opening up to yet another API or when some savings are promised with a new product/product feature?

Re: LastPass notifies users of yet another data breach

#44
post #23
post #16

Earlier quoted context omitted.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

And it will continue until we can sue company being breached for criminal negligence. Should a single company executive be personally liable in these situations, the scale of the problem would be orders of magnitude less severe because they would spend the appropriate amount of effort to cover their damn ass.

This is it. These companies don't really care about their customer's data. Their SDLC is no more rigorous than any other SaaS product. They have junior people and (now) AI pushing code with a quick "LGTM" PR check just like everyone else.

The way to stop this is to have actual consequences for the decision makers here. You can build high-integrity software and some fields (avionics) have done it. But the organization needs to be built from the ground up to do it and nobody's going to do it if you can just get breached and offer a phony apology over and over again.

Re: LastPass notifies users of yet another data breach

#45
post #12

I'm sure this is worse than using lastpass in some way but for the past couple years I've just generated and forgotten 90% of my passwords. the final 10% I keep in a password manager. But if the service isn't really that important I just use the 'forgot my password' to change and generate a new password every time I need to login

I got caught out as I had no longer access to the old phone number that was now used to send 2FA text.

Re: LastPass notifies users of yet another data breach

#46

Sitting here with my KeepassX and being happy, again.

For folks new to the KeePass ecosystem, it’s KeePassXC[0] now. The original KeePass is still developed as well, however KeePassXC is a cross-platform updated version. [0] https://keepassxc.org/

How good is their mobile and sync story?

Re: LastPass notifies users of yet another data breach

#47
post #8
post #3

Using a password manager has 2 main tradeoffs and mistakes: 1- Tradeoff individual account risk, for systemic risk. You may argue password managers are safe, but few would argue that the risk model reduces the risk of individual password leaks more than the risk of all your passwords leaking. It's a tradeoff. 2- Cat and mouse security: There's a class of security decisions that work because they are new and different…

"Password manager" used to mean a program that runs locally on your computer. At some point people started making it into a SaaS, because that's more profitable. I do think there are some cases where an online password manager makes sense, e.g. for businesses, but for individuals it's better to just stick with an offline password manager, at least for the high value accounts.

It became SaaS because its more practical when you have many devices or many users.

Re: LastPass notifies users of yet another data breach

#48

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

I’ve done a lot of security consulting work for hundreds of companies and one thing I noticed is that the companies that actually took security seriously were the ones that had been breached in the past. Until the execs and board see the dollar impact themself and not just read about it, the security program never gets the funds it needs.

I’m not saying I recommend LastPass for that reason, but I wouldn’t write them off for that reason.

Re: LastPass notifies users of yet another data breach

#49
post #44
post #23

Earlier quoted context omitted.

And it will continue until we can sue company being breached for criminal negligence. Should a single company executive be personally liable in these situations, the scale of the problem would be orders of magnitude less severe because they would spend the appropriate amount of effort to cover their damn ass.

This is it. These companies don't really care about their customer's data. Their SDLC is no more rigorous than any other SaaS product. They have junior people and (now) AI pushing code with a quick "LGTM" PR check just like everyone else. The way to stop this is to have actual consequences for the decision makers here. You can build high-integrity software and some fields (avionics) have done it. But the organization…

“Here’s a year of credit monitoring. Be grateful.”

Re: LastPass notifies users of yet another data breach

#50

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

The one that amazes me is Okta. OK their Mac UX is great, but given their rate of incidents how can you trust it? Clearly this stuff is not actually bought based on track record.

Funny I used to work in an org with Okta.

Having your own auth workflow was instant fail with the well architected framework committee. Using Okta was instant pass.

I don't necessarily disagree with that policy but given that Okta was breached several times while I was working there, it was interesting the extent to which our CSO had blinders about it.

Post reply on HN