Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

181–190 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#181
post #3

It is difficult for me to believe that this could be true unless their web application has also been hacked. And if that were the case then this is really getting into criminal negligence territory (especially the way they've been disclosing it).

When I read their most recent email updating about the situation today or yesterday, I did get a definite chill down my spine. I've not used LP for a year or so, but my data (much of it now old) is still stored there, mainly left as a backup as I'd heard some people had some weird issues migrating to other password managers. I had made a mental note some months back when this first happened I should really go through…

LastPass allows you to delete your account without entering your master password. If their infa is compromised, you don't want to enter your master password to lastpast again it case the hacker planted something in lastpass' client code to snoop entered master password.

Re: The situation at LastPass may be worse than they are letting on

#182
post #64

Having all your keys/passwords on a 3rd party server is something that I've never been willing to accept from a security standpoint. That's what always kept me from using a `hosted` solution. I do get the allure from a multi-user management aspect though.

But you do not have the keys and passwords on that server. Only their encrypted forms. And the master password never leaves your machine(s), the sensitive bits are only decrypted locally.

This is reasonably safe, as long as you're careful with your master password, no different form GPG.

Re: The situation at LastPass may be worse than they are letting on

#183
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

Bitwarden, Keeper ($ but trusted at megacorps), and good ol' PasswordSafe are the safest solutions. I run BW with Yubikey 2FA and a local hosted sync server. KeePassX/C perhaps. Vault for secrets management. Never touched LastPass, 1Password or any of these other mickey-mouse commercial apps that invariably claim "military-grade encryption" or "unhackable" when their fundamental constructions are crap.

I see a lot of people mentioning bitwarden around here; is their actually a technical reason to believe they are better than Lastpass or any of their competition (have they like open sourced all their stuff?).

There’s very little room for failure and learning in the online password safe field, so I generally assume these companies are in one of two states:

* has unknown bugs waiting to be revealed

* out of business

Re: The situation at LastPass may be worse than they are letting on

#184
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

Bitwarden, Keeper ($ but trusted at megacorps), and good ol' PasswordSafe are the safest solutions. I run BW with Yubikey 2FA and a local hosted sync server. KeePassX/C perhaps. Vault for secrets management. Never touched LastPass, 1Password or any of these other mickey-mouse commercial apps that invariably claim "military-grade encryption" or "unhackable" when their fundamental constructions are crap.

When it comes to password management, trust should not even be a thing.

https://www.lesspass.com/

Re: The situation at LastPass may be worse than they are letting on

#185

Earlier quoted context omitted.

I don't know why, but I'm still a bit afraid of using security key everywhere. I have an irrational fear of losing/breaking my security key. Even though I know my phone is fine and always with me (as a comparison). I just set up a whole backup solution for my many self hosted applications, all encrypted with the keys safely in my password manager. Even uploaded to S3, because I figured if I'm paying for it, I could I…

One option is to have two identical security keys. In general, you can't easily read the secrets from an existing key, but you can overwrite/initialize them to get two with identical data.

Most services allow you to enrol two or more security keys, so you wouldn't need to overwrite one.

Re: The situation at LastPass may be worse than they are letting on

#186
post #167

Earlier quoted context omitted.

I like this idea. Have you tried setting this up on iOS?

I have and it's fantastic: https://apps.apple.com/us/app/pass-password-store/id12058205...

Maybe this is terrible logic but I would never trust an app that had 120 reviews and what appears to be a single person as the app owner with all my passwords.

Re: The situation at LastPass may be worse than they are letting on

#187

I’m skeptical of this. Seems like if it were true, we would be hearing the same thing from several other independent and credible sources.

I agree: LastPass has been hot garbage for many years but it still has a significant presence, some guy’s low-value crypto wallets would not be the first we hear about a compromise of LastPass vaults. There are entire companies using LastPass for critical systems. I absolutely believe it’s possible that LastPass has been compromised more than they’ve let on and I won’t be surprised if we eventually find out vaults ar…

This attitude is why a poor person will effectively be put in debtors prison and no one bats an eye. It requires "someone important" before people think maybe it actually happens.

Re: The situation at LastPass may be worse than they are letting on

#188
post #182
post #64

Having all your keys/passwords on a 3rd party server is something that I've never been willing to accept from a security standpoint. That's what always kept me from using a `hosted` solution. I do get the allure from a multi-user management aspect though.

But you do not have the keys and passwords on that server. Only their encrypted forms. And the master password never leaves your machine(s), the sensitive bits are only decrypted locally. This is reasonably safe, as long as you're careful with your master password, no different form GPG.

I'd still rather not let anyone have the encrypted versions of my keys/passwords. If the software is compromised then it's reasonable to consider the encrypted data can be brute forced with some time.

I'm not here to argue the merits of encryption. I understand it very well. I'm only considering my own levels of comfort and need to trust a 3rd party as well as pay a recurring fee to store my keys/passwords.

Re: The situation at LastPass may be worse than they are letting on

#189
post #167

Earlier quoted context omitted.

I like this idea. Have you tried setting this up on iOS?

I have and it's fantastic: https://apps.apple.com/us/app/pass-password-store/id12058205...

Does that work as a password manager provider that you can enable for iOS auto fill?

Re: The situation at LastPass may be worse than they are letting on

#190
post #36

Earlier quoted context omitted.

I feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable. It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak.

I definitely feel the opposing law works. When I see a project with a massive disclaimer about "this crypto is not audited, I'm a noob never deploy this anywhere" I'm likely to see better crypto than most of the commercial products I work with, including ones with sales people that talk about unbreakable crypto.

And likewise “military grade encryption” usually means “win2k Visual Basic backend”
Post reply on HN