Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

121–130 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#121

I think we can do better in protecting vaults against offline brute force attacks. As written in the this post, 1Password uses a randomly generated "secret key" together with the user-chosen master password. This "secret key" is not stored on 1Password's servers, instead it should be printed on a piece of paper and stored safely. While this is a good starting point, it significantly reduces usability, since you need…

> since the e2ee does not depend on a user chosen master password.

What's the story with "my phone went in the lake" using that setup?

Re: What’s in a PR statement: LastPass breach explained

#122

I think we can do better in protecting vaults against offline brute force attacks. As written in the this post, 1Password uses a randomly generated "secret key" together with the user-chosen master password. This "secret key" is not stored on 1Password's servers, instead it should be printed on a piece of paper and stored safely. While this is a good starting point, it significantly reduces usability, since you need…

What does migration look like for a new device?

If a phone is lost and it's TPM compromised would that put all future credentials at risk?

Most of the derived ideas strike me foolish since they compromise future and past. And they accrue state anyway once one must rotate keys.

Re: What’s in a PR statement: LastPass breach explained

#123
>> The cloud storage service accessed by the threat actor is physically separate from our production environment.

> Is that supposed to be reassuring, considering that the cloud storage in question apparently had a copy of all the LastPass data? Or is this maybe an attempt to shift the blame: “It wasn’t our servers that the data has been lifted from”?

Wow, seriously, they are really good at this. If not for this explanation, I would totally thought only testing environment got accessed.

Re: What’s in a PR statement: LastPass breach explained

#124
post #38

Incredibly pathetic. I am so disappointed in LastPass. I was willing to forgive their subpar UX because hey, at least my passwords were safe. I've moved over to Bitwarden and am happy for now, but man what a shitshow.

> disappointed in LastPass ... moved over to Bitwarden

Same as well, with an intermediate move to Dashlane. I want a reliable, expensive password manager. It's not an easy problem to solve, so if someone's trying to do it cheap, they'll get it wrong. I wish Bitwarden would charge more, but they've proven more secure than LastPass and the Android client is way more reliable than Dashlane.

Re: What’s in a PR statement: LastPass breach explained

#125

I think we can do better in protecting vaults against offline brute force attacks. As written in the this post, 1Password uses a randomly generated "secret key" together with the user-chosen master password. This "secret key" is not stored on 1Password's servers, instead it should be printed on a piece of paper and stored safely. While this is a good starting point, it significantly reduces usability, since you need…

> This "secret key" is not stored on 1Password's servers, instead it should be printed on a piece of paper and stored safely. While this is a good starting point, it significantly reduces usability, since you need this piece of paper when re-installing 1Password.

you can bootstrap from an existing installation too. you’re painting this to be more of a hassle than it actually is in practice.

Re: What’s in a PR statement: LastPass breach explained

#126
post #81

Earlier quoted context omitted.

What about just using chrome’s saved passwords and syncing? It would be great if someone can succinctly destroy that idea :D

I use this and it's convenient but the fact that Google can wipe out my entire digital identity on a whim scares me.

That’s always there. People rely on the google a lot. Have apps in play Store, run YT channel. And other platforms similarly have power over their user base.

Re: What’s in a PR statement: LastPass breach explained

#127

Catastrophic breach after catastrophic breach since 2011. Lastpass has failed their fiduciary duty as a steward of sensitive information and IMO exhibited gross negligence in not encrypting URI data, ostensibly as a trade off for consumer functionality. not to be overly vindictive, as I understand the near impossibility of running a perfectly secure service at absolutely enormous scale…but does anyone else feel LastP…

I feel this way but this is wishful thinking. It's more likely that they will transition even more into a gray privacy territory by marketing LastPass to less and less tech-savvy users, eventually bundling it for free with some spammy ad-supported service and/or preinstalled on a phone or laptop (basically, Norton and McAfee territory). The parent company is already not trustworthy, and this breach is the last nail into LastPass as a trustworthy service.

Re: What’s in a PR statement: LastPass breach explained

#128
post #58
post #28

Earlier quoted context omitted.

Disclaimer : I am the author of this article. What kind of pragmatism would you prefer? LastPass messed up way more than they are willing to admit. And it’s not like nobody warned them before, quite a few of the issues which turn out to be very problematic now aren’t news – I brought them up years ago as did others. LastPass should be warning users now and suggesting mitigation steps, instead they claim that nobody h…

This is a compelling article, I feel more motivated now to reconsider my options. FWIW, my $0.02 feedback on pragmatism: as a user, it would be nice to have more what-to-do-about-it for non-security-experts. Also I didn’t love the parts of the article where you speculated about LastPass’ motivations and process (even if they turn out to be true!) The opening paragraph is making assumptions about the timing, which cou…

The statement you objected to was used to demonstrate that a specific claim by LastPass ("As a reminder, the master password is never known to LastPass and is not stored or maintained by LastPass") offers no guarantees that your master password is known only to you. This, in turn, leads to the conclusion that, even if you followed all of LastPass's guidance on master password security, the prudent thing would be to take some action - something that LastPass explicitly denied later in the statement.

I'm sorry if you find this disturbing, but I do not see why it should not be said.

Re: What’s in a PR statement: LastPass breach explained

#129

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

For some reason "MacOS" appears twice for me in the "options" section. I'd love for some more options.

- Doesn't require a subscription

- Doesn't require a web login

- Allows local vaults

Re: What’s in a PR statement: LastPass breach explained

#130
post #129

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

For some reason "MacOS" appears twice for me in the "options" section. I'd love for some more options. - Doesn't require a subscription - Doesn't require a web login - Allows local vaults

gnu-pass and bitwarden tick those boxes at least-

any other requirements that maybe you simply assume should be available (like browser extensions)

Post reply on HN