Earlier quoted context omitted.
Do this instead https://spectre.app/
Doesn't that make your passwords predictable? If you use the same secret for every domain and now if an attacker figures out your one secret then they would be able to find out all your passwords.
The situation at LastPass may be worse than they are letting on
141–150 of 436 posts
Re: The situation at LastPass may be worse than they are letting on
#142This claim looks strange. A 16 characters password from all character types can’t be broken. How could hackers break the vault, with end to end encryption and such password?
Re: The situation at LastPass may be worse than they are letting on
#143For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…
Bitwarden, Keeper ($ but trusted at megacorps), and good ol' PasswordSafe are the safest solutions. I run BW with Yubikey 2FA and a local hosted sync server. KeePassX/C perhaps. Vault for secrets management. Never touched LastPass, 1Password or any of these other mickey-mouse commercial apps that invariably claim "military-grade encryption" or "unhackable" when their fundamental constructions are crap.
Re: The situation at LastPass may be worse than they are letting on
#144Earlier quoted context omitted.
Just for your consideration, I'd bet good money that the 2FA only protects against login credential stuffing, but the vault data is only protected by your master password and can be attacked offline and indefinitely
I mean the individual accounts are protected by 2fa. I have an account or two where I know the password has been leaked but they're so unimportant that I can't be bothered to change the passwords. They still can't get in without my approval.
Re: The situation at LastPass may be worse than they are letting on
#145Earlier quoted context omitted.
I know Dropbox isn't added security, my question is why Dropbox losing the vault wouldn't be just as bad and as likely as Bitwarden losing the vault? Another reply indicates that the main thing is that you don't have to trust the cloud service to do the encryption and zero-knowledge stuff right.
No possibility for a MITM attack (except, I suppose, with a keylogger, but then you've got bigger problems), and absolutely NOTHING outside of encryption, whereas whoever has this leak now knows what users have accounts on what websites, which is a veritable treasure trove. That plus security through obscurity: no one is presuming you're going to come out of a Dropbox hack with millions of password vaults. Even findi…
LastPass is a disaster, but in theory these benefits are true of Bitwarden as well. They say they encrypt the entire vault, no exceptions, and do the encryption entirely on device.
I can see the honeypot argument, but Dropbox is also a big honeypot for different reasons (tons and tons of plain text information that could be very valuable in the right hands). And I don't think finding the vaults would be as hard as you think it would, because searching for encrypted files should be relatively easy, and any encrypted file is probably worth attempting to crack.
I'm not trying to argue for cloud password managers, I'm totally open to being persuaded and would immediately switch if I were, but I'm really failing to see where the added security is versus Bitwarden. Bitwarden is open source just like KeePassX, so if it did not implement the security model that claims to I think someone would have blown a whistle by now.
Re: The situation at LastPass may be worse than they are letting on
#146Earlier quoted context omitted.
I agree: LastPass has been hot garbage for many years but it still has a significant presence, some guy’s low-value crypto wallets would not be the first we hear about a compromise of LastPass vaults. There are entire companies using LastPass for critical systems. I absolutely believe it’s possible that LastPass has been compromised more than they’ve let on and I won’t be surprised if we eventually find out vaults ar…
But if you had a ton of credentials from people, scanning for crypto credentials and trying to use those may be easier/faster/safer to turn into money than system credentials to some random company network.
Re: The situation at LastPass may be worse than they are letting on
#147I feel like this is an excellent time to, once again, give out two reminders to anyone who needs reminding: "The cloud" is just someone else's computer. Sharing your password with anyone always makes you less secure.
And so does sending your passwords to a phone or a home/work pc via chats or email, or using a single password everywhere, or maybe a couple of them with trivial variations. Cloud password managers wouldn’t even exist if people didn’t do much more stupid things to enter their passwords on a different device than the cloud could ever think of.
"You should do something stupid because most people do things that are even more stupid" is not a good argument in my opinion. I've been in the computer/tech space for 30+ years without every sharing a password or doing something stupid with my passwords, and it hasn't ever been any sort of burden. Why is it so controversial among the HN crowd to simply be minimally intelligent and careful with your sensitive information?
Re: The situation at LastPass may be worse than they are letting on
#148Earlier quoted context omitted.
Passwordless might be the way to go. We (as a society) have been trying to do 2FA now wherever we can. 2FA can involve an authenticator app but it is easier with a physical key. That physical key by itself can obsolete the password for many uses. The more numerous the places where we can abandon passwords, the fewer the secrets that we need to keep.
I don't know why, but I'm still a bit afraid of using security key everywhere. I have an irrational fear of losing/breaking my security key. Even though I know my phone is fine and always with me (as a comparison). I just set up a whole backup solution for my many self hosted applications, all encrypted with the keys safely in my password manager. Even uploaded to S3, because I figured if I'm paying for it, I could I…
It is a little bit of a hassle. But changing 200 passwords because LastPass was breached is also a hassle.
Re: The situation at LastPass may be worse than they are letting on
#149Earlier quoted context omitted.
Passwordless might be the way to go. We (as a society) have been trying to do 2FA now wherever we can. 2FA can involve an authenticator app but it is easier with a physical key. That physical key by itself can obsolete the password for many uses. The more numerous the places where we can abandon passwords, the fewer the secrets that we need to keep.
I don't know why, but I'm still a bit afraid of using security key everywhere. I have an irrational fear of losing/breaking my security key. Even though I know my phone is fine and always with me (as a comparison). I just set up a whole backup solution for my many self hosted applications, all encrypted with the keys safely in my password manager. Even uploaded to S3, because I figured if I'm paying for it, I could I…
Re: The situation at LastPass may be worse than they are letting on
#150Earlier quoted context omitted.
I used to use KeePass and synced the database (but not the keys or password) with Dropbox. Very secure and mostly convenient.
I loved a similar setup when 1Password used to make that easy. I am very grumpy about them bait and switching me to a cloud/subscription model. (But not quite grumpy enough to have done anything about it yet.)