Password reset page is down: "Oops! Our servers are a bit overloaded right now. Please try your password change again shortly, we will catch up soon."
LastPass Security Notice
101–110 of 311 posts
Re: LastPass Security Notice
#102Any good tricks on how to generate a new master password that is a) secure enough and b) I can memorize?
Re: LastPass Security Notice
#103Earlier quoted context omitted.
> (Though if you've found a good option, that will allow me to easily sync across my home desktop, laptop, office pc, tablet, and smartphone, without using the cloud, I would absolutely love to hear about it! Maybe something Bluetooth based?) I don't know if it meets but your needs, but I love PasswordMaker ( http://passwordmaker.org ). There is no need for sync'ing, because the password is generated from a master pa…
I tried to use something similar a long time ago (SuperGenPass). The problem I had with it was that often times the password would not meet the password requirements of the site. Sometimes it's too long, sometimes there weren't enough numbers or symbols. I couldn't use it if I'd have to remember that it didn't work for particular sites (after all, the whole point is not having to remember information for each site).…
Re: LastPass Security Notice
#104Does LastPass keep the encrypted copy of the password file for non-premium accounts? For accounts that don't sync and just use it from a single browser?
Re: LastPass Security Notice
#105If you are using LastPass without 2FA (YubiKey, etc), people attacking LastPass itself is really the least of your problems. I'd be much more concerned about keyloggers grabbing your password. BeEF can pop up a LastPass phishing prompt if you just happen to load the wrong javascript file. Using just one string of characters to protect ALL of your passwords is insane.
Though even with 2FA, couldn't a sophisticated keylogger grab your password database after you've authenticated and downloaded it?
Re: LastPass Security Notice
#106See quite a few nods to 1Password in here, which is good, although I tend to favor KeePass myself, given that it's FOSS. It also has a way better Firefox add-on than any of the others I've seen (which is my main browser), and the Android apps, if unofficial, aren't bad either [0]. Importantly, they feature the ability to either pull from a local Keepass DB or to get it from a connected Google Drive account. I've take…
Re: LastPass Security Notice
#107Earlier quoted context omitted.
Why is 1Password over Dropbox the "worst of both worlds"? Seems like it's potentially safer, because it's encrypted with your passphrase and also your dropbox credentials. Sure, the NSA can probably get it, but J Random Hacker can't.
I'm not even convinced the NSA can get it. There are no side-channels to exploit here (which we know the NSA is good at) and cooperation from online services won't work either. The protocols used to encrypt this are fairly simple and well-understood and we should not assume that the NSA is capable of breaking the underlying (strong) primitives.
Whether or not they can break the Keepass encryption after getting your data is debatable but strikes me as "probably yes."
Re: LastPass Security Notice
#108I just deleted, regenerated, and re-associated Google Authenticator and then altered the number of iterations from 10,000 to 10,001 (causing it to re-encrypt the database). None of this is really required but it has invalidated much of the information they could have stolen. The thing that really bugs me about this, is the email address. I have a very low spam level on that account (sub-1 per day on average) and I wa…
How will that invalidate the info they have?
By disabling / deleting your OTP token and re-adding it, you are essentially re-generating this seed.
I am not sure I understood the comment "altered the number of iterations from 10,000 to 10,001 (causing it to re-encrypt the database)", care to elaborate @Someone1234?
Re: LastPass Security Notice
#109Earlier quoted context omitted.
> Maybe there are people out there who will accept much more inconvenience in exchange for avoiding the risk associated with a cloud-based service. But, for me, the inconvenience is simply too much. Sure, it's a balance everyone has to find for themselves. As you note earlier, a cloud password manager is better than shared passwords. I'm certainly happy to accept a bit more inconvenience than most. I only do banking…
> I simply don't want a single place where all my passwords are available that isn't hardware physically under my control. That makes sense. What would be really nice -- and what I had in mind -- would be some sort of device where the passwords were stored to which my other devices could easily connect to to access the passwords, sort of like a wireless dongle. (Though, really, even the wireless part is negotiable. I…
Re: LastPass Security Notice
#110Earlier quoted context omitted.
I just write down my passwords. Well not exactly. A few key ones I have memorized, and a few throw away ones I rotate between for when a site requires an account and I'll never be back. But my rare use passwords for important things are physically recorded in a locked notebook. Anyone who could get access to that could've just installed a keylogger into my computer. My problem with a password manager in general is th…
> I just write down my passwords. People may laugh, but for many people that's a huge step up. I've tried explaining password managers to family members, and I've failed. The usability just isn't there for many classes of user, and as noted elsewhere in this thread losing access to that database is catastrophic. Getting them to use unique passwords per-site, even if those passwords are written down and stored in thei…