"engaged a leading cybersecurity and forensics firm." This is the current trend each time there is a breach: let's pretend/show that we are serious and waste money taking "security" consultants, that will in the end probably tell us obvious things. Pay more or listen to your own employees instead and eventually go hire competent engineers instead of funding bullshit jobs. Lastpass is supposed to be in the "cyber secu…
LastPass: Notice of Security Incident
121–130 of 141 posts
Re: LastPass: Notice of Security Incident
#122"engaged a leading cybersecurity and forensics firm." This is the current trend each time there is a breach: let's pretend/show that we are serious and waste money taking "security" consultants, that will in the end probably tell us obvious things. Pay more or listen to your own employees instead and eventually go hire competent engineers instead of funding bullshit jobs. Lastpass is supposed to be in the "cyber secu…
This isn't hiring an auditor or consultant to recommend better security practices but more like a team of world-class detectives, investigators, and forensicists to figure out exactly what happened and how, what they might have done or taken, if they still have or could regain access, and, potentially, ideas as to who or what the culprits may be and what their objectives were. In particular, you want to have as much confidence as possible in what they may have done when they had access to your systems and that they have been effectively shut out and don't have any other access points/backdoors.
LastPass undoubtedly also has their own security incident response team - most companies probably should - but it's like the local county PD calling in the FBI when a serious or sophisticated crime occurs.
Re: LastPass: Notice of Security Incident
#123Earlier quoted context omitted.
> They are savy enough to know what a password manager is, but not savy enough to deal with an offline one. Not the person you responded to, but: I think that most people are savvy enough to know what a password manager is, and most people are not savvy enough to be interested in the work necessary to setup, personalize, and maintaining an offline password manager that functions well across multiple devices. That doe…
My point is to illustrate that the commenter is speaking out of their respective ass. None of us know what the average person thinks, we are a group of tremendous nerds who are engaging, not just reading, in the comments section to a post about a flipping password manager.
Re: LastPass: Notice of Security Incident
#124I switched over to a self hosted bitwarden, and not only is the user experience a lot better, I've got better security confidence since my password store never leaves my home network.
Re: LastPass: Notice of Security Incident
#125Earlier quoted context omitted.
I thought the 2FA all the big services have is so that they will deliver you your encrypted vault, rather than another layer of encryption? (I know FIDO can theoretically do that, but AFAIK it really wasn't designed for it). The threat isn't the service having the encrypted vault anyway; we kind of trust the encryption to be decent (though of course you can't know what technological threats are looming). The real thr…
> I thought the 2FA all the big services have is so that they will deliver you your encrypted vault, rather than another layer of encryption? Correct, 2FA is protection in addition to your password manager. So if someone gets your unsealed vault they cannot log into any services without also compromising your second factor. 2FA is not for further cryptographic hardening of the vault itself. > The real threat is that…
Google et al... have already proven that they are at least decent at security and that they care about things owing to their success in the market. They've proven that they've handled this reasonably well and following their lead on how to do security in software is probably pretty good. They have both experience and skin in the game, lots of it, in the form of lots of money et al.
NOW, these password companies? NOPE. They simply don't have the right incentives in place to be trustable. (or more specifically, that they're going to be much better at securing my stuff than I will) They're too young and don't have sufficient "punishment" at the ready for me to be able to trust them much. They don't do indemnification, and liability for them isn't going to be great. I can't presume the same level of skill or care because the infrastructure/incentives aren't as presumably solid.
(Put differently, the Lifelock guy was a hero, he was at least willing to put something real on the line.)
Re: LastPass: Notice of Security Incident
#126I'm so glad we switched from LastPass to Bitwarden earlier this year. It seems like every few years there's some kind of breach with LastPass.
What advantages does Bitwarden have in terms of security? I’m on LastPass and curious if and why I should switch.
BitWarden's UX is a little different, and in some ways inferior to LastPass. Sharing passwords with my wife feels convoluted in BW, but it works perfectly fine. You have to create an "organization" where both users join, and then add your sites/pws to. In LastPass you just share it. But I've also found BitWarden works better, especially on mobile. LastPass would fail filling in passwords on some sites, and I'd have to use different autofill methods to get it to fill. But BitWarden doesn't have the same issue and mostly just works. I also like BitWarden's built-in 2FA field for each site's password, which eliminates having to use other authenticator apps. Except you'll still want to use a 2FA app for BitWarden's master password.
Re: LastPass: Notice of Security Incident
#127Not enough data to say what the impact of this is. Good for them disclosing it early while they investigate. > we have seen no evidence that this incident involved any access to customer data or encrypted password vaults. One way to prevent risk to your passwords in the event of a security breach is to not store them in the cloud at all. KeePass is great!
Re: LastPass: Notice of Security Incident
#128Re: LastPass: Notice of Security Incident
#129Earlier quoted context omitted.
My point is to illustrate that the commenter is speaking out of their respective ass. None of us know what the average person thinks, we are a group of tremendous nerds who are engaging, not just reading, in the comments section to a post about a flipping password manager.
Many of us in this forum are people that have tried to influence those around us - family, friends, coworkers - to use better security practices such as password managers. Those personal experiences alongside the prevalence and adoption of cloud-sync enabled password managers (including browsers) creates a reasonable foundation from which to form a not-fully-ignorant opinion.
Re: LastPass: Notice of Security Incident
#130Earlier quoted context omitted.
My point is to illustrate that the commenter is speaking out of their respective ass. None of us know what the average person thinks, we are a group of tremendous nerds who are engaging, not just reading, in the comments section to a post about a flipping password manager.
I'm speaking out of personal experience trying to get non-average users (my friends and family, some of whom work in non-technical roles at software companies) to understand and use password managers. Most of them can't and won't invest the time just to switch to 1Password. The average person isn't going to exceed that bar by a margin that even I, a software developer, wouldn't bother with. When something is too tech…
It's easy, unless you have actual data, what you have is an opinion.