Live data from Hacker News

LastPass users warned their master passwords are compromised

bleepingcomputer.com

121–130 of 326 posts

Re: LastPass users warned their master passwords are compromised

#121

Confession: I store all my passwords in a plaintext file on my local desktop. I'm sure some people will look at me very funny for doing this, but it seems to me that I have both fewer hassles logging in and fewer breaches than people using more "secure" methods (like handing your passwords over to LastPass's mystery Chrome extension). Think about today's threat landscape and tell me I'm wrong. I may not be more secur…

Confession: I write them down.

My threat model is 100% aimed at remote attacks/hackers. I could not care less about law enforcement. I also use a hardware backed second factor.

Re: LastPass users warned their master passwords are compromised

#122
post #115

To those who are recommending all different password managers, I have a question: why not using Chrome (or Firefox/Edge/ )'s built-in password manager? I have been using it for a couple years and haven't noticed any issue. Even if Google decides to screw me over and terminates my Google account, I can still access the passwords via the local copy in Chrome, so that is not really a concern. (Though, don't take this as…

> I have a question: why not using Chrome's built-in password manager

Because then you are locked into Chrome and some people prefer the freedom to switch browsers at any time

Re: LastPass users warned their master passwords are compromised

#123

Confession: I store all my passwords in a plaintext file on my local desktop. I'm sure some people will look at me very funny for doing this, but it seems to me that I have both fewer hassles logging in and fewer breaches than people using more "secure" methods (like handing your passwords over to LastPass's mystery Chrome extension). Think about today's threat landscape and tell me I'm wrong. I may not be more secur…

You could just use KeePass: https://keepass.info/ It's a free open source app that runs on your local machine and stores your passwords locally - never uploads your passwords to a server. But it does this securely. And you can run it on multiple machines (and phones) and transfer the passwords (the vault) without ever uploading anything to servers.

Keepass is great.

If you like to have synced database between devices with minimal risk of exposure I would recommend setting it up to use a master password AND generated key file. I do this, then sync my database to cloud/butt and just keep my key file offline and on device only.

Edit: I believe you can also use a FIDO/U2F key (yubikey, google titan, etc.) in place of a key file but 2 password lock is great even if someone guesses your master password, the database is still useless without the 2nd key.

Re: LastPass users warned their master passwords are compromised

#124
post #115

To those who are recommending all different password managers, I have a question: why not using Chrome (or Firefox/Edge/ )'s built-in password manager? I have been using it for a couple years and haven't noticed any issue. Even if Google decides to screw me over and terminates my Google account, I can still access the passwords via the local copy in Chrome, so that is not really a concern. (Though, don't take this as…

Because as far as I know you can't easily access your password outside of Chrome. For example, it's not practical to use on my iOS devices. If you want to log into an app, I believe you can't easily use passwords stored in Chrome.

Re: LastPass users warned their master passwords are compromised

#125

Confession: I store all my passwords in a plaintext file on my local desktop. I'm sure some people will look at me very funny for doing this, but it seems to me that I have both fewer hassles logging in and fewer breaches than people using more "secure" methods (like handing your passwords over to LastPass's mystery Chrome extension). Think about today's threat landscape and tell me I'm wrong. I may not be more secur…

You could just use KeePass: https://keepass.info/ It's a free open source app that runs on your local machine and stores your passwords locally - never uploads your passwords to a server. But it does this securely. And you can run it on multiple machines (and phones) and transfer the passwords (the vault) without ever uploading anything to servers.

Thanks for the tip! I will look into it. I am curious to find out how it syncs without servers. (I assume this is not an incredibly hard problem but we are just not used to doing things without "the cloud" these days)

Re: LastPass users warned their master passwords are compromised

#126
post #115

To those who are recommending all different password managers, I have a question: why not using Chrome (or Firefox/Edge/ )'s built-in password manager? I have been using it for a couple years and haven't noticed any issue. Even if Google decides to screw me over and terminates my Google account, I can still access the passwords via the local copy in Chrome, so that is not really a concern. (Though, don't take this as…

because i like to use firefox?

Re: LastPass users warned their master passwords are compromised

#127
post #42

Earlier quoted context omitted.

Just tried deleting my account--got exactly that error. That's not reassuring

Same here. It appears(?) that my account got deleted.

Confirmed. I deleted my account, received the error above. Then when attempting to login again, I was told my email was mistyped.

I stopped using LastPass a long time ago, but this has definitely put them on thin ice for me, I won't be recommending them going forward.

Re: LastPass users warned their master passwords are compromised

#128
Algorithmic passwords. Come up with an algorithm a(website, rules) that you can remember and that generates unique passwords per website. Store the rules (length restrictions, special character restrictions, number of times the password has changed, etc) in a google doc or something. Print out your algorithm on a physical piece of paper and put it in a safe place for after you die and people need to access your accounts. People always poop on algorithmic passwords, but so far no one has hacked my brain and gotten the algorithm unlike all these other cloud-based password managers that keep getting compromised.

Plus, if my phone or my yubikey or whatever is stolen in a foreign country I'm not SoL because the algorithm is in my brain and the rules are public knowledge.

Re: LastPass users warned their master passwords are compromised

#129
post #114

Confession: I store all my passwords in a plaintext file on my local desktop. I'm sure some people will look at me very funny for doing this, but it seems to me that I have both fewer hassles logging in and fewer breaches than people using more "secure" methods (like handing your passwords over to LastPass's mystery Chrome extension). Think about today's threat landscape and tell me I'm wrong. I may not be more secur…

I see nothing wrong with using a plaintext file on your computer, that’s likely going to be safer than using a cloud based solution for a desktop computer that only you access, especially if you don’t have remote access. Important questions might be how secure is your computer (encrypted HD, multiple users, etc), what incoming services have you enabled (ssh?), does your computer ever travel (is it a laptop, is it pro…

Yeah, if hackers got to your plain text file, they probably also installed a keylogger and clipboard scanner, in which case they have all your passwords, lastpass or not.

Re: LastPass users warned their master passwords are compromised

#130

Earlier quoted context omitted.

So original article is down, but this sounds like people who used the same password as their master and in some _other_ service that has been leaked. ie a user who's lastpass master pass is same as their facebook. Very different from having LastPass leak master pass. Is this the same issue or a case of LastPass not getting the situation?

This article mentions that there were users with unique LastPass passwords who had this occur. Also, I guess they have no incentive to admit a breach

> I guess they have no incentive to admit a breach

It's an interesting game: Reputation is essential to their business. Admitting a breach will harm their reputation, denying it and then getting caught will harm it a lot, but denying it without being proven wrong will probably harm their reputation less (than an admission).

Personally, I'd rather trust a provider that admits a breach, provides transparency, demonstrates good incident response, and hasn't shown complete incompetence from the breach than a provider that has credible rumors of a breach and no good explanation, but I think I'm in the minority here.

Notably, TeamViewer had one of these "rumors but denying a breach and claiming credential stuffing" cases (they later admitted that they also had an earlier but unrelated intrusion that they kept secret for three years, which doesn't help). I think that if it was more than credential stuffing (that's a big if, the credential stuffing explanation is plausible), the strategy worked much better than admitting a breach.

Post reply on HN