Earlier quoted context omitted.
> You just have to deal with the very mild inconvenience of keeping your database synchronized across devices. Which is pretty easy with SyncThing. Other services like Dropbox are also fine if you have a sufficiently high entropy password. The danger isn't in the "online", but a third party being able to decrypt your passwords.
> Which is pretty easy with SyncThing Is SyncThing available for iOS? I thought it wasn’t but I’d love to be wrong.
Lastpass Security Incident
161–170 of 587 posts
Re: Lastpass Security Incident
#162Yubico hardware stuff does work with both Bitwarden and BitLocker
It's the solution I will be transitioning to at some point.
Note, GitHub requires 2-auth fall of 2023 in case anyone forgot.
Re: Lastpass Security Incident
#163Kudos to the CEO for disclosing this as it's happening and writing the post. This disclosure post is direct, forthright about what's known, specific about engaging help, and explicit about notifying people as more happens. Hacking sucks, but the CEO's post is IMHO on the right track.
Re: Lastpass Security Incident
#164> Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture. https://blog.lastpass.com/2022/11/notice-of-recent-security-...
Re: Lastpass Security Incident
#165Kudos to the CEO for disclosing this as it's happening and writing the post. This disclosure post is direct, forthright about what's known, specific about engaging help, and explicit about notifying people as more happens. Hacking sucks, but the CEO's post is IMHO on the right track.
Ridiculous take. Absolutely zero kudos because it was obvious to everyone that this was the most likely outcome way back in August. Back in August the company issued a bullshit statement that they'd ruled out that the intruder accessed customer data. Now they are saying they did lose customer data.
Re: Lastpass Security Incident
#166it's so baffling to me that people give ALL their password to a third party, commercial, organization...
Re: Lastpass Security Incident
#167And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…
I'd suggest using it in conjunction with Keepass2Android and KyPass(on iOS, someone mentioned Strongbox), although the Keepass2Android syncs and merges properly and the iOS does not.
Re: Lastpass Security Incident
#168And here I am still just using KeePass. I feel like passwords can be way too sensitive to entrust to a third party. Even if you can verify that it is secure, you could still find yourself in a jam if their service goes down or is otherwise inaccessible. You don't have to worry about any of this with a KeePass database. You just have to deal with the very mild inconvenience of keeping your database synchronized across…
I keep them local too, but I haven't found a solution on how to keep my laptop and phone in sync. It is not fun having to type a 30+ character password consisting uppercase+lowercase letters, numbers and special characters on a mobile device. But it has helped me to keep my phone clutter free, so maybe there's an upside to it too :)
Re: Lastpass Security Incident
#169it's so baffling to me that people give ALL their password to a third party, commercial, organization...
Re: Lastpass Security Incident
#170Earlier quoted context omitted.
I never pick a real answer to my security questions. It just seems pointlessly dangerous.
How do you keep track of phony answers to security questions if they are different for each site? If it is the same phony answer for every site, it is not any safer to use real answers to the security questions.