Live data from Hacker News

LastPass Security Notice

blog.lastpass.com

101–110 of 311 posts

Re: LastPass Security Notice

#101
post #68

Password reset page is down: "Oops! Our servers are a bit overloaded right now. Please try your password change again shortly, we will catch up soon."

I am sure they are just overloaded with legitimate requests. But it that would be pretty interesting if the attackers first stole data from their servers and promptly followed this attack with a DDOS attack to their password reset endpoints!

Re: LastPass Security Notice

#103
post #66
post #57

Earlier quoted context omitted.

> (Though if you've found a good option, that will allow me to easily sync across my home desktop, laptop, office pc, tablet, and smartphone, without using the cloud, I would absolutely love to hear about it! Maybe something Bluetooth based?) I don't know if it meets but your needs, but I love PasswordMaker ( http://passwordmaker.org ). There is no need for sync'ing, because the password is generated from a master pa…

I tried to use something similar a long time ago (SuperGenPass). The problem I had with it was that often times the password would not meet the password requirements of the site. Sometimes it's too long, sometimes there weren't enough numbers or symbols. I couldn't use it if I'd have to remember that it didn't work for particular sites (after all, the whole point is not having to remember information for each site).…

I hate such site with a passion. Especially ones that say a 10 character password is too long.

Re: LastPass Security Notice

#104
post #90

Does LastPass keep the encrypted copy of the password file for non-premium accounts? For accounts that don't sync and just use it from a single browser?

All of the accounts sync even if you don't use mobile, if that's what you're saying. You can always log into their website and view your passwords.

Re: LastPass Security Notice

#105

If you are using LastPass without 2FA (YubiKey, etc), people attacking LastPass itself is really the least of your problems. I'd be much more concerned about keyloggers grabbing your password. BeEF can pop up a LastPass phishing prompt if you just happen to load the wrong javascript file. Using just one string of characters to protect ALL of your passwords is insane.

> If you are using LastPass without 2FA (YubiKey, etc), people attacking LastPass itself is really the least of your problems. I'd be much more concerned about keyloggers grabbing your password...

Though even with 2FA, couldn't a sophisticated keylogger grab your password database after you've authenticated and downloaded it?

Re: LastPass Security Notice

#106

See quite a few nods to 1Password in here, which is good, although I tend to favor KeePass myself, given that it's FOSS. It also has a way better Firefox add-on than any of the others I've seen (which is my main browser), and the Android apps, if unofficial, aren't bad either [0]. Importantly, they feature the ability to either pull from a local Keepass DB or to get it from a connected Google Drive account. I've take…

So you're trusting Google?

Re: LastPass Security Notice

#107
post #33
post #23

Earlier quoted context omitted.

Why is 1Password over Dropbox the "worst of both worlds"? Seems like it's potentially safer, because it's encrypted with your passphrase and also your dropbox credentials. Sure, the NSA can probably get it, but J Random Hacker can't.

I'm not even convinced the NSA can get it. There are no side-channels to exploit here (which we know the NSA is good at) and cooperation from online services won't work either. The protocols used to encrypt this are fairly simple and well-understood and we should not assume that the NSA is capable of breaking the underlying (strong) primitives.

The NSA will just get your data off Dropbox by having a judge ask them nicely. That much is undeniable.

Whether or not they can break the Keepass encryption after getting your data is debatable but strikes me as "probably yes."

Re: LastPass Security Notice

#108

I just deleted, regenerated, and re-associated Google Authenticator and then altered the number of iterations from 10,000 to 10,001 (causing it to re-encrypt the database). None of this is really required but it has invalidated much of the information they could have stolen. The thing that really bugs me about this, is the email address. I have a very low spam level on that account (sub-1 per day on average) and I wa…

How will that invalidate the info they have?

I presume he is under the assumption that the secret seed to the OTP algorithm was compromised.

By disabling / deleting your OTP token and re-adding it, you are essentially re-generating this seed.

I am not sure I understood the comment "altered the number of iterations from 10,000 to 10,001 (causing it to re-encrypt the database)", care to elaborate @Someone1234?

Re: LastPass Security Notice

#109
post #30

Earlier quoted context omitted.

> Maybe there are people out there who will accept much more inconvenience in exchange for avoiding the risk associated with a cloud-based service. But, for me, the inconvenience is simply too much. Sure, it's a balance everyone has to find for themselves. As you note earlier, a cloud password manager is better than shared passwords. I'm certainly happy to accept a bit more inconvenience than most. I only do banking…

> I simply don't want a single place where all my passwords are available that isn't hardware physically under my control. That makes sense. What would be really nice -- and what I had in mind -- would be some sort of device where the passwords were stored to which my other devices could easily connect to to access the passwords, sort of like a wireless dongle. (Though, really, even the wireless part is negotiable. I…

U2f (Universal 2nd Factor) is a standard to have a 2nd factor authentication usb device that uses a different secret for each website/resource. The only problem is that a version 2.0 is being discussed and you can't be sure that today's hardware will work with it.

Re: LastPass Security Notice

#110
post #95

Earlier quoted context omitted.

I just write down my passwords. Well not exactly. A few key ones I have memorized, and a few throw away ones I rotate between for when a site requires an account and I'll never be back. But my rare use passwords for important things are physically recorded in a locked notebook. Anyone who could get access to that could've just installed a keylogger into my computer. My problem with a password manager in general is th…

> I just write down my passwords. People may laugh, but for many people that's a huge step up. I've tried explaining password managers to family members, and I've failed. The usability just isn't there for many classes of user, and as noted elsewhere in this thread losing access to that database is catastrophic. Getting them to use unique passwords per-site, even if those passwords are written down and stored in thei…

I'm just not facing any meatspace targeting with my current businesses. Security is about considering reasonable defenses against potential threats. For me a virus on my computer is a far more likely threat.
Post reply on HN