Live data from Hacker News

I Lost All Faith in LastPass

infosec.exchange

1–10 of 322 posts

Re: I Lost All Faith in LastPass

#2
Well, that sounds bad. I mean, I'm not an infosec expert, but I can follow enough of that to see that it's not good. I use Lastpass at work, because we have a site license, but maybe I'll look into whether I can switch over to bitwarden. I don't expect perfect security, but I expect them to at least try.

Re: I Lost All Faith in LastPass

#4
post #3

Has LastPass always been this bad and nobody noticed or did the new owners change it?

I think the answers is yes, there has been grumbling about LastPass for years. Prior to them being owned by LogMeIn.

They were hacked back in 2015 too: https://www.wired.com/2015/06/hack-brief-password-manager-la...

> On Monday password manager service LastPass admitted it had been the target of a hack that accessed its users' email addresses, encrypted master passwords, and the reminder words and phrases that the service asks users to create for those master passwords.

(That's from 2015 but could read like the other week!)

Re: I Lost All Faith in LastPass

#5
post #3

Has LastPass always been this bad and nobody noticed or did the new owners change it?

Yes. But prior to this breach it was easy to look the other way due to the extremely large amount of inertia associated with changing a manager and all your passwords. I know this was the case for me. In August we thought it was simply another "simple" breach. E.g. they got hold of some information that would be useful to spearphish or whatever but not the vaults themselves. No big deal, just be on the lookout for emails.

Once it came to light they lost control of their vaults the calculus changed. In my memory this is the largest, most prolific breach in history. Every other breach of a major site pales in comparison. The only solution is to change password managers immediately (I went to 1password) and begin the process of changing everything and updating your security posture. Unfortunately, the hackers also have an insane amount of metadata on customers. So if you stored incriminating (either legally or socially) websites in there the hackers now have a lot of leverage to get you to bend the knee.

In summary, lastpass has been on the down slope for a long time. But it was easy to just accept this and work around it. This breach changed everything. It revealed their incompetence in full and woke a lot of people, including myself, up to just how hard it is to trust a company. It's just not enough anymore to have a big company slapped onto your logo (LogMeIn) and hope they provide the correct mitigations through experience. From now on I, and many people I know, will be carefully evaluating their choices with password managers, etc from now on. I don't think their CEO can be trusted especially with all the weasel words used in the disclosure and the timing of the disclosure. They showed no respect for their customers in either the aspect of security or disclosure. If you know nothing else about this breach that should be enough to get you and everyone you know to run.

Re: I Lost All Faith in LastPass

#7
The post looks a bit weird on first sight: "I always knew LastPass has a ton of flaws, but promoted it anyway".

This may make sense though. LastPass seemed to be the only one with a good enough UX. And without a good enough UX, you can't make users actually use it. Using an imperfect but usable password manager is still much better than not using one with better security but poor UX.

(Here comes the old adage: make the friction low for the customer, and any shortcomings elsewhere will matter little.)

Re: I Lost All Faith in LastPass

#8
post #3

Has LastPass always been this bad and nobody noticed or did the new owners change it?

Plenty of folks knew LP was always bad. I've been using 1Password for years, not just because it's so good (it is) but also because LastPass, which I previously used, was horrendous. Even canceling my family account with them was a nightmare.

Re: I Lost All Faith in LastPass

#9
God damnit, but what doesn't. I am sure BitWarden has its own problems and it (seems?) not 100% FOSS but its core is.

LP extension and web vault ARE pure garbage:

1. It can't even recognize sites correctly ?! WTF really. I usually get 10 or so (looks like random) hits for any site but not the one that I should.

2. It offers me to extend pro support 5 years after I stopped paying for it. What I need to do for it to stop ffs.

3. Its UI is simply outrageous, i.e. if you search something it shows empty folders among those that contain the item etc.

I recommend NextCloud Passwords plugin: https://apps.nextcloud.com/apps/passwords

Its awesome, supports team work, and if you have NC its no brainer. Probably too much work to install NC if you don't use it but in small company settings its probalby good idea as you need online office anyway.

Re: I Lost All Faith in LastPass

#10
How do we know 1Password doesn't have similar glaring oversights like LP?

We can't audit their code unless it is open source? I'm not going to just believe them at face value because some random internet personality says so. Unless some respected authority can publish an audit of the security posture and source code, we're just taking them at their word.

Granted, if I had to chose today, I would instantly pick 1Password based on what I can find on google, and LP has far, far more leaks than 1P.

But let's not kid ourselves that 1P is somehow more trustworthy without audits. And I'll eat crow if 1P has proof that they are routinely audited by 3rd parties.

EDIT: removed snark.

EDIT#2: If Signal can publish open source, why cant 1Password? If security is done right, the source code should be visible to everyone without jeopardy, or at least that's what I've been led to believe.

EDIT#3: Thanks for the link y'all, here it is at top level: https://1passwordstatic.com/files/security/1password-white-p... ... mmmm crow

EDIT#4: We trust browsers too much. 1P stores the secret key on every device so that you only have to enter your passphrase. I'd really like that code to be public because that's a great way to lose control of everyone's secret key. Extensions worry me because they are a critical component in any password manager's usability-vs-security. But perhaps that is a digression or worth an Ask HN.

Post reply on HN