Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

201–210 of 246 posts

Re: LastPass notifies users of yet another data breach

#201

As much as the collective dumping on LastPass for yet another breach, and how they're totally irresponsible for handing customer data to some third party is amusing. I think if people took a moment to actually look at what happened, they might realise that the story everyone has in their heads is quite different from reality. Klue is one of those CRM services that so many sales teams are using. Yes, you have to hand…

> I am more surprised that these breaches don't happen more often. They do.

they do.

how often you notify the public is a completely different discussion.

Re: LastPass notifies users of yet another data breach

#202

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

I’ve done a lot of security consulting work for hundreds of companies and one thing I noticed is that the companies that actually took security seriously were the ones that had been breached in the past. Until the execs and board see the dollar impact themself and not just read about it, the security program never gets the funds it needs. I’m not saying I recommend LastPass for that reason, but I wouldn’t write them…

If the execs and board of a password manager company need to experience a breach to take security seriously, I don't really know what to say.

Re: LastPass notifies users of yet another data breach

#204

Earlier quoted context omitted.

1Password checks all these boxes and hasn't yet had a data breach. Their biggest security hole is probably somewhere in the operational pipeline between 1P browser client developers and the static file servers hosting them.

Unfortunately it's one of the most bug-ridden and unreliable pieces of software I've ever used. I encounter issues with it on a daily basis, but the burden of switching and a lack of superior options keeps me locked in.

Any example bugs that you've encountered in the last week?

Re: LastPass notifies users of yet another data breach

#205

Earlier quoted context omitted.

How good is their mobile and sync story?

These threads are always filled with keepass people who will tell you how great it is and not mention that you’re on your fucking own for you know Miner things like syncing or mobile use. I’m sure it works for many people to Dropbox their vault around anytime they want to access something and manually handle copies and sync. I’m not nearly so naive as to think that has any degree of success outside tech bubbled peopl…

I have yet to meet a KeePass user under the illusion that the syncing story is a good fit for everyone.

But we are prioritizing “can’t” over “won’t” in terms of provider access to our credentials. That’s why these hack-related threads tend to draw folks who will remind you that other tradeoffs exist.

For a technical audience like HN, “can work out how to sync a file” is a decent assumption to make.

Re: LastPass notifies users of yet another data breach

#206
post #189

Earlier quoted context omitted.

I stopped paying them when they killed local valuts, and secondarily when then moved away from native apps. I drifted along on the old 7.x client for awhile with local values. I've more or less switched to apple keychain/passwords at this point. I need a solution for linux, and have been thinking about some kind of simple 1-way sync issue that dumps stuff from keychain into some other tool for use on linux.

Curious if you have any gripes or concerns about using the Apple keychain/passwords setup. Aside from Apple devices, do you mostly also stick with Safari? Was it hard to transition things like TOTP or passkeys?

i mostly stick to firefox I do some management of moving some passwords back and forth (i'm not yet using the firefox extension for apple passwords because i just learned about it).. but because i use firefox on my phone as well.. nbd.

In terms of TOTP I just use googleauth and oathtool.

Re: LastPass notifies users of yet another data breach

#208
post #69

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.

KeepassXC comes with its own share of risks (supply-chain attacks, zero-day vulnerability detections etc). No matter, which 3p software you are using, you are effectively gambling on the chance that none of those risks materialize. The only alternative is to personally audit the code - library by library, script by script and build it yourself. But even that carries risks: https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...

Re: LastPass notifies users of yet another data breach

#209
post #124

Earlier quoted context omitted.

> I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. Yeah but wanting a product like LastPass doesn't require that you use LastPass. There are many good alternatives.

What's the solution? Don't have a CRM and store stuff about customers under lock and key? Don't give access to the CRM to any employees? More security training about clicking shady links? I don't get how you think some other competitor would be better suited against this threat. The right solution is to mitigate the damage. CRM has minimum available stuff, like names, addresses, etc. Don't keep stuff like payment inf…

Brand damage and lost of trust from customers are consequences of security breaches. I'm not saying don't have a CRM, but I am saying don't complain when the customer data in your CRM leaks and customers complain. LastPass has had several such breaches over the years, and I think people are right to say that the company has a reputation of poor security hygiene.

By all means, have a CRM. But consider that it probably doesn't need to be as broadly accessible as you think it does, and consider that the people with access to it probably need to be held to a higher standard.

Re: LastPass notifies users of yet another data breach

#210
post #202

Earlier quoted context omitted.

I’ve done a lot of security consulting work for hundreds of companies and one thing I noticed is that the companies that actually took security seriously were the ones that had been breached in the past. Until the execs and board see the dollar impact themself and not just read about it, the security program never gets the funds it needs. I’m not saying I recommend LastPass for that reason, but I wouldn’t write them…

If the execs and board of a password manager company need to experience a breach to take security seriously, I don't really know what to say.

Weirdly being a security company actually can have the opposite affect. A small portion of potential customers or investors assume the company is more secure because they are a security company after all (and should be); therefore, the customer's security review are less stringent so exec can get away with smaller internal security budgets. Of course good security companys with good leadership doesn't do that... but those aren't the big companies.
Post reply on HN