Lastpass Security Incident
181–190 of 587 posts
Re: Lastpass Security Incident
#182Never using online password manager is a good start. Only use encrypted local password manager preferably on encrypted file system and never use same passwords and emails. Best have seperate emails at least for the most important data. Also generating random 50+ alpha-numeric-symbols.
Easier said than done, sadly.
https://www.passwordstore.org/
There's even a decent Android client:
https://github.com/android-password-store/Android-Password-S...
Re: Lastpass Security Incident
#183Just a reminder: if you are deciding to migrate from LastPass to something else, the password export malfunctions for unknown reasons. If you have memos, it could be a character in the memo. You must make sure the exported CSV file has everything!
Re: Lastpass Security Incident
#184Keepassxc supports Yubikey, so you can lock it down strongly!
Re: Lastpass Security Incident
#185Is there a better cloud-based alternative to LastPass? I see KeePass being mentioned but I’m not interested in the keeping devices in sync myself.
Re: Lastpass Security Incident
#186What does the hacker news community think about Google Chrome's internal password manager?
The one where you can just launch chrome and click the eyeball icon to see what the password is? Or does chrome have something fancier I am not aware of?
Re: Lastpass Security Incident
#187Kudos to the CEO for disclosing this as it's happening and writing the post. This disclosure post is direct, forthright about what's known, specific about engaging help, and explicit about notifying people as more happens. Hacking sucks, but the CEO's post is IMHO on the right track.
Re: Lastpass Security Incident
#188Earlier quoted context omitted.
Most of them are build without having decrypted passwords or keys for them on server, so attacker would need to get to the point where they can craft malicious update to the client (or exploit the client)
1. Get access to build infrastructure (e.g. via supply chain attack) 2. Inject code in build to export user's passwords to remote server after update is installed
Re: Lastpass Security Incident
#189Re: Lastpass Security Incident
#190Great, now I'm going to have to rename my dog.
I never pick a real answer to my security questions. It just seems pointlessly dangerous.
A few years later after the semester break I forgot my password. I had to email IT to reset it, and they replied "Please provide the answer to your security question: Dicks?". And I had to reply "Yes no problem, the answer is Dicks". It was an awkward email exchange, but in my defence I had immediately remembered the answer so it served its purpose.