Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

171–180 of 246 posts

Re: LastPass notifies users of yet another data breach

#171
post #124

Earlier quoted context omitted.

What's the solution? Don't have a CRM and store stuff about customers under lock and key? Don't give access to the CRM to any employees? More security training about clicking shady links? I don't get how you think some other competitor would be better suited against this threat. The right solution is to mitigate the damage. CRM has minimum available stuff, like names, addresses, etc. Don't keep stuff like payment inf…

> What's the solution? Use any of the other password managers that don't have the poor security history that LP do.

I think they're asking how LastPass is supposed to prevent this particular breach.

Re: LastPass notifies users of yet another data breach

#173

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

If you think I'm going to try and get my mom onto a different password manager, after it took literally ten years to migrate her away from the printed list in her purse...

A printed list in her purse has certain beneficial properties that a password manager does not.

Re: LastPass notifies users of yet another data breach

#174
post #111

I've been an Enpass user for years because I got a lifetime purchase for a good deal. They don't host the cloud services for syncing passwords. Instead you just auth your cloud storage (I use Google Drive) and it syncs to that. This approach seems better to me. For one thing, I'd already be screwed if someone malicious got into my Google account, probably worse than if they got into my password manager. And additiona…

How is that different from KeyPass for example?

As another happy Enpass user I don't think it is significantly different. The exception being that the KeePass frontends are really just as expensive as Enpass is now.

I also got a good deal on the lifetime pro membership before they moved to more of an annual model, which factors into my decision.

Which Keepass frontend do you use (if you use one on mobile)? Keepassium and Strongbox seem to be the ones that people talk about, but they are pricey too. I don't know anything about AuthPass, but I'm reluctant to use a free product; I'd rather use an inexpensive one, just to hopefully thwart supply chain attacks on that front.

Re: LastPass notifies users of yet another data breach

#175

Did lastpass also pull the dumbass 'no local vaults' move that 1password made? One of the nice things about a 'bring your own vault syncing' is that breaches like this don't have to mean a goddamned thing to you.

Not for this data, but in the past, yes - there is persistent pressure to do that for any maker of password managers, be it independent, in-browser or in-OS. (Source: I was a cofounder of a company that made a password manager as part of our product).

Re: LastPass notifies users of yet another data breach

#176

Earlier quoted context omitted.

If you think I'm going to try and get my mom onto a different password manager, after it took literally ten years to migrate her away from the printed list in her purse...

A printed list in her purse has certain beneficial properties that a password manager does not.

Similarly, it has certain deficits that a password manager does not.

Re: LastPass notifies users of yet another data breach

#177
post #16

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

A lot of people and orgs don't use security products for security. They use them for security theater. A vast majority of people, even many security people, will never hear about this breach. So LastPass still works great for them.

"We need to be able to answer an RFP that asks "do you have a comprehensive credential management system?"."

Just like a previous employer I had, on background checks. "We need to run one. We don't care what you did or didn't do, if you're doing good work for us. But some of our customers require that we have performed them."

Re: LastPass notifies users of yet another data breach

#178

Earlier quoted context omitted.

i'd love to switch from my lastpass family plan to... something else. but there is a non-trivial switching cost to migrate several people (with varying technical aptitudes) that each use several platforms. if 1password had a one-click migration flow they'd be able to win over a lot of converts.

You pretty much export your data from lastpass and import it into 1password. The only thing it doesn't do is have 1password log into your lastpass account and pull it out itself.

At least in the past the default import-export route did not move attachments, be careful!

Re: LastPass notifies users of yet another data breach

#179
I can see how any password manager can be safe. Especially from supply chain attacks. I use password safe on android, it writes an encrypted file locally. I'd really like to be able to flat seal the app to prevent network access. But I don't think android has such a feature.

Re: LastPass notifies users of yet another data breach

#180

Earlier quoted context omitted.

How good is their mobile and sync story?

These threads are always filled with keepass people who will tell you how great it is and not mention that you’re on your fucking own for you know Miner things like syncing or mobile use. I’m sure it works for many people to Dropbox their vault around anytime they want to access something and manually handle copies and sync. I’m not nearly so naive as to think that has any degree of success outside tech bubbled peopl…

[deleted]
Post reply on HN