Live data from Hacker News

LastPass users warned their master passwords are compromised

bleepingcomputer.com

131–140 of 326 posts

Re: LastPass users warned their master passwords are compromised

#131
post #115

To those who are recommending all different password managers, I have a question: why not using Chrome (or Firefox/Edge/ )'s built-in password manager? I have been using it for a couple years and haven't noticed any issue. Even if Google decides to screw me over and terminates my Google account, I can still access the passwords via the local copy in Chrome, so that is not really a concern. (Though, don't take this as…

Google's/Chrome's password manager would be reasonable if I could actually add passwords to it, manually. It only saves passwords that you type in a login page in the browser. So for the plethora of other credentials I need to manage it's less than useless, because it just gets in the way.

Re: LastPass users warned their master passwords are compromised

#132
Not good news - I use Bitwarden, not LastPass, but if you're using a password manager make sure to use 2 factor authentication and this really wouldn't be an issue in the first place.

I have my TOTP codes stored in Bitwarden for other services like Facebook etc, but I use Authy as an independent TOTP provider for Bitwarden. 1.5 factor I guess (2FA tokens in a password manager), but works a treat and is very convenient!

Re: LastPass users warned their master passwords are compromised

#133
post #71

Earlier quoted context omitted.

What's your personal threat model? I'm always trying to balance the risk of a party focused on security vs the minimal effort I'm likely to put into it. I don't want to be a story about the guy that lost their password to a wallet or anything else important. I used to be able to reliably remember complex passwords reliably but finding that's no longer the case, now only shorter intermittently used ones based on how o…

I’ve decided that besides a password manager, all of my passwords will also have a number at the end, like 8 (simple, easy to append manually in a password field. Now the password manager has to get defeated AND my own small personal salt value will have to be known.

This is a good idea that's never occurred to me. I guess you could also consider it like having one password for all your accounts, except salted with some random string from your password manager

Re: LastPass users warned their master passwords are compromised

#134
post #115

To those who are recommending all different password managers, I have a question: why not using Chrome (or Firefox/Edge/ )'s built-in password manager? I have been using it for a couple years and haven't noticed any issue. Even if Google decides to screw me over and terminates my Google account, I can still access the passwords via the local copy in Chrome, so that is not really a concern. (Though, don't take this as…

Because as far as I know you can't easily access your password outside of Chrome. For example, it's not practical to use on my iOS devices. If you want to log into an app, I believe you can't easily use passwords stored in Chrome.

You can use passwords.google.com, which is what I have been using.

Re: LastPass users warned their master passwords are compromised

#135

Confession: I store all my passwords in a plaintext file on my local desktop. I'm sure some people will look at me very funny for doing this, but it seems to me that I have both fewer hassles logging in and fewer breaches than people using more "secure" methods (like handing your passwords over to LastPass's mystery Chrome extension). Think about today's threat landscape and tell me I'm wrong. I may not be more secur…

Not that your approach doesn't have advantages, but at that point I would just keep them in a paper notebook hidden in my desk.

That's what I do.

The number of times my home's been broken into: 0 (and based on news, virtually all of burglars are just looking for jewelry, wallets, and similar stuff and they won't bother trawling through your papers for passwords).

The number of times I've had devices on my network that run some hastily put together vendor firmware that was last updated six years ago: too many to count.

The number of times I've had to rush to update/patch my own computers to fix a newly disclosed remotely exploitable vuln: quite a few.

The number of times I've actually witnessed attempts at trying to exploit said remote vulns: too many to count! Sometimes mere hours after I've patched my stuff.

The number of times I've known I've had malware: at least a couple times (admittedly long ago, back when I ran Windows..).

I just don't trust keeping personal passwords on online connected computing devices. And password managers are a very lucrative target today (plus it tends to be all eggs in one basket for most people!).

I do keep passwords for employer's stuff in a password manager but not on the same device(s) I use said passwords on; even if you had malware on my work laptop, you wouldn't get my master password, nor would you be able to grab my password database. Passwords are also not stored on any third party service.

The price I pay is a relatively minor inconvenience. (I do have plans for something more convenient though!)

Re: LastPass users warned their master passwords are compromised

#136

Earlier quoted context omitted.

You could just use KeePass: https://keepass.info/ It's a free open source app that runs on your local machine and stores your passwords locally - never uploads your passwords to a server. But it does this securely. And you can run it on multiple machines (and phones) and transfer the passwords (the vault) without ever uploading anything to servers.

Seems useful, the name gave me a chuckle. If I only saw the URL, I would imagine this was a service that providing info on preserving your buttocks.

It's fitting, good password management is the "watch out for your Cornhole" of the 21st century...

Re: LastPass users warned their master passwords are compromised

#137
post #54
post #7

> Some customers have also reported changing their master passwords since they received the login warning, only to receive another alert after the password was changed. Must be a compromised browser extension at this point. > To make things even worse, customers who tried disabling and deleting their LastPass accounts after receiving these warnings also report [1, 2] receiving "Something went wrong: A" errors after c…

>Must be a compromised browser extension at this point. The previous thread had password never typed, copied or used for years. Unless we are talking about multiple vector, otherwise browser extension doesn't fit most of the reported scenario.

Agreed. If it was a compromised extension it would steal all the passwords when you unlock and upload it somewhere like pastebin.

Re: LastPass users warned their master passwords are compromised

#138
post #122
post #115

To those who are recommending all different password managers, I have a question: why not using Chrome (or Firefox/Edge/ )'s built-in password manager? I have been using it for a couple years and haven't noticed any issue. Even if Google decides to screw me over and terminates my Google account, I can still access the passwords via the local copy in Chrome, so that is not really a concern. (Though, don't take this as…

> I have a question: why not using Chrome's built-in password manager Because then you are locked into Chrome and some people prefer the freedom to switch browsers at any time

Right, that is why browsers have the option to import passwords. I actually use Firefox at the same time and imported my passwords without any problems.

Re: LastPass users warned their master passwords are compromised

#139
Related question: I find it incredibly stupid that LastPass makes it so difficult to see your complete account login history. The "View Account History" table is beyond awful - beyond making it to filter for, example, failed login attempts, it is limited to 1 page and doesn't let you paginate, at least in my browser. Am I missing something?

Re: LastPass users warned their master passwords are compromised

#140
post #115

To those who are recommending all different password managers, I have a question: why not using Chrome (or Firefox/Edge/ )'s built-in password manager? I have been using it for a couple years and haven't noticed any issue. Even if Google decides to screw me over and terminates my Google account, I can still access the passwords via the local copy in Chrome, so that is not really a concern. (Though, don't take this as…

because i like to use firefox?

Then why not use Firefox's built-in password manager? I thought my question should automatically generalize to any browser's built-in password manager.
Post reply on HN