Live data from Hacker News

LastPass Security Notice

blog.lastpass.com

11–20 of 311 posts

Re: LastPass Security Notice

#12
While LastPass seems to be responding well, I find their entire service exceeds my tolerance for risk.

If you don't use a password manager, you've got 99 problems, but a centralized store of your credentials for everything that's a huge target by virtue of having thousands of similarly centralized users ain't one.

Using a password manager (good idea) and then storing all your passwords on a 3rd party service of which you have no control seems inherently risky. Lastpass is a huge target, and while I believe they generally take reasonable security measures, for many the risk of compromise may be greater than an encrypted stand-alone password database. Use a password manager, please, but keep it offline and don't aggregate it with loads of other people's databases.

This is one area where I feel strongly that the conveniences of 'Cloud' are outweighed by the risks.

Re: LastPass Security Notice

#14
post #10

Thoughts on LastPass vs 1Password?

For my personal use, I feel more comfortable with 1Password and having full control over my data.

For company wide use, LastPass Enterprise is a better fit. Centralized management is essential when dealing with larger numbers of not particularly tech savvy and security conscious users.

And despite this incident, I trust a specialized operation like Lastpass more with keeping the data secure 24/7 than myself or company IT.

Re: LastPass Security Notice

#15
post #9
post #3

Oh great, just the day before yesterday I finally jumped to LastPass (because obviously WinKee is not compatible to my new Lumia phone), using my best password (long, no real syllables, memorized). It sounds like the password is still safe enough, but it's a very unfortunate, inconvenient timing indeed.

Try 1Password.

I did just quickly evaluate it on my iPad (got it in some promotion ages ago), but it didn't "click" with me.

OTOH I'm not terribly sold on LastPass's UI, either.

I don't know, but I'm going to sleep a few days over it and check out my options on the weekend. This isn't an "everything's on fire" event, anyway.

Re: LastPass Security Notice

#17
post #12

While LastPass seems to be responding well, I find their entire service exceeds my tolerance for risk. If you don't use a password manager, you've got 99 problems, but a centralized store of your credentials for everything that's a huge target by virtue of having thousands of similarly centralized users ain't one. Using a password manager (good idea) and then storing all your passwords on a 3rd party service of which…

A centralized store is however unavoidable if you want to share and manage passwords inside an organization.

Although I share you discomfort, looking at it rationally I prefer to trust a specialized service, who's very existence and reputation depends on it, more than the alternatives.

The other alternative for sharing is stuff like 1Password over Dropbox, which is imho the worst of both worlds.

Re: LastPass Security Notice

#18
post #12

While LastPass seems to be responding well, I find their entire service exceeds my tolerance for risk. If you don't use a password manager, you've got 99 problems, but a centralized store of your credentials for everything that's a huge target by virtue of having thousands of similarly centralized users ain't one. Using a password manager (good idea) and then storing all your passwords on a 3rd party service of which…

I understand your take on the problem, but one of the features of those services is that they are precisely online: I can get my passwords on my phone, tablet, desktop, laptop, abroad or at work. If my password manager is offline, it's safer, but it's also a poorer experience.

Maybe if there was a way to deploy our own personal password manager server on a dedicated server that would help the "one big target" issue.

Re: LastPass Security Notice

#19
post #12

While LastPass seems to be responding well, I find their entire service exceeds my tolerance for risk. If you don't use a password manager, you've got 99 problems, but a centralized store of your credentials for everything that's a huge target by virtue of having thousands of similarly centralized users ain't one. Using a password manager (good idea) and then storing all your passwords on a 3rd party service of which…

STRIP (https://www.zetetic.net/strip/) is a mature offline password manager that has been around since the late 1990s, available on iOS, Android, Windows and OSX. It uses the open-source encryption extension to SQLite, https://github.com/sqlcipher/sqlcipher, developed by the same company.

STRIP supports mobile-desktop synchronization over local wifi or remote cloud (Dropbox & Gdrive).

Re: LastPass Security Notice

#20

I don't use LastPass, but one thing that impresses me about their blog post: they didn't hide behind "your passwords are hashed" or something equally weaselly, but instead said exactly and clearly how passwords are hashed. Every online company should take note.

I would however appreciate more detail on the breach. This would at least give an indication of their general security posture.

I'm reading this as an embarrassing security lapse in general security, so they misdirect by talking in depth about password hashing.

Post reply on HN