This approach seems better to me. For one thing, I'd already be screwed if someone malicious got into my Google account, probably worse than if they got into my password manager. And additionally, this means they're not creating an absolute jackpot of data to breach in a centralized place. No one's gonna hack Enpass of all their passwords because that would require hacking all of Google Drive, Dropbox, iCloud, etc. and looking for the files manually.
LastPass notifies users of yet another data breach
111–120 of 246 posts
Re: LastPass notifies users of yet another data breach
#112Earlier quoted context omitted.
> I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already. This has nothing to do with the security of your passwords stored in LP. They have some CRM, some person from their 800 employees clicked a sketchy link and it leaked that. It's not good, but its hardly an indictment of their product or usefulness Would you be okay will a public dat…
Of course it's not okay. But this is pissing in the ocean. This is throwing buckets of water on the Titanic. The damage is already done. Your private information was already leaked long ago. You can't make a sunk boat more wet.
Re: LastPass notifies users of yet another data breach
#113I've been an Enpass user for years because I got a lifetime purchase for a good deal. They don't host the cloud services for syncing passwords. Instead you just auth your cloud storage (I use Google Drive) and it syncs to that. This approach seems better to me. For one thing, I'd already be screwed if someone malicious got into my Google account, probably worse than if they got into my password manager. And additiona…
Re: LastPass notifies users of yet another data breach
#114I'm so glad we migrated away from LastPass (to BitWarden). It was a breach that caused us to move in the first instance.
Re: LastPass notifies users of yet another data breach
#115Earlier quoted context omitted.
One of the security advantages of KeePass being just a file is that you can sync it in the way that makes sense to you. The need to have an opinion on how you’d like to sync a file does, as you suggest, eliminate some portion of the population who need a fully baked answer in one step. I used to use Google Drive, but now I use Syncthing, further reducing my exposure. Paired with Synctrain and KeePassium on iOS. One t…
What would happen if the file was edited concurrently? Would any data be lost?
Re: LastPass notifies users of yet another data breach
#116Earlier quoted context omitted.
Yes, in a separate breach.
>The vaults were accessed years ago > Yes, in a separate breech. Not nearly that cut and dry. Many, not all encrypted vaults leaked out. If you lost data it was because you used a weak master password for that vault.
> If you lost data it was because you used a weak master password for that vault.
Even this is more complex (horrible pbkdf2 defaults, you're welcome for getting lastpass to increase them btw that was me) but it isn't relevant, no vaults are accessed in this breach.
Re: LastPass notifies users of yet another data breach
#117Earlier quoted context omitted.
A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.
I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…
What you are describing is a password manager. No one here is questioning why people would use a password manager. That's like asking why people would use a toothbrush. The question is why anyone would use LastPass as their password manager.
> Also, let's be real:
> > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.
> I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already.
I'm sorry to put it so bluntly, but this comment strikes me as really baffling.
LastPass has a very long history of breaches, some of them very severe with a big fallout. It's at the point where the yearly LastPass breach has become a meme just like the yearly T-Mobile breach. It makes no sense whatsoever to look at this incidence without that context and to claim "it's not that bad, they only leaked xyz".
On another note, of course does a breach tell something about the security practices of a password manager company. You really want the developer of your password manager to have good security practices and any sign to the contrary is concerning even when it is not directly related to the core product. Of course security is not about absolutes and mistakes and incidents do happen – what counts is how, how is dealt with them and if they repeat. In the case of LastPass history, including this breach, shows that they have atrocious security and you do not want to let your credentials get any millimeter closer to them than you can possibly avoid.
> I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already.
Again, I'm sorry for being so direct, but this argument annoys me greatly: This argument – that others have done similar bad already and similar harm has already been done – is beyond stupid and needs to die. It's why slippery slopes are real. It's the reason why normalization of bad things happen. It's what people with bad intentions continuously use with great success to slowly make their bad deeds socially acceptable.
When my neighbor dumps his trash on the street that does not allow me to do the same and does not make it any better if I do. I will be just as much in the wrong as him. The only difference being – when I use that excuse – that I will also be a coward.
The wrongdoing of others is never an apology to do the same; and just because something bad is normal does not make it any better and it is especially not an argument for making it even worse.
Re: LastPass notifies users of yet another data breach
#118Earlier quoted context omitted.
Liability is the answer! If you build an auth system and it fails, it's your backside. If Okta fails, it's theirs. Enterprises buy products as much as they buy protection from problems.
They don't offer any meaningful reimbursement if they lose your data so what does that matter ?
e.g. when Crowdstrike takes down Windows across the worlds or AWS east coast falls over everybody hurts. At that point the story is easy, you point at the broken thing, mumble something about improving resilience, and everyone just moves on.
Roll your own system and have it taken down / breached specifically? There's noone to point at. It's hard to make the narrative anything except it being your fault.
Re: LastPass notifies users of yet another data breach
#119Earlier quoted context omitted.
Liability is the answer! If you build an auth system and it fails, it's your backside. If Okta fails, it's theirs. Enterprises buy products as much as they buy protection from problems.
They don't offer any meaningful reimbursement if they lose your data so what does that matter ?
Re: LastPass notifies users of yet another data breach
#120Earlier quoted context omitted.
Compare https://hn.algolia.com/?q=lastpass to basically any other password manager, like https://hn.algolia.com/?q=1password or https://hn.algolia.com/?q=bitwarden Those companies do not have the same number and severity of security incidents. lastpass is truly in a category of its own
i'd love to switch from my lastpass family plan to... something else. but there is a non-trivial switching cost to migrate several people (with varying technical aptitudes) that each use several platforms. if 1password had a one-click migration flow they'd be able to win over a lot of converts.