LastPass notifies users of yet another data breach
131–140 of 246 posts
Re: LastPass notifies users of yet another data breach
#132Earlier quoted context omitted.
> I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. Yeah but wanting a product like LastPass doesn't require that you use LastPass. There are many good alternatives.
What's the solution? Don't have a CRM and store stuff about customers under lock and key? Don't give access to the CRM to any employees? More security training about clicking shady links? I don't get how you think some other competitor would be better suited against this threat. The right solution is to mitigate the damage. CRM has minimum available stuff, like names, addresses, etc. Don't keep stuff like payment inf…
Use any of the other password managers that don't have the poor security history that LP do.
Re: LastPass notifies users of yet another data breach
#133Earlier quoted context omitted.
I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…
> I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. > With something like LastPass it's also much easier to create unique strong passwords for other sites. Sure, but LastPass, in addition to being the least secure option, doesn't even have a good user interface, and it's expensive. There are dozens of other pass…
Switching takes time and energy.
Changing all your passwords after you switch so they aren't potentially exposed in the next LastPass break takes time and energy.
People have a lot of things going on and have to make a decision about whether the risk justifies the effort.
Then there's feature gaps. LastPass is available on all platforms, has convenient sharing, a good story for emergency recovery if I'm incapacitated and want family to get access to things, and support for 2FA options such as Yubikey. Most competitors lack at least some of those, which is an issue if you're relying on them.
Personally, I left Lastpass for 1Password several breaches ago, but it took me a couple weeks of research to decide where to move to, at least a week of changing passwords on sites afterwards, and however much time and energy it took me to help others who I share credentials with switch at the same time.
Re: LastPass notifies users of yet another data breach
#134Earlier quoted context omitted.
A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.
I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…
Right, but LastPass is a company that wants to make you believe that you can trust them with some of your most important assets.
--
Probably related to this:
https://www.bleepingcomputer.com/news/security/lastpass-conf...
“On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams, which integrates with our Salesforce and Gong systems,” LastPass says.
"We immediately launched an investigation and learned that, as part of this incident, an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass.”
“The threat actor then used these credentials to access LastPass customer data within our Salesforce environment.”
Re: LastPass notifies users of yet another data breach
#135Any detailed info on why Klue had this data, apart from being their partner? How does it serve LastPass customers to give that data to Klue?
Alternate revenue source to keep them in business as they probably hemorrhage customers due to being maybe the least secure password manager ever? I have to wonder how they have any customers left at all at this point
It's a purpose specific knowledge base, not a data broker or any sort. But it will surely have information of who you sold to or tried to sell to because of it.
Re: LastPass notifies users of yet another data breach
#136Earlier quoted context omitted.
“ the priority of sales and profits has resulted in the sacrifice of the main quality measure of their main and only product” What do you mean exactly here What do you think LastPass could have done to prevent this specific issue?
Not installing the infected package of course. It's worth noting that this is not 'their marketing provider' what they do is load 30 different providers for some reason, to maximize the reach of their data sharing and advertising network. Well, their network reached too far and touched an infected node.
Re: LastPass notifies users of yet another data breach
#137How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.
Re: LastPass notifies users of yet another data breach
#138How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.
Re: LastPass notifies users of yet another data breach
#139Re: LastPass notifies users of yet another data breach
#140Earlier quoted context omitted.
I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…
1Password checks all these boxes and hasn't yet had a data breach. Their biggest security hole is probably somewhere in the operational pipeline between 1P browser client developers and the static file servers hosting them.