Live data from Hacker News

Lastpass setting the delete account div to display: none

infosec.exchange

11–20 of 210 posts

Re: Lastpass setting the delete account div to display: none

#12

I work at a large company and against the opinion of many engineers and infosec folks, lastpass was picked as our preferred corporate password storage. I'm just waiting for a call from infosec asking me to log on and to rotate a bunch of creds. Happy Holidays.

At my previous employer I remember saying don't do it with LastPass as the credentials will get stolen. The so-called tech lead said, "I hear what you're saying but it's been decided." I wonder what he is thinking now when he hears about this. Probably nothing.

Re: Lastpass setting the delete account div to display: none

#13

I work at a large company and against the opinion of many engineers and infosec folks, lastpass was picked as our preferred corporate password storage. I'm just waiting for a call from infosec asking me to log on and to rotate a bunch of creds. Happy Holidays.

Our new parent company -- that works in a security-sensitive industry -- rolled out LastPass over the last few months. I sent a warning letter to the CISO listing the previous hacks and vulnerabilities in LastPass. Then this new hack happened, and the CISO sent out a letter saying that there is nothing to be concerned about and that all is well. When the news broke that the breach was worse than predicted, I sent ano…

It's human nature to repeatedly double-down on any strongly stated opinion until its defence becomes untenable. It takes repeated intentional practice to keep your ego in check.

Re: Lastpass setting the delete account div to display: none

#14

I work at a large company and against the opinion of many engineers and infosec folks, lastpass was picked as our preferred corporate password storage. I'm just waiting for a call from infosec asking me to log on and to rotate a bunch of creds. Happy Holidays.

Our new parent company -- that works in a security-sensitive industry -- rolled out LastPass over the last few months. I sent a warning letter to the CISO listing the previous hacks and vulnerabilities in LastPass. Then this new hack happened, and the CISO sent out a letter saying that there is nothing to be concerned about and that all is well. When the news broke that the breach was worse than predicted, I sent ano…

You are reading too much into it. Probably ciso is busy with other things and cannot respond to every's smartass wishes.

Re: Lastpass setting the delete account div to display: none

#15

I work at a large company and against the opinion of many engineers and infosec folks, lastpass was picked as our preferred corporate password storage. I'm just waiting for a call from infosec asking me to log on and to rotate a bunch of creds. Happy Holidays.

Our new parent company -- that works in a security-sensitive industry -- rolled out LastPass over the last few months. I sent a warning letter to the CISO listing the previous hacks and vulnerabilities in LastPass. Then this new hack happened, and the CISO sent out a letter saying that there is nothing to be concerned about and that all is well. When the news broke that the breach was worse than predicted, I sent ano…

There is absolutely no reason to suspect kickbacks when there is already a massive incentive to not be seen as responsible for a massive blunder and waste of company resources.

The moment some exec pushes for some tech or process change, they become incentivized to ignore all problems and sell it as a success.

Re: Lastpass setting the delete account div to display: none

#17

Is LastPass one of those password managers that only encrypt passwords and leave other data as is? I always cringe when password managers do that. This is a funny joke for anyone who understands even a little about cryptography.

I see why it's a bad idea, but what does that have to do with cryptography?

Re: Lastpass setting the delete account div to display: none

#18
post #16

I spent last night resetting dozens of passwords and migrating everything into Keychain. Some observations: Keychain integration with 2fa codes is really nice. Passkeys are awesome and I wish more sites implemented this. So far I only saw Google and eBay?

> Passkeys are awesome and I wish more sites implemented this.

99% of the time, websites that allow you to use a "Security Key" or "Fingerprint" are using WebAuthn, which is all that's needed for PassKeys to work, (besides a few sites that use a stricter webauthn config).

Re: Lastpass setting the delete account div to display: none

#19

Is LastPass one of those password managers that only encrypt passwords and leave other data as is? I always cringe when password managers do that. This is a funny joke for anyone who understands even a little about cryptography.

I see why it's a bad idea, but what does that have to do with cryptography?

I don't understand enough to know why it's a bad idea but Cryptography is the practice and study of techniques for secure communication in the presence of adversarial behaviour, so this part seems clear to me.
Post reply on HN