Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

161–170 of 246 posts

Re: LastPass notifies users of yet another data breach

#162

Earlier quoted context omitted.

1Password checks all these boxes and hasn't yet had a data breach. Their biggest security hole is probably somewhere in the operational pipeline between 1P browser client developers and the static file servers hosting them.

Unfortunately it's one of the most bug-ridden and unreliable pieces of software I've ever used. I encounter issues with it on a daily basis, but the burden of switching and a lack of superior options keeps me locked in.

I stopped paying them when they killed local valuts, and secondarily when then moved away from native apps. I drifted along on the old 7.x client for awhile with local values.

I've more or less switched to apple keychain/passwords at this point. I need a solution for linux, and have been thinking about some kind of simple 1-way sync issue that dumps stuff from keychain into some other tool for use on linux.

Re: LastPass notifies users of yet another data breach

#163
post #147

I, like many others, wanted to move off of LP but was too lazy. So I just exported my passwords and put them into Google Sheets. While I have rotated many of those passwords (especially the important ones) and put them into a better password manager, there are several I haven't — and they've remained safer in Google Sheets than in LP. The lesson here is to get off of LP ASAP, you can figure out where to go later.

You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.

I had exactly this happen to me, suffered great monetary losses and had my identity stolen. I've learnt my lesson and have moved on to 1password.

At the end of it I couldn't help but reflect on my foolishness. I realised just how much better I would've felt if only it had been an American, Canadian, or European Googler who stole my data. It really is the worst when malicious entities are Chinese, Indian, or Pakistani. Just the worst!!! (/s)

Re: LastPass notifies users of yet another data breach

#164
post #147

I, like many others, wanted to move off of LP but was too lazy. So I just exported my passwords and put them into Google Sheets. While I have rotated many of those passwords (especially the important ones) and put them into a better password manager, there are several I haven't — and they've remained safer in Google Sheets than in LP. The lesson here is to get off of LP ASAP, you can figure out where to go later.

You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.

[deleted]

Re: LastPass notifies users of yet another data breach

#165
post #147

I, like many others, wanted to move off of LP but was too lazy. So I just exported my passwords and put them into Google Sheets. While I have rotated many of those passwords (especially the important ones) and put them into a better password manager, there are several I haven't — and they've remained safer in Google Sheets than in LP. The lesson here is to get off of LP ASAP, you can figure out where to go later.

You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.

I put my passwords in Google Sheets temporarily. Then I moved them to 1Password, except the throwaway stuff.

Google accounts aren’t immune to being compromised, so I agree that it’s not a good home for passwords (without even the need to invoke internal threats) — but it felt safer than LastPass. Which ought to be an embarrassment.

Re: LastPass notifies users of yet another data breach

#166

Earlier quoted context omitted.

You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.

I had exactly this happen to me, suffered great monetary losses and had my identity stolen. I've learnt my lesson and have moved on to 1password. At the end of it I couldn't help but reflect on my foolishness. I realised just how much better I would've felt if only it had been an American, Canadian, or European Googler who stole my data. It really is the worst when malicious entities are Chinese, Indian, or Pakistani…

[deleted]

Re: LastPass notifies users of yet another data breach

#167
post #55

Earlier quoted context omitted.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

When their CRM and support systems are improperly secured, it doesn't bode well for the security of their vaults. When attackers infiltrate one system, it's easier to laterally move to other systems. Also, their marketing systems are also a mess. I've unsubscribed from their marketing emails multiple times, but to date I'm still getting marketing emails from them even though I'm no longer a customer. Even contacting…

Assuming you are in EU you could report them to local DPA. Objection (i.e. unsubscribing. Original automatic subscription may or or may not have been legal) to direct marketing is pretty much absolute due to GDPR Article 21(2), I'm not aware of any "workaround" companies have successfully managed to argue.

In the US you can report it to FTC for CAN-SPAM violations, but don't hold your breath on any enforcement.

Re: LastPass notifies users of yet another data breach

#168

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

If you think I'm going to try and get my mom onto a different password manager, after it took literally ten years to migrate her away from the printed list in her purse...

Re: LastPass notifies users of yet another data breach

#169
post #16

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

Well, these types of companies typically carry cyber incident insurance. If there was, say, a ransomware attack, the carrier is going to bring in a forensic team to investigate. If it is determined that there was negligence, like not patching a system, that will be used to deny a claim. This might be a little different from the lastpass situation in that it's an untrustworthy vendor, but there's still significant exposure.

If this bank were my client, I would make sure that the decision-makers were aware.

Re: LastPass notifies users of yet another data breach

#170
post #158

Earlier quoted context omitted.

This is why a lot of services have just moved to using email with magic links to log people in. In the end for a lot of services controlling your email is defacto controlling the login.

Links sent in plaintext over the network. :(

Potentially, but if you have your password reset process be sending a reset code by email it's effectively the same account access.
Post reply on HN