Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

131–140 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#131

Is there any reason to use these cloud based solutions when open source alternatives like KeepassXC is available?

Same problem with many other open source alternatives. Lousy user experience, in this case across devices.

Although LastPass had a pretty lousy UX for years and years.

Re: The situation at LastPass may be worse than they are letting on

#132
post #106

I feel like this is an excellent time to, once again, give out two reminders to anyone who needs reminding: "The cloud" is just someone else's computer. Sharing your password with anyone always makes you less secure.

And so does sending your passwords to a phone or a home/work pc via chats or email, or using a single password everywhere, or maybe a couple of them with trivial variations. Cloud password managers wouldn’t even exist if people didn’t do much more stupid things to enter their passwords on a different device than the cloud could ever think of.

Or typing your password in! Keyloggers…

Re: The situation at LastPass may be worse than they are letting on

#133
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

Bitwarden, Keeper ($ but trusted at megacorps), and good ol' PasswordSafe are the safest solutions.

I run BW with Yubikey 2FA and a local hosted sync server.

KeePassX/C perhaps. Vault for secrets management.

Never touched LastPass, 1Password or any of these other mickey-mouse commercial apps that invariably claim "military-grade encryption" or "unhackable" when their fundamental constructions are crap.

Re: The situation at LastPass may be worse than they are letting on

#134

Earlier quoted context omitted.

you're thinking too much about the specific example and not the general point, but I edited the parent comment with an actual example edit: oh, I did say append so I see why you'd think that. that's my bad. what I meant was include

By your example, your passwords are a set of fixed or knowable data, plus a unique identifier that in your examples is three characters long. Therefore knowing one of your passwords gives all except three characters of every other password, thus making your effective password length three characters (substitute the actual length of your unique identifier if it's more than three).

Possibly not even 3 characters; 3 numbers.

Re: The situation at LastPass may be worse than they are letting on

#135

Earlier quoted context omitted.

The database is encrypted when at rest; i.e., no plaintext is stored on Dropbox. Assuming your master password is decent, you could plaster the database on a billboard and it would be safe. LastPass, on the other hand, encrypts some information (the actual passwords). The URLs and other sensitive information is stored in plaintext in the cloud. [Final edit. I swear.] As you note, as long as the entire blob is encrypt…

But that is the same claim that Bitwarden and 1Password make. Both insist that they don't ever see your master password, which means that your vault security depends entirely on it being good enough. And both encrypt everything. Assuming that I trust Bitwarden not to lie about their security model, what do I gain by piecing together multiple tools to accomplish the same thing?

(Sorry, I turned around and made an edit, but not before you replied.) KeePass encrypts the entire database, all fields, as one giant blob. LastPass stores URLs and other fields as plaintext; these too can contain critically sensitive information. [Edit: (See I flagged it)] As far as know it wasn't LastPass's client that was compromised--it was their servers/data store.

Re: The situation at LastPass may be worse than they are letting on

#136

Earlier quoted context omitted.

But that is the same claim that Bitwarden and 1Password make. Both insist that they don't ever see your master password, which means that your vault security depends entirely on it being good enough. And both encrypt everything. Assuming that I trust Bitwarden not to lie about their security model, what do I gain by piecing together multiple tools to accomplish the same thing?

(Sorry, I turned around and made an edit, but not before you replied.) KeePass encrypts the entire database, all fields, as one giant blob. LastPass stores URLs and other fields as plaintext; these too can contain critically sensitive information. [Edit: (See I flagged it)] As far as know it wasn't LastPass's client that was compromised--it was their servers/data store.

[deleted]

Re: The situation at LastPass may be worse than they are letting on

#137

And when I say that I will stop using 1password when the local vault no longer works, people look at me like I'm paranoid and crazy. I've looked at the white paper https://1passwordstatic.com/files/security/1password-white-p... , I think 1password has a decent security posture for their cloud offering but then there's always the risk of a breach where the attacker controls the site and can intercept your master passw…

I know more and more people that are unwilling. But looks like 1Password is still unable to recognize this.

Re: The situation at LastPass may be worse than they are letting on

#138
post #64

Having all your keys/passwords on a 3rd party server is something that I've never been willing to accept from a security standpoint. That's what always kept me from using a `hosted` solution. I do get the allure from a multi-user management aspect though.

Write yourself a graph of your core account recoveries, don't put those on. Just put your leaf accounts on (those that recover from the core accounts).

Re: The situation at LastPass may be worse than they are letting on

#139
Is there a site or something where you can put in all the devices you own (e.g., iPhone, Mac laptop, tablet, chromebook, etc) and what features you want (e.g., adding a password on one device syncs it automatically to all other devices, offline useage, auto fill of browser form fields, auto saves now username/passwords, etc.) and it will tell you what password manager best meets your needs?

Re: The situation at LastPass may be worse than they are letting on

#140

If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?

Do encryption on offline computer with trusted open source encryption solutions. Why do you think bitcoin experts have always said to do everything offline?
Post reply on HN