Live data from Hacker News

LastPass users warned their master passwords are compromised

bleepingcomputer.com

11–20 of 326 posts

Re: LastPass users warned their master passwords are compromised

#11
post #3

Let this be your Last non-selfhosted Pass solution.

Securing a server is hard for the average user. But in any case LastPass uses E2EE so if the password was compromised that's most likely on client side, and for this self-hosted or not would make no difference.

Re: LastPass users warned their master passwords are compromised

#12
post #3

Let this be your Last non-selfhosted Pass solution.

Self hosting sucks for an average user, and terrible for a mobile user. It is possible to have hosted password solution that is secure, so why not use it? This is basically the same "cloud" vs "on-prem" debate. Cloud won, I think.

I use KeePassDX on Android and KeePassXC on a laptop, and they are synced with Syncthing. I have no issues with this setup

Re: LastPass users warned their master passwords are compromised

#13
post #3

Let this be your Last non-selfhosted Pass solution.

Self hosting sucks for an average user, and terrible for a mobile user. It is possible to have hosted password solution that is secure, so why not use it? This is basically the same "cloud" vs "on-prem" debate. Cloud won, I think.

My setup: - Windows Desktop - Macbook Air

I installed Keepass on my windows desktop along with iCloud drive sync. I keep my Keepass database in my iCloud directory. I can now use this Keepass database on my iPhone (via Files app), on my Macbook (iCloud Drive). Any changes made are automatically synced daily.

Is that really too difficult? And yes, it does "just work".

Bonus: Any passwords stored in my iCloud Keychain are also synced to my Windows Chrome instance via Apple's 'iCloud Passwords'[1] plugin.

[1] https://chrome.google.com/webstore/detail/icloud-passwords/p...

Re: LastPass users warned their master passwords are compromised

#14

LastPass's statement via HowToGeek: https://www.howtogeek.com/776450/lastpass-says-it-didnt-leak...

So original article is down, but this sounds like people who used the same password as their master and in some _other_ service that has been leaked. ie a user who's lastpass master pass is same as their facebook. Very different from having LastPass leak master pass. Is this the same issue or a case of LastPass not getting the situation?

Re: LastPass users warned their master passwords are compromised

#16
post #3

Let this be your Last non-selfhosted Pass solution.

Self hosting sucks for an average user, and terrible for a mobile user. It is possible to have hosted password solution that is secure, so why not use it? This is basically the same "cloud" vs "on-prem" debate. Cloud won, I think.

The fact that 1Pass is dropping local hosting means I’ll be dropping 1Pass.

Re: LastPass users warned their master passwords are compromised

#17
Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.

Re: LastPass users warned their master passwords are compromised

#18

Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.

Ah yes, the $5 wrench method.

Re: LastPass users warned their master passwords are compromised

#19

Earlier quoted context omitted.

Self hosting sucks for an average user, and terrible for a mobile user. It is possible to have hosted password solution that is secure, so why not use it? This is basically the same "cloud" vs "on-prem" debate. Cloud won, I think.

My setup: - Windows Desktop - Macbook Air I installed Keepass on my windows desktop along with iCloud drive sync. I keep my Keepass database in my iCloud directory. I can now use this Keepass database on my iPhone (via Files app), on my Macbook (iCloud Drive). Any changes made are automatically synced daily. Is that really too difficult? And yes, it does "just work". Bonus: Any passwords stored in my iCloud Keychain…

For what it's worth, my attempt at using Keepass drove me away because the password database kept becoming conflicted, necessitating a merge. Keepass' options for dealing with conflicts were to "accept mine" or "accept theirs", but I'd often end up in situations where the conflict went sideways and I lost my login completely.

In the end I was running the conflict resolution command once every couple days.

Normally I wouldn't mind, but the only time the warning comes up saying that my db file is conflicted is when I need to enter a password in... which is the last time I want to be dealing with this.

This was Keepass with the db file on Dropbox, by the way. Not sure how Syncthing would handle it differently, but it wouldn't have anything to do with merging db files if they go out of sync.

Re: LastPass users warned their master passwords are compromised

#20

Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.

What if you’re in another country and your devices get stolen? Should you bring the Yubikey to travel? What happens if there’s a fire at your house and the Yubikey is destroyed?
Post reply on HN