Live data from Hacker News

LastPass Security Notice

blog.lastpass.com

111–120 of 311 posts

Re: LastPass Security Notice

#111
post #106

See quite a few nods to 1Password in here, which is good, although I tend to favor KeePass myself, given that it's FOSS. It also has a way better Firefox add-on than any of the others I've seen (which is my main browser), and the Android apps, if unofficial, aren't bad either [0]. Importantly, they feature the ability to either pull from a local Keepass DB or to get it from a connected Google Drive account. I've take…

So you're trusting Google?

The KeePass database itself is encrypted with a Master Password/Password Phrase. You can take a look at the encryption they use for it here:

http://keepass.info/help/base/security.html#secencrypt

Hence, I am reasonably confident that even if Google were to turn over my Drive account to the NSA, they wouldn't be able to crack open the database.

See also: discussion on feasibility of brute forcing a KeePass database:

https://security.stackexchange.com/questions/8476/how-diffic...

Re: LastPass Security Notice

#112
post #106

See quite a few nods to 1Password in here, which is good, although I tend to favor KeePass myself, given that it's FOSS. It also has a way better Firefox add-on than any of the others I've seen (which is my main browser), and the Android apps, if unofficial, aren't bad either [0]. Importantly, they feature the ability to either pull from a local Keepass DB or to get it from a connected Google Drive account. I've take…

So you're trusting Google?

The point of using a locally-encrypted password database like KeePass is that you don't have to trust Google (or DropBox, or Microsoft). You trust the encryption instead.

Re: LastPass Security Notice

#113
Things like this are why I prefer Firefox Sync. Works across all my devices (home laptop, work laptop, Android phone), and uses client-side encryption, so a compromise of the Sync server provides the attacker with nothing of value.

Re: LastPass Security Notice

#114
post #92
post #16

Earlier quoted context omitted.

Switched from LastPass to 1Password two weeks ago. 1Password has a much cleaner and intuitive UI.

How hard was it to make the switch? I'm considering doing a switch soon if it's not too painful.

Manual, so the number of accounts will determine your pain. That said, 1Password has an OSX client + Chrome extension. Day to day is much easier to use.

Re: LastPass Security Notice

#115
post #30

Earlier quoted context omitted.

But this depends on the alternative. If, instead of using a password manager, uses only one (or even two or three) passwords across all the websites they frequent, then you are still, in effect, trusting numerous third parties to keep your password safe in the cloud--if any one of these sites is compromised, then your password for all (or half, or 1/3rd, etc.) is compromised along with it. I agree with you that an of…

> Maybe there are people out there who will accept much more inconvenience in exchange for avoiding the risk associated with a cloud-based service. But, for me, the inconvenience is simply too much. Sure, it's a balance everyone has to find for themselves. As you note earlier, a cloud password manager is better than shared passwords. I'm certainly happy to accept a bit more inconvenience than most. I only do banking…

A solution I have found that (I think) is relatively secure. Setup a keepass database that requires the use of an unlock password and key file. Sync the database to Google Drive but never sync the key file! Only store the keyfile on a locally ecrypted thumb drive or only stored locally on the devices (preferably encrypted) that you need to access keepass from.

In random time/day intervals reset your key file and keepass password.

The key to this method "working" which should be "secure" barring total ownage by a state actor or well funded individual is to never sync the key file and database to the same service. Additionally, sync up a "false flag" key file if you want some additional level of obscurity.

tl;dr:

1) Setup Keepass database to require password and key file to unlock.

2) Sync database to cloud service but never the key file.

3) In random time intervals (t=60+days) Randomly change both the password and generate a new key file for your database.

4) Keep your key file on an encrypted drive or on the device (preferably encrypted) that needs access to Keepass.

Re: LastPass Security Notice

#116
post #43

Earlier quoted context omitted.

Actually that's how LastPass works (they move around an AES-256 encrypted database, and decrypt it on the client/browser). The problem LastPass has, is that they re-use the same master password for two distinct things: - Authenticating to login to your account. - Encrypt your password database. So in situations like this the loss of the authentication hash is relevant. I'd prefer to have a different password for the…

I find this design kind of baffling. Why go through the trouble of storing data encrypted only to snatch defeat from the jaws of victory by demanding that the client provide a secret derived from the encryption key just to log in?

I finally managed to convince my mother to start using LastPass recently; if I'd had to convince her to use two "master" passwords-- one for the encryption key, one for the service-- I'm fairly sure she'd still be using Google Contacts to store her secrets. :-\

Re: LastPass Security Notice

#117
post #52
post #25

One another incident that reminds me, why 2 factor authentication is absolutely necessary for important information.

If the authentication database is being breached, presumably the 2FA shared secret is going to be in the same database. Constructing the 2FA code would be trivial. After all, the server needs a way to check that a given 2FA code is correct for an authenticating user, so there has to be some way to generate those as well. It would help protect against any other sites that you use the same password on, with a different…

So it would be wise to change the LastPass master password and also regenerate the Google Authenticator key. LastPass does enable you to regenerate this key from the account settings page.

Re: LastPass Security Notice

#118
post #18

Earlier quoted context omitted.

I understand your take on the problem, but one of the features of those services is that they are precisely online: I can get my passwords on my phone, tablet, desktop, laptop, abroad or at work. If my password manager is offline, it's safer, but it's also a poorer experience. Maybe if there was a way to deploy our own personal password manager server on a dedicated server that would help the "one big target" issue.

But even that won't help much. If you are using "off the shelf" software, then that means i have something to scan for, and a vulnerability in the software means that i have tons of targets. Most of which won't be as secure as LastPass servers might be, and probably won't update immediately.

Only if the software itself has a vulnerability - and it isn't that hard to secure a website or server that can't be accessed at all without a password, as opposed to one that needs to provide some level of service to anyone. Centralized services are also at risk of generic attacks such as convincing the hosting service/domain registrar/a company employee/etc. that you're authorized to change things, while pulling this off for many independently hosted site instances is considerably more difficult.

Re: LastPass Security Notice

#119

Earlier quoted context omitted.

I have a sftp account on my server for my keepass data, I can sync it from anywhere and I don't have to worry about google drive having access to my (encrypted) data. I like it.

Which extension do you use for that?

He might be using the IOProtocol Extension: http://keepass.info/plugins.html#ioprotocolext

Re: LastPass Security Notice

#120
post #12

While LastPass seems to be responding well, I find their entire service exceeds my tolerance for risk. If you don't use a password manager, you've got 99 problems, but a centralized store of your credentials for everything that's a huge target by virtue of having thousands of similarly centralized users ain't one. Using a password manager (good idea) and then storing all your passwords on a 3rd party service of which…

Not sure I'm with you on the "responding well" part. Why blog about it before even notifying your customers? And Joe's whole post seems fairly low-key given that this was a security breach and security is their entire business.
Post reply on HN