Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

141–150 of 246 posts

Re: LastPass notifies users of yet another data breach

#141
post #69

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.

KeePassXC is not for a "normal" user. It really needs to get default entry tempates [1] out the door.

[1] https://github.com/keepassxreboot/keepassxc/issues/8228

Re: LastPass notifies users of yet another data breach

#143
Unpopular take:

I "just" use google chrome password manager for "everything".. yes im sure it horrifies some HN ppl but my thinking is, from all the password managers out there, does anyone one spend more on security or hire better security ppl or have access to better security tools and infra than google (yes yes im sure outliers and some counter examples exists).

I routinely die a little inside when i see my gf (none techie) try and remember which one of her fav 3-5 often used passwords she has used for site/service abc as she tries to login.

Kinda tongue in cheek, I always tell her if you can remember your password it's a bad one !

Re: LastPass notifies users of yet another data breach

#144
post #55
post #16

Earlier quoted context omitted.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

When their CRM and support systems are improperly secured, it doesn't bode well for the security of their vaults. When attackers infiltrate one system, it's easier to laterally move to other systems.

Also, their marketing systems are also a mess. I've unsubscribed from their marketing emails multiple times, but to date I'm still getting marketing emails from them even though I'm no longer a customer. Even contacting their support about this issue hasn't helped.

Re: LastPass notifies users of yet another data breach

#145
WTF is LastPasd doing, handing customer details to a market research company? Any such data should have been fully anonymized: no names, no specific addresses, etc..

For anyone looking for a recommendation: I use KeepassXC with Keepass2Android. Open source, with a local database that you can choose to sync (or not). I sync using Own cloud.

Re: LastPass notifies users of yet another data breach

#147
I, like many others, wanted to move off of LP but was too lazy. So I just exported my passwords and put them into Google Sheets. While I have rotated many of those passwords (especially the important ones) and put them into a better password manager, there are several I haven't — and they've remained safer in Google Sheets than in LP.

The lesson here is to get off of LP ASAP, you can figure out where to go later.

Re: LastPass notifies users of yet another data breach

#149
post #69

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.

it's "trivial" in the sense of "I can launch the app in 2 minutes," but "non-trivial" in the sense of "I have a working, synced password manager across my devices with good security practices."

Re: LastPass notifies users of yet another data breach

#150
post #20
post #14

Earlier quoted context omitted.

“ the priority of sales and profits has resulted in the sacrifice of the main quality measure of their main and only product” What do you mean exactly here What do you think LastPass could have done to prevent this specific issue?

Did they need to give them all of this? customer names, phone numbers, email addresses, physical addresses, support case data, sales-related data.

Generally yes, if you want to use a Customer Relationship Management system like Salesforce. Customer names, contact information, and info about what they bought from you is table stakes data for CRM is it not?
Post reply on HN