Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

121–130 of 246 posts

Re: LastPass notifies users of yet another data breach

#121
post #8

Earlier quoted context omitted.

"Password manager" used to mean a program that runs locally on your computer. At some point people started making it into a SaaS, because that's more profitable. I do think there are some cases where an online password manager makes sense, e.g. for businesses, but for individuals it's better to just stick with an offline password manager, at least for the high value accounts.

>At some point people started making it into a SaaS, because Wait. That's a thing? Like, there are drooling, mouth-breathing stooges out there that would trust not just one of their passwords to such a thing, but all their passwords to it?

Are you sarcastic, or do you not realize your vault is encrypted with your master password and never readable to the service?

Re: LastPass notifies users of yet another data breach

#122
post #12

I'm sure this is worse than using lastpass in some way but for the past couple years I've just generated and forgotten 90% of my passwords. the final 10% I keep in a password manager. But if the service isn't really that important I just use the 'forgot my password' to change and generate a new password every time I need to login

This is why a lot of services have just moved to using email with magic links to log people in.

In the end for a lot of services controlling your email is defacto controlling the login.

Re: LastPass notifies users of yet another data breach

#123

Earlier quoted context omitted.

Compare https://hn.algolia.com/?q=lastpass to basically any other password manager, like https://hn.algolia.com/?q=1password or https://hn.algolia.com/?q=bitwarden Those companies do not have the same number and severity of security incidents. lastpass is truly in a category of its own

i'd love to switch from my lastpass family plan to... something else. but there is a non-trivial switching cost to migrate several people (with varying technical aptitudes) that each use several platforms. if 1password had a one-click migration flow they'd be able to win over a lot of converts.

You pretty much export your data from lastpass and import it into 1password. The only thing it doesn't do is have 1password log into your lastpass account and pull it out itself.

Re: LastPass notifies users of yet another data breach

#124
post #55

Earlier quoted context omitted.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

> I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. Yeah but wanting a product like LastPass doesn't require that you use LastPass. There are many good alternatives.

What's the solution? Don't have a CRM and store stuff about customers under lock and key? Don't give access to the CRM to any employees? More security training about clicking shady links?

I don't get how you think some other competitor would be better suited against this threat. The right solution is to mitigate the damage. CRM has minimum available stuff, like names, addresses, etc. Don't keep stuff like payment information, passwords, etc in that place as that's the vulnerable system. It seems like that's what LP does and probably every other company in this space does.

Again, it's entirely reasonable to have an off the shelf CRM, pretty broad access to it. You try to prevent phishing email or phone scams (assuming this is what it was) but you have 800 employees, its bound to happen.

Re: LastPass notifies users of yet another data breach

#125
post #55
post #16

Earlier quoted context omitted.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

> I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh.

> With something like LastPass it's also much easier to create unique strong passwords for other sites.

Sure, but LastPass, in addition to being the least secure option, doesn't even have a good user interface, and it's expensive. There are dozens of other password managers out there, each one better than LastPass in every way.

Re: LastPass notifies users of yet another data breach

#126
post #55
post #16

Earlier quoted context omitted.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

1Password checks all these boxes and hasn't yet had a data breach.

Their biggest security hole is probably somewhere in the operational pipeline between 1P browser client developers and the static file servers hosting them.

Re: LastPass notifies users of yet another data breach

#127
post #33
post #16

Earlier quoted context omitted.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

Moving to another solution involves some expense and operational risk (changing procedures, increased human error rates, locking yourself out). Even though the risk of staying with the existing solution goes from "unlikely" to "possible" (so maybe from yellow/amber to red), a lot of companies rationalize it as "but now the provider will be extra careful so the likelihood is actually lower". Crowdstrike had a famous i…

I worked for a big company that switched from 1password to Keeper. The transition was smooth and I do not see why it shouldn’t be as long as IT knows what they are doing.

Re: LastPass notifies users of yet another data breach

#128
post #55

Earlier quoted context omitted.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

> I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. > With something like LastPass it's also much easier to create unique strong passwords for other sites. Sure, but LastPass, in addition to being the least secure option, doesn't even have a good user interface, and it's expensive. There are dozens of other pass…

Password managers are entirely a UX problem waiting to be solved better. Every time I hit a UX bug with my password manager, I mutter that I could do fix that, and then know that mine would also be worse in so many ways just to reach parity. What I wish is there was a public bug tracker of UX issues/optimizations that I, and the rest of the world, could log ideas to. Password managers are such a good idea but they all need just that much more work to be seamless.

Re: LastPass notifies users of yet another data breach

#129

I'm so glad we migrated away from LastPass (to BitWarden). It was a breach that caused us to move in the first instance.

How is the experience with BitWarden clients so far? Their chrome extension bugs out for me for the most basic tasks.

I was just making the change from LP to BW yesterday, completely by coincidence. My first reaction is that the out-of-box experience is poor.

The first step was easy. The account creation and import of legacy data all went pretty well. But after that it wasn't so pretty.

The first hurdle was trying to understand their model for sharing data (so my wife and I can share important credentials). The model that LastPass uses is pretty intuitive to me: it's just a matter of sharing a folder, so relatively transparent. But Bitwarden has a whole separate concept of "organization", and the items being managed don't go in "folders" here, but in "collections". So there are two separate, and subtly different, models in play, and this is confusing. The good news is that the client aggregates the data so when you're using it day-to-day to fill login forms, you don't have to worry about the differences.

Once I'd gotten the data in place, I had to get the clients set up on the various platforms (browser extensions; desktop native, which is actually required for the browser extension's security to work right; phone). The OoB settings were entirely paranoid, and had me re-entering the complex master password over and over, really annoying me. Figuring out how to get to a reasonable balance required figuring out some settings whose labels are misleading. For example, "Unlock with PIN" sounded to me like it was going to add an extra layer of security, but it turns out that it really means "allow unlock using PIN in lieu of master password".

Also, note that while most of the settings default to paranoia-level (like the "require master password every time I inhale", that I mentioned above), you will probably want to change the default crypto cypher. It defaults to PBKDF2, but a better modern approach is the other choice, Argon2id.

...which also reminds me that there's a distinct lack of parity between client platforms. Although you need the desktop native app to manage browser extension security, there's a bunch it can't do. For example, after importing my legacy data, I needed to select all the contents of my LP shared folders and move them to the BW organization collection, but the native app (which seems to be an Electron app, btw) doesn't have a multi-select feature; you need to do that in the online web app.

Re: LastPass notifies users of yet another data breach

#130
post #69

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.

I use KeepassXC, but I have no need to share passwords with other people. In a corporate situation that would probably not work as well.
Post reply on HN