I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…
Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…
What’s in a PR statement: LastPass breach explained
141–150 of 292 posts
Re: What’s in a PR statement: LastPass breach explained
#142Earlier quoted context omitted.
Clicking on a 'phishing' link can't hurt, and it's not like this person's website is ever going to be presented to you in a sensitive context (e.g. "download/install software from this site"). You should trust that your browser is secure enough to render random webpages. Excuse the self-promotion, but I take it that you're also too wary to click on this link to read my blog: https://dangerous.link/virus.exe
Any URL on the web could host a browser exploit that requires no interaction beyond visiting, but if I had to guess which one were most likely to, I'd put phishing links up there. > You should trust that your browser is secure enough to render random webpages. I honestly don't. Is dangerous.link/virus.exe any more dangerous than nytimes.com? Probably not. However if some 0-day, no interaction browser exploit does exi…
Re: What’s in a PR statement: LastPass breach explained
#143I think we can do better in protecting vaults against offline brute force attacks. As written in the this post, 1Password uses a randomly generated "secret key" together with the user-chosen master password. This "secret key" is not stored on 1Password's servers, instead it should be printed on a piece of paper and stored safely. While this is a good starting point, it significantly reduces usability, since you need…
> since the e2ee does not depend on a user chosen master password. What's the story with "my phone went in the lake" using that setup?
Re: What’s in a PR statement: LastPass breach explained
#144I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…
Re: What’s in a PR statement: LastPass breach explained
#145Earlier quoted context omitted.
Have to plan ahead and have the keypass password in an envelope in the safe deposit box.
What else is in your self deposit box? I thought only rich people with gold and jewels and spies with fake passports and ready currency used safe deposit boxes.
I don't have one currently but perhaps I should.
Re: What’s in a PR statement: LastPass breach explained
#146Earlier quoted context omitted.
With KeePass, the trivial solution for this situation could just be a second subset database of relevant accounts on a thumb drive, with the password known to family individuals. That seems easier than relying on a cloud provider and some sort of half-baked insecure emergency access mode.
FYI, thumb drives die. The longest I’ve hand one work was about 7 years, more recent thumb drives tend to only last 3-4 years. For longevity a CD / DVD might last longer, but even then those are 30 years on average.
Re: What’s in a PR statement: LastPass breach explained
#147Earlier quoted context omitted.
Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…
Excuse me if this seems impolite, but is there a reason you need his passwords? Financial institutions have a very regulated pipeline for access of deceased accounts to relatives. And for personal email and stuff, well I think that should remain private unless the deceased explicitly wanted to share.
Re: What’s in a PR statement: LastPass breach explained
#148Earlier quoted context omitted.
> since the e2ee does not depend on a user chosen master password. What's the story with "my phone went in the lake" using that setup?
Since i use Google Authenticator for numerous services this is going to happen to me one day. So what I did was set it up on more than one phone.
Re: What’s in a PR statement: LastPass breach explained
#149Earlier quoted context omitted.
Please change your domain, looks like a phishing website. I would never clic on that anywhere else on the internet.
Clicking on a 'phishing' link can't hurt, and it's not like this person's website is ever going to be presented to you in a sensitive context (e.g. "download/install software from this site"). You should trust that your browser is secure enough to render random webpages. Excuse the self-promotion, but I take it that you're also too wary to click on this link to read my blog: https://dangerous.link/virus.exe
Contrast that to a link like "password-man-comp.tool.win". Which at first glance can be confusing to most where the TLD is and where the subdomain is. Or like the above person's tool. Either go with something readable, even if long, or go with something short and clever. Combining both winds up looking suspicious to most people.
Which I guess is the funny part, the ones most harmed by a badly named website/link are genuine people wanting to provide a service to others, whereas malicious actors will likely use more effective (and less easily blocked) means of phishing.
Re: What’s in a PR statement: LastPass breach explained
#150Assuming I'm a LastPass user and I have a sufficiently long master password with hardware based 2FA do I have anything to worry about? The one weak link is mobile authentication which bypasses 2FA. I honestly forget how that's configured.
A long password doesn't mean much by itself. If it has been previously leaked in a different breach, reused, is relatively easily brute-forced - then yes, you need to worry about that. The bigger problem is: even if you are safe right now, your vault is out there. If at any point your master password surfaces somewhere - all your accounts are instantly compromised. So the only sensible solution IMO is to start rotati…