Earlier quoted context omitted.
Funny I used to work in an org with Okta. Having your own auth workflow was instant fail with the well architected framework committee. Using Okta was instant pass. I don't necessarily disagree with that policy but given that Okta was breached several times while I was working there, it was interesting the extent to which our CSO had blinders about it.
Liability is the answer! If you build an auth system and it fails, it's your backside. If Okta fails, it's theirs. Enterprises buy products as much as they buy protection from problems.
LastPass notifies users of yet another data breach
101–110 of 246 posts
Re: LastPass notifies users of yet another data breach
#102Re: LastPass notifies users of yet another data breach
#103any company that stuck around (or began using) lastpass after vaults were leaked probably does not care about this one at all, considering its just CRM data. i can sympathize a little bit with companies that stick with lastpass. when i had to switch an org from lastpass to 1password, it was a massive undertaking and incredibly annoying. however, i have no sympathy for anyone who has chosen lastpass after 2022.
The non-story here is the data is of minor criticality.
The real story is is that however minor, you expect LastPass to be better. They’re a password storage company, in order to be trusted they need to be better than this.
Re: LastPass notifies users of yet another data breach
#104Earlier quoted context omitted.
The vaults were accessed years ago
Yes, in a separate breach.
> Yes, in a separate breech.
Not nearly that cut and dry.
Many, not all encrypted vaults leaked out. If you lost data it was because you used a weak master password for that vault.
Re: LastPass notifies users of yet another data breach
#105Re: LastPass notifies users of yet another data breach
#106Earlier quoted context omitted.
For folks new to the KeePass ecosystem, it’s KeePassXC[0] now. The original KeePass is still developed as well, however KeePassXC is a cross-platform updated version. [0] https://keepassxc.org/
How good is their mobile and sync story?
I’m sure it works for many people to Dropbox their vault around anytime they want to access something and manually handle copies and sync. I’m not nearly so naive as to think that has any degree of success outside tech bubbled people.
Re: LastPass notifies users of yet another data breach
#107Earlier quoted context omitted.
Syncing isn't a KeePassXC problem. The database is just a file. That may or may not make your life easier. There are a few decent Android and iOS apps that work well. I use Nextcloud and WebDAV for access. Not a setup I can recommend to just anybody though.
One of the security advantages of KeePass being just a file is that you can sync it in the way that makes sense to you. The need to have an opinion on how you’d like to sync a file does, as you suggest, eliminate some portion of the population who need a fully baked answer in one step. I used to use Google Drive, but now I use Syncthing, further reducing my exposure. Paired with Synctrain and KeePassium on iOS. One t…
Re: LastPass notifies users of yet another data breach
#108Re: LastPass notifies users of yet another data breach
#109Earlier quoted context omitted.
> I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already. This has nothing to do with the security of your passwords stored in LP. They have some CRM, some person from their 800 employees clicked a sketchy link and it leaked that. It's not good, but its hardly an indictment of their product or usefulness Would you be okay will a public dat…
Yes, a public database like this would be acceptable. That way the info isn't paywalled behind some white pages site or similar. And then maybe I could even update my own info to be correct. Contact info is pretty much out there for most people already. Hell, I put it on my resume and send that out to many people and put it on public sites.
Since we still use SMS as second factors (or primary, as some in this thread said they don't write down passwords but just use password reset links to login), it's not the best security hygiene
Re: LastPass notifies users of yet another data breach
#110How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.