Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

181–190 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#181

Can someone point out a big flaw in my password management system? I have always felt kinda dumb for not using a PW manager but my system has worked for the last ~10+ years and I have never had any issues. I memorized a small function that takes the product name as input and spits out a password. it achieves the goal of having a unique pw for every service without having to write anything down (in software or on pape…

> Can someone point out a big flaw in my password management system?

The issue is that your passwords have almost zero entropy in them. The only guard is that others don't know your secret function. Password crackers are already programmed to handle functional password composition. You might want to ask yourself why pw crackers are programmed that way.

Re: What’s in a PR statement: LastPass breach explained

#182
post #39

Earlier quoted context omitted.

Seems like a great product, but something about the URL is reminiscent of those scammy websites that try to trick you into downloading scamware.

I'm admittedly a hammer seeing everything as a nail, but as a designer, I see so many opportunities in FOSS lost to basic, unnecessary branding and usability oversights. Developers shouldn't expect themselves to be able to do good design work any more than designers should expect themselves to be able to make scalable, reliable, maintainable, production-ready code. It's a specialty for a reason! Incorporating designe…

> Developers shouldn't expect themselves to be able to do good design work

Rude. People can learn to do multiple things without being pigeonholed, you know?

> I see so many opportunities in FOSS lost to basic, unnecessary branding and usability oversights.

It's FOSS. Feel free to contribute.

Re: What’s in a PR statement: LastPass breach explained

#183

I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers. https://password-manager.soft-wa.re/ At this point it's mainly a fork&merge of some previous work. If you find any issues with the data please submit a PR. Edit: I am standing on the shoulders of giants. Take a look at the contributor…

maybe one thing to add is "number of HN results above 50 points in the past 3 years" as a proxy for potential security issues

Re: What’s in a PR statement: LastPass breach explained

#184

Catastrophic breach after catastrophic breach since 2011. Lastpass has failed their fiduciary duty as a steward of sensitive information and IMO exhibited gross negligence in not encrypting URI data, ostensibly as a trade off for consumer functionality. not to be overly vindictive, as I understand the near impossibility of running a perfectly secure service at absolutely enormous scale…but does anyone else feel LastP…

More interesting to me is that this shouldn't be an issue, they should just lose out to the competition organically. And yet here we are.

Most economic models of equilibrium explicitly state that they model outcomes “in the long run” for precisely this type of a circumstance.

Should a firm with a history of these types of problems lose out to competition organically? Sure, but there is no binary “losing out tot he competition” switch that just gets flipped one day.

This is part of the reason why I get so frustrated with the laissez faire mindset/meme.

Re: What’s in a PR statement: LastPass breach explained

#185

Catastrophic breach after catastrophic breach since 2011. Lastpass has failed their fiduciary duty as a steward of sensitive information and IMO exhibited gross negligence in not encrypting URI data, ostensibly as a trade off for consumer functionality. not to be overly vindictive, as I understand the near impossibility of running a perfectly secure service at absolutely enormous scale…but does anyone else feel LastP…

> Lastpass has failed their fiduciary duty

I get where you're coming from, and ultimately agree. But I doubt anyone at LastPass on the business side agrees - to them this is just another PR snafu. The business continues to chug along regardless of how many catastrophic breaches they go through. I think they see these numerous issues as a cost of doing business vs. having a critical broken product offering.

Again I agree, but, I doubt they're going to change their ways this late in the game.

Re: What’s in a PR statement: LastPass breach explained

#186

Can someone point out a big flaw in my password management system? I have always felt kinda dumb for not using a PW manager but my system has worked for the last ~10+ years and I have never had any issues. I memorized a small function that takes the product name as input and spits out a password. it achieves the goal of having a unique pw for every service without having to write anything down (in software or on pape…

Can't reuse a previous password is a great signal of what your password actually is.

There are a lot of sites with dumb rules like can't be more than 8 characters (old WSDOT toll rule) or can't have symbols... So it doesn't always work.

Re: What’s in a PR statement: LastPass breach explained

#187
post #181

Can someone point out a big flaw in my password management system? I have always felt kinda dumb for not using a PW manager but my system has worked for the last ~10+ years and I have never had any issues. I memorized a small function that takes the product name as input and spits out a password. it achieves the goal of having a unique pw for every service without having to write anything down (in software or on pape…

> Can someone point out a big flaw in my password management system? The issue is that your passwords have almost zero entropy in them. The only guard is that others don't know your secret function. Password crackers are already programmed to handle functional password composition. You might want to ask yourself why pw crackers are programmed that way.

Taken in isolation they might have a ton of entropy, just not taken across leaked password databases.

Re: What’s in a PR statement: LastPass breach explained

#188
post #19

Earlier quoted context omitted.

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

Excuse me if this seems impolite, but is there a reason you need his passwords? Financial institutions have a very regulated pipeline for access of deceased accounts to relatives. And for personal email and stuff, well I think that should remain private unless the deceased explicitly wanted to share.

This is a place with significant cultural differences.

I can't imagine my parents wanting me to be locked out, and I can't imagine wanting my children to be locked out. Things like personal correspondence usually stop being private once someone is deceased, and indeed, are one of the few ways to get you know your ancestors.

I'm not American by birth, but I've lived in America long enough to understand both values. I don't think either way is better, but this strong emphasis on privacy (with family) is a very Western phenomenon. In most places, families have far fewer internal secrets.

What's especially odd is how much more Google and other corporations are allowed to know about Americans than families. For me, it's backwards.

Re: What’s in a PR statement: LastPass breach explained

#189
post #19

Earlier quoted context omitted.

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

That sounds like a huge anti-feature to me. The few services that a next-of-kin should realistically need access to (banking and... that's pretty much it) will already have a process in place for handling this. The rest of my accounts should die when I do.

All of our family pictures and videos are in a place that only I have the password to. If anyone wants anything, they come to me. That is another password I would want passed on. I also pay all the bills. My wife would need access to all of the utility accounts, the mortgage payment account, the credit card accounts, the insurance accounts, the retirement fund accounts, etc. There is way more than just banking.

Re: What’s in a PR statement: LastPass breach explained

#190

Catastrophic breach after catastrophic breach since 2011. Lastpass has failed their fiduciary duty as a steward of sensitive information and IMO exhibited gross negligence in not encrypting URI data, ostensibly as a trade off for consumer functionality. not to be overly vindictive, as I understand the near impossibility of running a perfectly secure service at absolutely enormous scale…but does anyone else feel LastP…

I think the whole LastPass fiasco just shows why everyone wants to get into the SaaS business so bad - subscription revenue is the gift that keeps on giving.

LastPass has proven they have no business safekeeping anyone else's credentials. Anyone who cares a modicum about their security will have migrated off. But migrating off is a HUGE pain (people will need hours to update hundreds of passwords), and LastPass's announcement just days before Christmas was obviously done so that your average Joe would just miss it.

So LastPass will be able to continue collecting subscription revenue from users who were too busy or just not paying attention to the news, despite the fact that they really should be giving refunds to everyone who depended on their service.

Post reply on HN