Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

61–70 of 246 posts

Re: LastPass notifies users of yet another data breach

#61

Earlier quoted context omitted.

For folks new to the KeePass ecosystem, it’s KeePassXC[0] now. The original KeePass is still developed as well, however KeePassXC is a cross-platform updated version. [0] https://keepassxc.org/

How good is their mobile and sync story?

The mobile app is quite good, it works and gets out of your way. I use it on Android.

For syncing, I do it manually with rsync. Given the database is 1 file it's easy to move around. You can rsync / scp it over, use a USB cable, use cloud storage, etc..

I use a password manager in a "read many, write infrequently" way so I don't mind occasionally syncing it as needed.

Re: LastPass notifies users of yet another data breach

#62
post #43
post #33

Earlier quoted context omitted.

Moving to another solution involves some expense and operational risk (changing procedures, increased human error rates, locking yourself out). Even though the risk of staying with the existing solution goes from "unlikely" to "possible" (so maybe from yellow/amber to red), a lot of companies rationalize it as "but now the provider will be extra careful so the likelihood is actually lower". Crowdstrike had a famous i…

True, but how come such risks are addressable when adding AI or opening up to yet another API or when some savings are promised with a new product/product feature?

> when adding AI ... or when some savings are promised

Because savings are promised. And who could say no to AI? (/s)

There's always some risk mitigation possible but it's costly or inconvenient. Companies pretend the risk is lower so they can do whatever they wanted to do but now with less accountability. The risk matrix says so.

But sometimes the tradeoff is genuinely not worth it. The bottom line is that each company has to do it's own calculations and decide whether moving is overall a better choice. Which risk is higher, that your provider is breached again or that you have new operational issues with the new solution. Which costs more, a chance of another security issue, or the guaranteed expense of replacing the solution? You do the same math at home all the time. Your washing machine leaked once, do you replace everything or just patch the hole?

Re: LastPass notifies users of yet another data breach

#63

Earlier quoted context omitted.

How good is their mobile and sync story?

Syncing isn't a KeePassXC problem. The database is just a file. That may or may not make your life easier. There are a few decent Android and iOS apps that work well. I use Nextcloud and WebDAV for access. Not a setup I can recommend to just anybody though.

One of the security advantages of KeePass being just a file is that you can sync it in the way that makes sense to you.

The need to have an opinion on how you’d like to sync a file does, as you suggest, eliminate some portion of the population who need a fully baked answer in one step.

I used to use Google Drive, but now I use Syncthing, further reducing my exposure. Paired with Synctrain and KeePassium on iOS.

One tip: enable the atomic save option in settings to reduce the risk of weird cloud sync issues.

Re: LastPass notifies users of yet another data breach

#64
post #37

Earlier quoted context omitted.

As someone that is not really in the game, does Okta have such a bad track record, and are there alternatives that are considered solid? From the outside, it seemed like EntraID is a bit of a burning dumpster fire, while Okta seemed expensive, but usable and decent (from comments I read)

The current default for lazy enterprise customers seems to be an unholy tangle of Active Directory, Entra, and Okta. If you use all three it's 3x more secure, right?

Okta I get, Entra I sort of get. But AD is great.

Re: LastPass notifies users of yet another data breach

#65

Sitting here with my KeepassX and being happy, again.

For folks new to the KeePass ecosystem, it’s KeePassXC[0] now. The original KeePass is still developed as well, however KeePassXC is a cross-platform updated version. [0] https://keepassxc.org/

does the UI have a compact mode?

Re: LastPass notifies users of yet another data breach

#66

Earlier quoted context omitted.

For folks new to the KeePass ecosystem, it’s KeePassXC[0] now. The original KeePass is still developed as well, however KeePassXC is a cross-platform updated version. [0] https://keepassxc.org/

does the UI have a compact mode?

https://keepassxc.org/docs/KeePassXC_UserGuide#_compact_mode

Re: LastPass notifies users of yet another data breach

#67

Earlier quoted context omitted.

I’ve done a lot of security consulting work for hundreds of companies and one thing I noticed is that the companies that actually took security seriously were the ones that had been breached in the past. Until the execs and board see the dollar impact themself and not just read about it, the security program never gets the funds it needs. I’m not saying I recommend LastPass for that reason, but I wouldn’t write them…

But LastPass has been breached multiple times by now. I don't think they really care

There are lots of types of a “breach”. The first and second (the major ones) were likely related so more like one continuous incident. This one was a vendor breach that had access to their data so not a reflection of their security program as much as the first.

I’m not saying you’re wrong, I’m saying you can’t tell from this incident.

Re: LastPass notifies users of yet another data breach

#68
post #16

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

At some companies, "approved security vendor" just means the breach comes with procurement paperwork.

Re: LastPass notifies users of yet another data breach

#69

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

How does anyone trust ANY third party with all their passwords and encryption keys is beyond me.

Setting up KeePassXC is trivial.

Re: LastPass notifies users of yet another data breach

#70

This isn't great but it's not that big of a deal either. A lot of companies got bit by the Klue breach but it's not like your vaults are being accessed.

The vaults were accessed years ago

The encrypted vaults, yes. Ideally they are worthless when the master password is sufficiently complex
Post reply on HN