Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

161–170 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#161

I saw a class action filed. If the class is admitted I may opt out, I want compensation for each of the many hours I now have to spend rotating my hundreds of passwords. This is totally unacceptable.

You want compensation for rotating your passwords even though there is no evidence other than this random twitter thread that any of them are comprised?

Re: The situation at LastPass may be worse than they are letting on

#162
post #155
post #64

Having all your keys/passwords on a 3rd party server is something that I've never been willing to accept from a security standpoint. That's what always kept me from using a `hosted` solution. I do get the allure from a multi-user management aspect though.

FWIW. After using it at my previous workplace, I got a 1Password family account. It’s got my (not particularly technical) wife using unique strong passwords for all her online accounts and made family password sharing easy. I think the convenience of the cloud is key to this. I get that there’s a security risk that 1Password gets compromised and the app is infected with malware or there ends up being a vulnerability…

> but it still feels like a net improvement to my overall online security.

This is what I’m at on it too. Without cloud syncing convenience wins and we end up using simple passwords over and over again.

With cloud syncing I believe we are much more secure than we would otherwise be.

Re: The situation at LastPass may be worse than they are letting on

#163
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

Bitwarden, Keeper ($ but trusted at megacorps), and good ol' PasswordSafe are the safest solutions. I run BW with Yubikey 2FA and a local hosted sync server. KeePassX/C perhaps. Vault for secrets management. Never touched LastPass, 1Password or any of these other mickey-mouse commercial apps that invariably claim "military-grade encryption" or "unhackable" when their fundamental constructions are crap.

I do passwordsafe on google drive. I feel google does a good job w security / main risk a computer I’m using getting compromised

Re: The situation at LastPass may be worse than they are letting on

#164
post #162
post #155

Earlier quoted context omitted.

FWIW. After using it at my previous workplace, I got a 1Password family account. It’s got my (not particularly technical) wife using unique strong passwords for all her online accounts and made family password sharing easy. I think the convenience of the cloud is key to this. I get that there’s a security risk that 1Password gets compromised and the app is infected with malware or there ends up being a vulnerability…

> but it still feels like a net improvement to my overall online security. This is what I’m at on it too. Without cloud syncing convenience wins and we end up using simple passwords over and over again. With cloud syncing I believe we are much more secure than we would otherwise be.

The old 1Password, you could sync without cloud.

Re: The situation at LastPass may be worse than they are letting on

#166

I saw a class action filed. If the class is admitted I may opt out, I want compensation for each of the many hours I now have to spend rotating my hundreds of passwords. This is totally unacceptable.

You want compensation for rotating your passwords even though there is no evidence other than this random twitter thread that any of them are comprised?

Given the extent of the breach, it's prudent at this point to assume all passwords have been compromised.

Re: The situation at LastPass may be worse than they are letting on

#167
post #160

Best to just use pass ( https://www.passwordstore.org/ ) with your own gpg key rather than rely on any 3rd party service. Then set up a git repository on a (free) google cloud instance, (or even use github/gitlab), and you're set to sync your passwords to all your devices.

I like this idea. Have you tried setting this up on iOS?

Re: The situation at LastPass may be worse than they are letting on

#168
post #36
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

I feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable. It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak.

That assertion should be accepted even if you store your password offline.

Re: The situation at LastPass may be worse than they are letting on

#169
post #167
post #160

Best to just use pass ( https://www.passwordstore.org/ ) with your own gpg key rather than rely on any 3rd party service. Then set up a git repository on a (free) google cloud instance, (or even use github/gitlab), and you're set to sync your passwords to all your devices.

I like this idea. Have you tried setting this up on iOS?

Yes for me. On my iPad, using the Pass - Password Store app.

Re: The situation at LastPass may be worse than they are letting on

#170
post #167
post #160

Best to just use pass ( https://www.passwordstore.org/ ) with your own gpg key rather than rely on any 3rd party service. Then set up a git repository on a (free) google cloud instance, (or even use github/gitlab), and you're set to sync your passwords to all your devices.

I like this idea. Have you tried setting this up on iOS?

I have and it's fantastic:

https://apps.apple.com/us/app/pass-password-store/id12058205...

Post reply on HN