Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

141–150 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#141
post #51

Earlier quoted context omitted.

Do this instead https://spectre.app/

Doesn't that make your passwords predictable? If you use the same secret for every domain and now if an attacker figures out your one secret then they would be able to find out all your passwords.

How is that different from any other scheme which uses a master password?

Re: The situation at LastPass may be worse than they are letting on

#142
post #124

This claim looks strange. A 16 characters password from all character types can’t be broken. How could hackers break the vault, with end to end encryption and such password?

faulty implementation of encryption , such as using a weak RNG

Re: The situation at LastPass may be worse than they are letting on

#143
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

Bitwarden, Keeper ($ but trusted at megacorps), and good ol' PasswordSafe are the safest solutions. I run BW with Yubikey 2FA and a local hosted sync server. KeePassX/C perhaps. Vault for secrets management. Never touched LastPass, 1Password or any of these other mickey-mouse commercial apps that invariably claim "military-grade encryption" or "unhackable" when their fundamental constructions are crap.

Do you have any evidence to back your claims about 1password?

Re: The situation at LastPass may be worse than they are letting on

#144
post #21
post #19

Earlier quoted context omitted.

Just for your consideration, I'd bet good money that the 2FA only protects against login credential stuffing, but the vault data is only protected by your master password and can be attacked offline and indefinitely

I mean the individual accounts are protected by 2fa. I have an account or two where I know the password has been leaked but they're so unimportant that I can't be bothered to change the passwords. They still can't get in without my approval.

A lot of sites don’t limit total 2FA attempts, so a determined actor could still get in eventually.

Re: The situation at LastPass may be worse than they are letting on

#145

Earlier quoted context omitted.

I know Dropbox isn't added security, my question is why Dropbox losing the vault wouldn't be just as bad and as likely as Bitwarden losing the vault? Another reply indicates that the main thing is that you don't have to trust the cloud service to do the encryption and zero-knowledge stuff right.

No possibility for a MITM attack (except, I suppose, with a keylogger, but then you've got bigger problems), and absolutely NOTHING outside of encryption, whereas whoever has this leak now knows what users have accounts on what websites, which is a veritable treasure trove. That plus security through obscurity: no one is presuming you're going to come out of a Dropbox hack with millions of password vaults. Even findi…

> No possibility for a MITM attack ... and absolutely NOTHING outside of encryption

LastPass is a disaster, but in theory these benefits are true of Bitwarden as well. They say they encrypt the entire vault, no exceptions, and do the encryption entirely on device.

I can see the honeypot argument, but Dropbox is also a big honeypot for different reasons (tons and tons of plain text information that could be very valuable in the right hands). And I don't think finding the vaults would be as hard as you think it would, because searching for encrypted files should be relatively easy, and any encrypted file is probably worth attempting to crack.

I'm not trying to argue for cloud password managers, I'm totally open to being persuaded and would immediately switch if I were, but I'm really failing to see where the added security is versus Bitwarden. Bitwarden is open source just like KeePassX, so if it did not implement the security model that claims to I think someone would have blown a whistle by now.

Re: The situation at LastPass may be worse than they are letting on

#146
post #55

Earlier quoted context omitted.

I agree: LastPass has been hot garbage for many years but it still has a significant presence, some guy’s low-value crypto wallets would not be the first we hear about a compromise of LastPass vaults. There are entire companies using LastPass for critical systems. I absolutely believe it’s possible that LastPass has been compromised more than they’ve let on and I won’t be surprised if we eventually find out vaults ar…

But if you had a ton of credentials from people, scanning for crypto credentials and trying to use those may be easier/faster/safer to turn into money than system credentials to some random company network.

yes, this. crypto is the fastest to convert to cash

Re: The situation at LastPass may be worse than they are letting on

#147
post #106

I feel like this is an excellent time to, once again, give out two reminders to anyone who needs reminding: "The cloud" is just someone else's computer. Sharing your password with anyone always makes you less secure.

And so does sending your passwords to a phone or a home/work pc via chats or email, or using a single password everywhere, or maybe a couple of them with trivial variations. Cloud password managers wouldn’t even exist if people didn’t do much more stupid things to enter their passwords on a different device than the cloud could ever think of.

>And so does sending your passwords to a phone or a home/work pc via chats or email, or using a single password everywhere, or maybe a couple of them with trivial variations. Cloud password managers wouldn’t even exist if people didn’t do much more stupid things to enter their passwords on a different device than the cloud could ever think of.

"You should do something stupid because most people do things that are even more stupid" is not a good argument in my opinion. I've been in the computer/tech space for 30+ years without every sharing a password or doing something stupid with my passwords, and it hasn't ever been any sort of burden. Why is it so controversial among the HN crowd to simply be minimally intelligent and careful with your sensitive information?

Re: The situation at LastPass may be worse than they are letting on

#148
post #58

Earlier quoted context omitted.

Passwordless might be the way to go. We (as a society) have been trying to do 2FA now wherever we can. 2FA can involve an authenticator app but it is easier with a physical key. That physical key by itself can obsolete the password for many uses. The more numerous the places where we can abandon passwords, the fewer the secrets that we need to keep.

I don't know why, but I'm still a bit afraid of using security key everywhere. I have an irrational fear of losing/breaking my security key. Even though I know my phone is fine and always with me (as a comparison). I just set up a whole backup solution for my many self hosted applications, all encrypted with the keys safely in my password manager. Even uploaded to S3, because I figured if I'm paying for it, I could I…

I think that worry makes sense. It is a good idea to keep a backup. For example, you could get two YubiKeys, use one as your primary, and put the other in a safe place as your backup.

It is a little bit of a hassle. But changing 200 passwords because LastPass was breached is also a hassle.

Re: The situation at LastPass may be worse than they are letting on

#149
post #58

Earlier quoted context omitted.

Passwordless might be the way to go. We (as a society) have been trying to do 2FA now wherever we can. 2FA can involve an authenticator app but it is easier with a physical key. That physical key by itself can obsolete the password for many uses. The more numerous the places where we can abandon passwords, the fewer the secrets that we need to keep.

I don't know why, but I'm still a bit afraid of using security key everywhere. I have an irrational fear of losing/breaking my security key. Even though I know my phone is fine and always with me (as a comparison). I just set up a whole backup solution for my many self hosted applications, all encrypted with the keys safely in my password manager. Even uploaded to S3, because I figured if I'm paying for it, I could I…

One option is to have two identical security keys. In general, you can't easily read the secrets from an existing key, but you can overwrite/initialize them to get two with identical data.

Re: The situation at LastPass may be worse than they are letting on

#150
post #85
post #79

Earlier quoted context omitted.

I used to use KeePass and synced the database (but not the keys or password) with Dropbox. Very secure and mostly convenient.

I loved a similar setup when 1Password used to make that easy. I am very grumpy about them bait and switching me to a cloud/subscription model. (But not quite grumpy enough to have done anything about it yet.)

Version 7 is still available on their website to download (if you have a key for it). Oddly enough they still do update it. It's what I use and likely will use until it no-longer works or there is some issue with it.
Post reply on HN