Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

11–20 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#11
post #3

It is difficult for me to believe that this could be true unless their web application has also been hacked. And if that were the case then this is really getting into criminal negligence territory (especially the way they've been disclosing it).

When I read their most recent email updating about the situation today or yesterday, I did get a definite chill down my spine. I've not used LP for a year or so, but my data (much of it now old) is still stored there, mainly left as a backup as I'd heard some people had some weird issues migrating to other password managers. I had made a mental note some months back when this first happened I should really go through…

I'm not too worried because anything important that I have in LP is protected by 2fa. It's notable that the author says his accounts are protected by 2fa, but I don't understand how LP being hacked would allow an attacker to defeat that.

Re: The situation at LastPass may be worse than they are letting on

#14

Is there any reason to use these cloud based solutions when open source alternatives like KeepassXC is available?

Yeah: they’re cloud based. Your passwords get synced to all your devices automatically. That’s kinda the entire draw.

Exactly. I used Keepass for years but it became too much of a pain.

(Though I suppose changing a bunch of passwords that I had in LastPass is also kind of a pain.)

Re: The situation at LastPass may be worse than they are letting on

#16
post #11

Earlier quoted context omitted.

When I read their most recent email updating about the situation today or yesterday, I did get a definite chill down my spine. I've not used LP for a year or so, but my data (much of it now old) is still stored there, mainly left as a backup as I'd heard some people had some weird issues migrating to other password managers. I had made a mental note some months back when this first happened I should really go through…

I'm not too worried because anything important that I have in LP is protected by 2fa. It's notable that the author says his accounts are protected by 2fa, but I don't understand how LP being hacked would allow an attacker to defeat that.

he said his seed phrases were in lastpass. There is no 2fa protection for private keys if the assets are in his crypto wallet and he's custodying them.

Re: The situation at LastPass may be worse than they are letting on

#17

Is there any reason to use these cloud based solutions when open source alternatives like KeepassXC is available?

Same problem with many other open source alternatives. Lousy user experience, in this case across devices.

Re: The situation at LastPass may be worse than they are letting on

#18
Reminder that in 2015 LastPass was acquired by LogMeIn, who then in 2021 announced it was spinning off back into its own thing, though whether that has happened yet is unclear.

If you look into what LogMeIn (now renamed to “GoTo”) makes… this doesn’t make me feel good about GoToMeetings, GoToMyPC, or join.me.

Re: The situation at LastPass may be worse than they are letting on

#19
post #11

Earlier quoted context omitted.

When I read their most recent email updating about the situation today or yesterday, I did get a definite chill down my spine. I've not used LP for a year or so, but my data (much of it now old) is still stored there, mainly left as a backup as I'd heard some people had some weird issues migrating to other password managers. I had made a mental note some months back when this first happened I should really go through…

I'm not too worried because anything important that I have in LP is protected by 2fa. It's notable that the author says his accounts are protected by 2fa, but I don't understand how LP being hacked would allow an attacker to defeat that.

Just for your consideration, I'd bet good money that the 2FA only protects against login credential stuffing, but the vault data is only protected by your master password and can be attacked offline and indefinitely

Re: The situation at LastPass may be worse than they are letting on

#20
post #16
post #11

Earlier quoted context omitted.

I'm not too worried because anything important that I have in LP is protected by 2fa. It's notable that the author says his accounts are protected by 2fa, but I don't understand how LP being hacked would allow an attacker to defeat that.

he said his seed phrases were in lastpass. There is no 2fa protection for private keys if the assets are in his crypto wallet and he's custodying them.

Right, should've remembered reading that. Am I the only one who thinks that's a crazy thing to put in LP?
Post reply on HN