Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

141–150 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#141
post #19
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

Excuse me if this seems impolite, but is there a reason you need his passwords? Financial institutions have a very regulated pipeline for access of deceased accounts to relatives. And for personal email and stuff, well I think that should remain private unless the deceased explicitly wanted to share.

Re: What’s in a PR statement: LastPass breach explained

#142
post #138
post #114

Earlier quoted context omitted.

Clicking on a 'phishing' link can't hurt, and it's not like this person's website is ever going to be presented to you in a sensitive context (e.g. "download/install software from this site"). You should trust that your browser is secure enough to render random webpages. Excuse the self-promotion, but I take it that you're also too wary to click on this link to read my blog: https://dangerous.link/virus.exe

Any URL on the web could host a browser exploit that requires no interaction beyond visiting, but if I had to guess which one were most likely to, I'd put phishing links up there. > You should trust that your browser is secure enough to render random webpages. I honestly don't. Is dangerous.link/virus.exe any more dangerous than nytimes.com? Probably not. However if some 0-day, no interaction browser exploit does exi…

[dead]

Re: What’s in a PR statement: LastPass breach explained

#143

I think we can do better in protecting vaults against offline brute force attacks. As written in the this post, 1Password uses a randomly generated "secret key" together with the user-chosen master password. This "secret key" is not stored on 1Password's servers, instead it should be printed on a piece of paper and stored safely. While this is a good starting point, it significantly reduces usability, since you need…

> since the e2ee does not depend on a user chosen master password. What's the story with "my phone went in the lake" using that setup?

fish it out of the lake and pay someone $1000 to extract the tpm and restore it for you

Re: What’s in a PR statement: LastPass breach explained

#144
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

I've been using Dropbox, then Nextcloud to keep the database synchronized on all my devices for years and years. Absolutely no problem at all, and dead simple.

Re: What’s in a PR statement: LastPass breach explained

#145
post #29

Earlier quoted context omitted.

Have to plan ahead and have the keypass password in an envelope in the safe deposit box.

What else is in your self deposit box? I thought only rich people with gold and jewels and spies with fake passports and ready currency used safe deposit boxes.

When we first immigrated to Canada my family kept some of our documents such as birth records etc. It was super cheap and my family felt security was beneficial.

I don't have one currently but perhaps I should.

Re: What’s in a PR statement: LastPass breach explained

#146

Earlier quoted context omitted.

With KeePass, the trivial solution for this situation could just be a second subset database of relevant accounts on a thumb drive, with the password known to family individuals. That seems easier than relying on a cloud provider and some sort of half-baked insecure emergency access mode.

FYI, thumb drives die. The longest I’ve hand one work was about 7 years, more recent thumb drives tend to only last 3-4 years. For longevity a CD / DVD might last longer, but even then those are 30 years on average.

I still have my first 128MB thumb drive, bought in 2001 or so. Works fine. Holds a kdbx file fine :)

Re: What’s in a PR statement: LastPass breach explained

#147
post #19

Earlier quoted context omitted.

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

Excuse me if this seems impolite, but is there a reason you need his passwords? Financial institutions have a very regulated pipeline for access of deceased accounts to relatives. And for personal email and stuff, well I think that should remain private unless the deceased explicitly wanted to share.

Where I live it could take months (or even years if thr heirs of a deceased doesn't agree on the terms) to have the access to the money. It would be quite illegal to knowingly use the money of a deceased person, but things happens.

Re: What’s in a PR statement: LastPass breach explained

#148

Earlier quoted context omitted.

> since the e2ee does not depend on a user chosen master password. What's the story with "my phone went in the lake" using that setup?

Since i use Google Authenticator for numerous services this is going to happen to me one day. So what I did was set it up on more than one phone.

I would legit pay money for Google to pull that piece of junk from the Play Store, because it's damn malpractice at this point, given there are so many other options that don't straight-up swallow the TOTP keys

Re: What’s in a PR statement: LastPass breach explained

#149
post #114

Earlier quoted context omitted.

Please change your domain, looks like a phishing website. I would never clic on that anywhere else on the internet.

Clicking on a 'phishing' link can't hurt, and it's not like this person's website is ever going to be presented to you in a sensitive context (e.g. "download/install software from this site"). You should trust that your browser is secure enough to render random webpages. Excuse the self-promotion, but I take it that you're also too wary to click on this link to read my blog: https://dangerous.link/virus.exe

Your link is actually a great example. It's readable, you know what each part of the link is for (unless you're tech illiterate in which case just the readable quality is enough). And so by clicking it, I know I'll probably head to some page called Dangerous to see virus.exe.

Contrast that to a link like "password-man-comp.tool.win". Which at first glance can be confusing to most where the TLD is and where the subdomain is. Or like the above person's tool. Either go with something readable, even if long, or go with something short and clever. Combining both winds up looking suspicious to most people.

Which I guess is the funny part, the ones most harmed by a badly named website/link are genuine people wanting to provide a service to others, whereas malicious actors will likely use more effective (and less easily blocked) means of phishing.

Re: What’s in a PR statement: LastPass breach explained

#150

Assuming I'm a LastPass user and I have a sufficiently long master password with hardware based 2FA do I have anything to worry about? The one weak link is mobile authentication which bypasses 2FA. I honestly forget how that's configured.

A long password doesn't mean much by itself. If it has been previously leaked in a different breach, reused, is relatively easily brute-forced - then yes, you need to worry about that. The bigger problem is: even if you are safe right now, your vault is out there. If at any point your master password surfaces somewhere - all your accounts are instantly compromised. So the only sensible solution IMO is to start rotati…

To expand a little on your point - I don’t think 2FA is relevant once someone has your vault blob. 2FA only prevents them from acquiring the blob.
Post reply on HN