Live data from Hacker News

LastPass Security Notice

blog.lastpass.com

161–170 of 311 posts

Re: LastPass Security Notice

#162

Earlier quoted context omitted.

Switched to LastPass from 1Password a year or so ago because of linux support. Haven't minded. I like 1Password more (just because of the prettier UI), but LastPass is good enough.

Does 1password work on android and ios now?

Yes, 1password have official android and ios apps that are working quite well. It's possible to enter passwords without placing them in the phones paste buffer.

Re: LastPass Security Notice

#163

If you are using LastPass without 2FA (YubiKey, etc), people attacking LastPass itself is really the least of your problems. I'd be much more concerned about keyloggers grabbing your password. BeEF can pop up a LastPass phishing prompt if you just happen to load the wrong javascript file. Using just one string of characters to protect ALL of your passwords is insane.

If you got a keyloggers on your machine, you are already fucked, and 2FA won't help you. The keyloggers can simply steal your passwords straight from the browser when LastPass fills them in.

Re: LastPass Security Notice

#164
post #18
post #12

While LastPass seems to be responding well, I find their entire service exceeds my tolerance for risk. If you don't use a password manager, you've got 99 problems, but a centralized store of your credentials for everything that's a huge target by virtue of having thousands of similarly centralized users ain't one. Using a password manager (good idea) and then storing all your passwords on a 3rd party service of which…

I understand your take on the problem, but one of the features of those services is that they are precisely online: I can get my passwords on my phone, tablet, desktop, laptop, abroad or at work. If my password manager is offline, it's safer, but it's also a poorer experience. Maybe if there was a way to deploy our own personal password manager server on a dedicated server that would help the "one big target" issue.

I think if lastpass just allowed use of an out-of-channel external file as an additional encryption layer (as keepass can) then you should be able to worry about keeping that external file secure rather than worry about what's in the cloud.

Re: LastPass Security Notice

#165

Slightly off-topic: am I naive to believe that my personal system of password management is just about as good something like 1Password or LastPass? Hear me out. My passwords are generated as follows: [Low|Med|Hi] + [Key] + [Initials] + [Number] Low|Med|High = One of three keys based on how sensitive the site is. High: banking / work / email, Low: I don't trust the site, Med: other. Key = Random string that only I kn…

Another issue is that you cannot track changes in password for a specific site. Many sites do not allow the previous X number of passwords.

Re: LastPass Security Notice

#166
post #12

While LastPass seems to be responding well, I find their entire service exceeds my tolerance for risk. If you don't use a password manager, you've got 99 problems, but a centralized store of your credentials for everything that's a huge target by virtue of having thousands of similarly centralized users ain't one. Using a password manager (good idea) and then storing all your passwords on a 3rd party service of which…

But this depends on the alternative. If, instead of using a password manager, uses only one (or even two or three) passwords across all the websites they frequent, then you are still, in effect, trusting numerous third parties to keep your password safe in the cloud--if any one of these sites is compromised, then your password for all (or half, or 1/3rd, etc.) is compromised along with it. I agree with you that an of…

My compromise has been to come up with a password permutation scheme-- I have a long, secure, high-entropy password which I can modify/salt in a way that's predictable (to me) across sites, such that each site's credentials are unique. Obviously this works across all devices, because the scheme is in my head, and it's simple enough to remember. I don't use any password manager, because like OP, that seems like too much of an eggs-and-baskets risk for my taste.

A catastrophic compromise would require an attacker to see actual credentials (not just the hashes) across many sites, and on top of that reverse engineer my specific permutation scheme. This seems much less likely to me than a very public, high-profile centralized cloud service forgetting to cross a T somewhere and getting hacked.

Re: LastPass Security Notice

#167
post #143

If you are using LastPass without 2FA (YubiKey, etc), people attacking LastPass itself is really the least of your problems. I'd be much more concerned about keyloggers grabbing your password. BeEF can pop up a LastPass phishing prompt if you just happen to load the wrong javascript file. Using just one string of characters to protect ALL of your passwords is insane.

> If you are using LastPass without 2FA There is no 2FA with LastPass. Don't believe me? Set up a LastPass account and turn on 2FA. Go log in on an untrusted browser. Enter your password. At the 2FA prompt screen, there is a giant red "If you lost your Google Authenticator device, click here to disable Google Authenticator authentication" link. That's right. They give the attacker the option to disable 2FA for your a…

They send you an email and only with the link in the email can you login. Email is the second factor here.

Re: LastPass Security Notice

#168

Earlier quoted context omitted.

I don't understand why 1Password's approach to the cloud - syncing via Dropbox or Google Drive - is considered that much more secure than LastPass. If anything relying on Dropbox has always seemed to me to be a huge liability

It's a matter of target payoff. Dropbox, Drive, etc. are not specific to just storing password DBs. If my account is compromised, the attacker has one DB for their effort. If a cloud storage is compromised, the attacker has to scan through everything looking for DB files. LastPass cloud storage is meant only for storing password DBs, so an attacker knows that within a single target lies a large trove a specific type…

I don't understand this. So LastPass could increase their security by including a bunch of pictures of puppies in their folder for me? Why not do it then?

Re: LastPass Security Notice

#169
post #30

Earlier quoted context omitted.

> Maybe there are people out there who will accept much more inconvenience in exchange for avoiding the risk associated with a cloud-based service. But, for me, the inconvenience is simply too much. Sure, it's a balance everyone has to find for themselves. As you note earlier, a cloud password manager is better than shared passwords. I'm certainly happy to accept a bit more inconvenience than most. I only do banking…

> For web services (like HN) I simply don't need to log in and comment that badly if I'm on an unusual device. You also don't need to use one solution for every use-case. I use an online password manager (LastPass + 2FA) for relatively high-use, low-value credentials (things like web forums and online shopping sites). For higher-value credentials (investment accounts, banking, email), I use an offline password manage…

Seconding multiple solutions. I use LastPass to deal with the volume of credentials required, storing most but not all sites. I memorize the most important sites (bank, primary e-mail), never putting them in a password manager.
Post reply on HN