Live data from Hacker News

LastPass: Notice of Security Incident

blog.lastpass.com

131–140 of 141 posts

Re: LastPass: Notice of Security Incident

#131
post #120
post #95

Earlier quoted context omitted.

While this is true, and I did this for the better part of 2010s, it was pretty clunky. Especially if one needs a platform for their wife or children to also use. I'm gonna ride out LastPass until webauthn really takes off. Which could be soon based on what we're hearing from the mobile vendors.

> Which could be soon based on what we're hearing from the mobile vendors. I'd really like to see wider webauthn support, so I'm curious to know what you mean by what you're hearing from the mobile vendors please?

https://www.apple.com/newsroom/2022/05/apple-google-and-micr...

Re: LastPass: Notice of Security Incident

#132

Earlier quoted context omitted.

Many of us in this forum are people that have tried to influence those around us - family, friends, coworkers - to use better security practices such as password managers. Those personal experiences alongside the prevalence and adoption of cloud-sync enabled password managers (including browsers) creates a reasonable foundation from which to form a not-fully-ignorant opinion.

Yes, like me, and I've had success with getting people to use keepass. Should I extrapolate my personal anecdote to apply to everyone?

You have had success getting non-technically oriented friends and family to use a Keepass across multiple devices? Then you're doing far better than me.

I don't think your experience is representative. As I stated in my previous comment, I think the relative success of cloud-enabled password managers vs. more secure options like Keepass are a non-anecdotal form of support for this opinion. But I would be way off (which I also acknowledge).

Re: LastPass: Notice of Security Incident

#133

Earlier quoted context omitted.

Yes, like me, and I've had success with getting people to use keepass. Should I extrapolate my personal anecdote to apply to everyone?

You have had success getting non-technically oriented friends and family to use a Keepass across multiple devices? Then you're doing far better than me. I don't think your experience is representative. As I stated in my previous comment, I think the relative success of cloud-enabled password managers vs. more secure options like Keepass are a non-anecdotal form of support for this opinion. But I would be way off (whi…

Could be that those companies use marketing? Keepass doesn't market. Hard to say without any facts. :D

Re: LastPass: Notice of Security Incident

#134
post #2

Not enough data to say what the impact of this is. Good for them disclosing it early while they investigate. > we have seen no evidence that this incident involved any access to customer data or encrypted password vaults. One way to prevent risk to your passwords in the event of a security breach is to not store them in the cloud at all. KeePass is great!

by disclosing it early you mean two weeks later

Re: LastPass: Notice of Security Incident

#135
post #3
post #2

Not enough data to say what the impact of this is. Good for them disclosing it early while they investigate. > we have seen no evidence that this incident involved any access to customer data or encrypted password vaults. One way to prevent risk to your passwords in the event of a security breach is to not store them in the cloud at all. KeePass is great!

Most people use a work machine and a mobile device, so cloud syncing is absolutely necessary. LastPass and its competitors theoretically have zero-knowledge storage of everyone's passwords, so even a full breach of their servers would fail to leak passwords.

hack code, roll out app updates... you see where this is going?

Re: LastPass: Notice of Security Incident

#136

I switched providers the last time this happened, or was it the one before that. Not a good look for an online password storage service.

yea at this point it is about how well it is handled, and transparency of the incident. Currently I am seeing support staff on LP reddit complain about customers attitudes. I am done. moving my partner off LP, I was out to Bitwarden some time back but didnt have a reason to force her into a change, til now.

Re: LastPass: Notice of Security Incident

#137

I switched providers the last time this happened, or was it the one before that. Not a good look for an online password storage service.

As someone else said. Breaches can and will happen to anyone and we should assume they eventually will happen to everyone. What matters is how quickly you can detect the breach how limited the impact is. It's still too early to tell exactly whats happening here yet. That said, if this only impacted a development environment that contained no customer data then this is a good example of that principle.

hacked two weeks ago is what I am seeing. and they are still using words like "probably okay" wherever I look for answers. I havent had an email update from LP since the word salad notification they sent out yday that told me absolutely nothing but vagueries.

Re: LastPass: Notice of Security Incident

#138
post #124

Thanks for reminding me to delete my lastpass acount. I switched over to a self hosted bitwarden, and not only is the user experience a lot better, I've got better security confidence since my password store never leaves my home network.

it's better in all ways including export and backup solutions

Re: LastPass: Notice of Security Incident

#139

Earlier quoted context omitted.

You've picked a strange subset of 'most' for the people you're imagining. They are savy enough to know what a password manager is, but not savy enough to deal with an offline one. Are you sure its not just a few people like you?

> They are savy enough to know what a password manager is, but not savy enough to deal with an offline one. Not the person you responded to, but: I think that most people are savvy enough to know what a password manager is, and most people are not savvy enough to be interested in the work necessary to setup, personalize, and maintaining an offline password manager that functions well across multiple devices. That doe…

I'm savvy enough to maintain an offline password manager, but fuck that noise.

It's already painful enough to use a cloud password manager; why would I burn hours more of time to maintain a worse experience?

Re: LastPass: Notice of Security Incident

#140

Earlier quoted context omitted.

You've picked a strange subset of 'most' for the people you're imagining. They are savy enough to know what a password manager is, but not savy enough to deal with an offline one. Are you sure its not just a few people like you?

> They are savy enough to know what a password manager is, but not savy enough to deal with an offline one. Not the person you responded to, but: I think that most people are savvy enough to know what a password manager is, and most people are not savvy enough to be interested in the work necessary to setup, personalize, and maintaining an offline password manager that functions well across multiple devices. That doe…

How about cloud storage? iCloud, OneDrive, Google Drive, etc. Good apps support those out of box; for desktop install their client and use the file as you normally would.
Post reply on HN