Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

171–180 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#171
This is ultimately a predictable outcome for any password manager that stores your credentials on someone else's server.

Just like they say in crypto "not your keys, not your crypto" - it applies here too. Not your storage, not your passwords.

KeePass on an airgapped box, or an encrypted hardware password manager with no network interfaces is best, though frankly, I'd even be more comfortable writing down passwords on paper (at home) than I would be storing them on someone else's server.

I say all this as a big tech red teamer, or, someone who breaches other people's servers for a living.

Re: The situation at LastPass may be worse than they are letting on

#172
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

[deleted]

Re: The situation at LastPass may be worse than they are letting on

#173
post #164
post #162

Earlier quoted context omitted.

> but it still feels like a net improvement to my overall online security. This is what I’m at on it too. Without cloud syncing convenience wins and we end up using simple passwords over and over again. With cloud syncing I believe we are much more secure than we would otherwise be.

The old 1Password, you could sync without cloud.

Yeah I tried that for ages. Was never seamless enough to get the whole family on board easily.

Especially across multiple users.

Re: The situation at LastPass may be worse than they are letting on

#174

This is ultimately a predictable outcome for any password manager that stores your credentials on someone else's server. Just like they say in crypto "not your keys, not your crypto" - it applies here too. Not your storage, not your passwords. KeePass on an airgapped box, or an encrypted hardware password manager with no network interfaces is best, though frankly, I'd even be more comfortable writing down passwords o…

The idea of using crypto wallets as canaries is an interesting one, however. I bet you could set that up to only be tripped by a major compromise.

And yes - there is basically no way to actually prove that your passwords on a server aren’t accessible to someone - especially if they can update software.

Re: The situation at LastPass may be worse than they are letting on

#175
post #81
post #76

This is quite interesting. A couple of weeks ago, I received an extortion phishing email, but it was directed to a secondary email address that hasn’t been previously compromised. It made it past Gmail’s spam and phishing filters into my inbox. Maybe a coincidence, but I guess every weird thing that happens is going to raise alarm bells. I was suspicious of the LastPass concept (storing passwords in a cloud app) when…

I’d love to hear the story about bypassing/resetting that 2FA setting? Sounds suspiciously like something that could be social engineered around by a sufficiently skilled attacker? I am very much of the opinion that if I fuck up my side of 2FA protection, the resources/accounts they’re protecting should be lost forever. (Or at the very least, a co-account holder might be able to reset some things, like my AWS IAM cre…

Any two factor that doesn’t require your firstborn or travelling in person to some frightening building to remove is basically a form of security theater. Most can be removed by support pretty easily just by asking.

Re: The situation at LastPass may be worse than they are letting on

#176

I’m skeptical of this. Seems like if it were true, we would be hearing the same thing from several other independent and credible sources.

I'm pretty sure every other time lastpass has had an incident that we've seen isolated stories like this.

Re: The situation at LastPass may be worse than they are letting on

#177

This is why Microsoft's requirement to drink a verification can was so genius. Imagine being a hacker and have to drink multiple verification cans to be able to proceed throughout multiple transactions. "Hacker dies from overdose due to ingestion of too much Doritos and Mountain Dew" https://imgur.com/dgGvgKF

It’s basically what modern ddos protection does - the WASM computational calculation is a digital dew can.

Re: The situation at LastPass may be worse than they are letting on

#179
post #125

Earlier quoted context omitted.

Additionally, 1Password makes the extra effort to never even send the URLs of your accounts to their servers. Even with their Watchtower service, which notifies you of breached accounts and websites that support 2-factor authentication, your passwords and website URLs are never sent to 1Password servers. https://support.1password.com/watchtower-privacy/

They still require that your vault be hosted by them though. Terrible policy.

Yup. Still pissed that 1Password removed the standalone option.
Post reply on HN