LastPass notifies users of yet another data breach
161–170 of 246 posts
Re: LastPass notifies users of yet another data breach
#162Earlier quoted context omitted.
1Password checks all these boxes and hasn't yet had a data breach. Their biggest security hole is probably somewhere in the operational pipeline between 1P browser client developers and the static file servers hosting them.
Unfortunately it's one of the most bug-ridden and unreliable pieces of software I've ever used. I encounter issues with it on a daily basis, but the burden of switching and a lack of superior options keeps me locked in.
I've more or less switched to apple keychain/passwords at this point. I need a solution for linux, and have been thinking about some kind of simple 1-way sync issue that dumps stuff from keychain into some other tool for use on linux.
Re: LastPass notifies users of yet another data breach
#163I, like many others, wanted to move off of LP but was too lazy. So I just exported my passwords and put them into Google Sheets. While I have rotated many of those passwords (especially the important ones) and put them into a better password manager, there are several I haven't — and they've remained safer in Google Sheets than in LP. The lesson here is to get off of LP ASAP, you can figure out where to go later.
You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.
At the end of it I couldn't help but reflect on my foolishness. I realised just how much better I would've felt if only it had been an American, Canadian, or European Googler who stole my data. It really is the worst when malicious entities are Chinese, Indian, or Pakistani. Just the worst!!! (/s)
Re: LastPass notifies users of yet another data breach
#164I, like many others, wanted to move off of LP but was too lazy. So I just exported my passwords and put them into Google Sheets. While I have rotated many of those passwords (especially the important ones) and put them into a better password manager, there are several I haven't — and they've remained safer in Google Sheets than in LP. The lesson here is to get off of LP ASAP, you can figure out where to go later.
You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.
Re: LastPass notifies users of yet another data breach
#165I, like many others, wanted to move off of LP but was too lazy. So I just exported my passwords and put them into Google Sheets. While I have rotated many of those passwords (especially the important ones) and put them into a better password manager, there are several I haven't — and they've remained safer in Google Sheets than in LP. The lesson here is to get off of LP ASAP, you can figure out where to go later.
You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.
Google accounts aren’t immune to being compromised, so I agree that it’s not a good home for passwords (without even the need to invoke internal threats) — but it felt safer than LastPass. Which ought to be an embarrassment.
Re: LastPass notifies users of yet another data breach
#166Earlier quoted context omitted.
You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.
I had exactly this happen to me, suffered great monetary losses and had my identity stolen. I've learnt my lesson and have moved on to 1password. At the end of it I couldn't help but reflect on my foolishness. I realised just how much better I would've felt if only it had been an American, Canadian, or European Googler who stole my data. It really is the worst when malicious entities are Chinese, Indian, or Pakistani…
Re: LastPass notifies users of yet another data breach
#167Earlier quoted context omitted.
I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…
When their CRM and support systems are improperly secured, it doesn't bode well for the security of their vaults. When attackers infiltrate one system, it's easier to laterally move to other systems. Also, their marketing systems are also a mess. I've unsubscribed from their marketing emails multiple times, but to date I'm still getting marketing emails from them even though I'm no longer a customer. Even contacting…
In the US you can report it to FTC for CAN-SPAM violations, but don't hold your breath on any enforcement.
Re: LastPass notifies users of yet another data breach
#168How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
Re: LastPass notifies users of yet another data breach
#169How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.
If this bank were my client, I would make sure that the decision-makers were aware.
Re: LastPass notifies users of yet another data breach
#170Earlier quoted context omitted.
This is why a lot of services have just moved to using email with magic links to log people in. In the end for a lot of services controlling your email is defacto controlling the login.
Links sent in plaintext over the network. :(