Live data from Hacker News

LastPass: Notice of Security Incident

blog.lastpass.com

121–130 of 141 posts

Re: LastPass: Notice of Security Incident

#121

"engaged a leading cybersecurity and forensics firm." This is the current trend each time there is a breach: let's pretend/show that we are serious and waste money taking "security" consultants, that will in the end probably tell us obvious things. Pay more or listen to your own employees instead and eventually go hire competent engineers instead of funding bullshit jobs. Lastpass is supposed to be in the "cyber secu…

Accidents can and will happen. If Lastpass conducted the review it wouldn't be seen as impartial, they need a third party to remain transparent.

Re: LastPass: Notice of Security Incident

#122

"engaged a leading cybersecurity and forensics firm." This is the current trend each time there is a breach: let's pretend/show that we are serious and waste money taking "security" consultants, that will in the end probably tell us obvious things. Pay more or listen to your own employees instead and eventually go hire competent engineers instead of funding bullshit jobs. Lastpass is supposed to be in the "cyber secu…

Security incident response is a very specialized role that the vast majority of not only ordinary tech companies but also security tech companies can't necessarily be expected to do entirely on their own in the event of suspicion of a serious breach.

This isn't hiring an auditor or consultant to recommend better security practices but more like a team of world-class detectives, investigators, and forensicists to figure out exactly what happened and how, what they might have done or taken, if they still have or could regain access, and, potentially, ideas as to who or what the culprits may be and what their objectives were. In particular, you want to have as much confidence as possible in what they may have done when they had access to your systems and that they have been effectively shut out and don't have any other access points/backdoors.

LastPass undoubtedly also has their own security incident response team - most companies probably should - but it's like the local county PD calling in the FBI when a serious or sophisticated crime occurs.

Re: LastPass: Notice of Security Incident

#123

Earlier quoted context omitted.

> They are savy enough to know what a password manager is, but not savy enough to deal with an offline one. Not the person you responded to, but: I think that most people are savvy enough to know what a password manager is, and most people are not savvy enough to be interested in the work necessary to setup, personalize, and maintaining an offline password manager that functions well across multiple devices. That doe…

My point is to illustrate that the commenter is speaking out of their respective ass. None of us know what the average person thinks, we are a group of tremendous nerds who are engaging, not just reading, in the comments section to a post about a flipping password manager.

Many of us in this forum are people that have tried to influence those around us - family, friends, coworkers - to use better security practices such as password managers. Those personal experiences alongside the prevalence and adoption of cloud-sync enabled password managers (including browsers) creates a reasonable foundation from which to form a not-fully-ignorant opinion.

Re: LastPass: Notice of Security Incident

#124
Thanks for reminding me to delete my lastpass acount.

I switched over to a self hosted bitwarden, and not only is the user experience a lot better, I've got better security confidence since my password store never leaves my home network.

Re: LastPass: Notice of Security Incident

#125

Earlier quoted context omitted.

I thought the 2FA all the big services have is so that they will deliver you your encrypted vault, rather than another layer of encryption? (I know FIDO can theoretically do that, but AFAIK it really wasn't designed for it). The threat isn't the service having the encrypted vault anyway; we kind of trust the encryption to be decent (though of course you can't know what technological threats are looming). The real thr…

> I thought the 2FA all the big services have is so that they will deliver you your encrypted vault, rather than another layer of encryption? Correct, 2FA is protection in addition to your password manager. So if someone gets your unsealed vault they cannot log into any services without also compromising your second factor. 2FA is not for further cryptographic hardening of the vault itself. > The real threat is that…

Actually -- a "web of trust" idea for the browsers is quite sufficient.

Google et al... have already proven that they are at least decent at security and that they care about things owing to their success in the market. They've proven that they've handled this reasonably well and following their lead on how to do security in software is probably pretty good. They have both experience and skin in the game, lots of it, in the form of lots of money et al.

NOW, these password companies? NOPE. They simply don't have the right incentives in place to be trustable. (or more specifically, that they're going to be much better at securing my stuff than I will) They're too young and don't have sufficient "punishment" at the ready for me to be able to trust them much. They don't do indemnification, and liability for them isn't going to be great. I can't presume the same level of skill or care because the infrastructure/incentives aren't as presumably solid.

(Put differently, the Lifelock guy was a hero, he was at least willing to put something real on the line.)

Re: LastPass: Notice of Security Incident

#126

I'm so glad we switched from LastPass to Bitwarden earlier this year. It seems like every few years there's some kind of breach with LastPass.

What advantages does Bitwarden have in terms of security? I’m on LastPass and curious if and why I should switch.

LastPass is a larger target for attacks, which is why there's some kind of breach or security issue with it every few years. It's too often. I already lost trust in them years ago, but was too lazy to switch until this year. BitWarden hasn't had the same issues yet. Plus BW is open source and critical bugs can't be hidden. There's also the option to self-host your data if you want.

BitWarden's UX is a little different, and in some ways inferior to LastPass. Sharing passwords with my wife feels convoluted in BW, but it works perfectly fine. You have to create an "organization" where both users join, and then add your sites/pws to. In LastPass you just share it. But I've also found BitWarden works better, especially on mobile. LastPass would fail filling in passwords on some sites, and I'd have to use different autofill methods to get it to fill. But BitWarden doesn't have the same issue and mostly just works. I also like BitWarden's built-in 2FA field for each site's password, which eliminates having to use other authenticator apps. Except you'll still want to use a 2FA app for BitWarden's master password.

Re: LastPass: Notice of Security Incident

#127
post #2

Not enough data to say what the impact of this is. Good for them disclosing it early while they investigate. > we have seen no evidence that this incident involved any access to customer data or encrypted password vaults. One way to prevent risk to your passwords in the event of a security breach is to not store them in the cloud at all. KeePass is great!

I have 5 laptops, 6 mobile devices and a desktop machine that I am constantly moving between. All of them are ios or macos. I have been using lastpass since it is so simple and works flawlessly. Will keepass work as simply for my use case?

Re: LastPass: Notice of Security Incident

#129

Earlier quoted context omitted.

My point is to illustrate that the commenter is speaking out of their respective ass. None of us know what the average person thinks, we are a group of tremendous nerds who are engaging, not just reading, in the comments section to a post about a flipping password manager.

Many of us in this forum are people that have tried to influence those around us - family, friends, coworkers - to use better security practices such as password managers. Those personal experiences alongside the prevalence and adoption of cloud-sync enabled password managers (including browsers) creates a reasonable foundation from which to form a not-fully-ignorant opinion.

Yes, like me, and I've had success with getting people to use keepass. Should I extrapolate my personal anecdote to apply to everyone?

Re: LastPass: Notice of Security Incident

#130
post #74

Earlier quoted context omitted.

My point is to illustrate that the commenter is speaking out of their respective ass. None of us know what the average person thinks, we are a group of tremendous nerds who are engaging, not just reading, in the comments section to a post about a flipping password manager.

I'm speaking out of personal experience trying to get non-average users (my friends and family, some of whom work in non-technical roles at software companies) to understand and use password managers. Most of them can't and won't invest the time just to switch to 1Password. The average person isn't going to exceed that bar by a margin that even I, a software developer, wouldn't bother with. When something is too tech…

Paragraph one is good. In paragraph two, you're doing it again. :D

It's easy, unless you have actual data, what you have is an opinion.

Post reply on HN