Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

91–100 of 246 posts

Re: LastPass notifies users of yet another data breach

#93

Any detailed info on why Klue had this data, apart from being their partner? How does it serve LastPass customers to give that data to Klue?

Alternate revenue source to keep them in business as they probably hemorrhage customers due to being maybe the least secure password manager ever? I have to wonder how they have any customers left at all at this point

Re: LastPass notifies users of yet another data breach

#94
post #21

Lots more companies affected. Some more listed below: >"Klue has not said how many of its hundreds of customers are affected. Several companies have come forward to confirm they had data stolen during the attack, including Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium." >Cybercrime group Icarus took credit for the breach, saying on its leak site that it will publish the s…

[deleted]

Re: LastPass notifies users of yet another data breach

#95
post #16

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

Also use them as a password manager like an advanced version of Excel that fills in the passwords for you. Security isn't part of it. I have the feeling LastPass agrees.

Re: LastPass notifies users of yet another data breach

#96

Earlier quoted context omitted.

What's the risk, and does that change by moving to an alternative? Companies deal with leaked secrets a lot. A company already using a password manager is ahead of the game. Suppose they move to a competitor. That's a migration and training that someone has to drive. What do they gain? Another company that can also have exploits? Or they self-host, and now have to fund that, and still potentially get exploits? Ultima…

Compare https://hn.algolia.com/?q=lastpass to basically any other password manager, like https://hn.algolia.com/?q=1password or https://hn.algolia.com/?q=bitwarden Those companies do not have the same number and severity of security incidents. lastpass is truly in a category of its own

i'd love to switch from my lastpass family plan to... something else.

but there is a non-trivial switching cost to migrate several people (with varying technical aptitudes) that each use several platforms.

if 1password had a one-click migration flow they'd be able to win over a lot of converts.

Re: LastPass notifies users of yet another data breach

#99
post #8

Earlier quoted context omitted.

"Password manager" used to mean a program that runs locally on your computer. At some point people started making it into a SaaS, because that's more profitable. I do think there are some cases where an online password manager makes sense, e.g. for businesses, but for individuals it's better to just stick with an offline password manager, at least for the high value accounts.

>At some point people started making it into a SaaS, because Wait. That's a thing? Like, there are drooling, mouth-breathing stooges out there that would trust not just one of their passwords to such a thing, but all their passwords to it?

heavy mouth-breathing

Re: LastPass notifies users of yet another data breach

#100
post #3

Using a password manager has 2 main tradeoffs and mistakes: 1- Tradeoff individual account risk, for systemic risk. You may argue password managers are safe, but few would argue that the risk model reduces the risk of individual password leaks more than the risk of all your passwords leaking. It's a tradeoff. 2- Cat and mouse security: There's a class of security decisions that work because they are new and different…

We need a bitcoin hardware wallet kind of password manager, where the actual passwords are stored on a hardware security key. When you click on the computer on the password you want to use, the hardware security key shows it's name on it's screen, and asks you to press a button on it to confirm that you want to use it.

For backup, the hardware security key let's you download a file from it with all of your passwords encrypted, and the decryption password it's shown on it's screen (something like 12 random words)

Post reply on HN