i can sympathize a little bit with companies that stick with lastpass. when i had to switch an org from lastpass to 1password, it was a massive undertaking and incredibly annoying. however, i have no sympathy for anyone who has chosen lastpass after 2022.
LastPass notifies users of yet another data breach
51–60 of 246 posts
Re: LastPass notifies users of yet another data breach
#52Earlier quoted context omitted.
For folks new to the KeePass ecosystem, it’s KeePassXC[0] now. The original KeePass is still developed as well, however KeePassXC is a cross-platform updated version. [0] https://keepassxc.org/
How good is their mobile and sync story?
Re: LastPass notifies users of yet another data breach
#53I'm sure this is worse than using lastpass in some way but for the past couple years I've just generated and forgotten 90% of my passwords. the final 10% I keep in a password manager. But if the service isn't really that important I just use the 'forgot my password' to change and generate a new password every time I need to login
I got caught out as I had no longer access to the old phone number that was now used to send 2FA text.
Re: LastPass notifies users of yet another data breach
#54Re: LastPass notifies users of yet another data breach
#55How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.
With something like LastPass it's also much easier to create unique strong passwords for other sites.
Also, let's be real:
> The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.
I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already. This has nothing to do with the security of your passwords stored in LP. They have some CRM, some person from their 800 employees clicked a sketchy link and it leaked that. It's not good, but its hardly an indictment of their product or usefulness
Re: LastPass notifies users of yet another data breach
#56Earlier quoted context omitted.
For folks new to the KeePass ecosystem, it’s KeePassXC[0] now. The original KeePass is still developed as well, however KeePassXC is a cross-platform updated version. [0] https://keepassxc.org/
How good is their mobile and sync story?
There are a few decent Android and iOS apps that work well. I use Nextcloud and WebDAV for access.
Not a setup I can recommend to just anybody though.
Re: LastPass notifies users of yet another data breach
#57Using a password manager has 2 main tradeoffs and mistakes: 1- Tradeoff individual account risk, for systemic risk. You may argue password managers are safe, but few would argue that the risk model reduces the risk of individual password leaks more than the risk of all your passwords leaking. It's a tradeoff. 2- Cat and mouse security: There's a class of security decisions that work because they are new and different…
"Password manager" used to mean a program that runs locally on your computer. At some point people started making it into a SaaS, because that's more profitable. I do think there are some cases where an online password manager makes sense, e.g. for businesses, but for individuals it's better to just stick with an offline password manager, at least for the high value accounts.
Wait. That's a thing? Like, there are drooling, mouth-breathing stooges out there that would trust not just one of their passwords to such a thing, but all their passwords to it?
Re: LastPass notifies users of yet another data breach
#58Earlier quoted context omitted.
The one that amazes me is Okta. OK their Mac UX is great, but given their rate of incidents how can you trust it? Clearly this stuff is not actually bought based on track record.
As someone that is not really in the game, does Okta have such a bad track record, and are there alternatives that are considered solid? From the outside, it seemed like EntraID is a bit of a burning dumpster fire, while Okta seemed expensive, but usable and decent (from comments I read)
Re: LastPass notifies users of yet another data breach
#59How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
I’ve done a lot of security consulting work for hundreds of companies and one thing I noticed is that the companies that actually took security seriously were the ones that had been breached in the past. Until the execs and board see the dollar impact themself and not just read about it, the security program never gets the funds it needs. I’m not saying I recommend LastPass for that reason, but I wouldn’t write them…
Re: LastPass notifies users of yet another data breach
#60This isn't great but it's not that big of a deal either. A lot of companies got bit by the Klue breach but it's not like your vaults are being accessed.