Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

181–190 of 246 posts

Re: LastPass notifies users of yet another data breach

#181

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

If the passwords are still not known, the "breach" is not a fail for the end user. If the master password to the vault is secure, and the only way to the vault is still only through the master password, it's still doing what the end user wants it to do. "Breach" is meaningless without qualifiers.

Re: LastPass notifies users of yet another data breach

#183
post #152

Earlier quoted context omitted.

This is why a lot of services have just moved to using email with magic links to log people in. In the end for a lot of services controlling your email is defacto controlling the login.

I am a vocal opponent to magic links via email (I am an unhinged person, in case it wasn't obvious before :) ). I NEVER log into my mail from my laptop/desktop. I access my email via my phone's mail app. So 1. try logging on via my laptop's browser 2. service sends a magic link to my email 3. click the link on my phone 4. now I'm logged in on my phone! not what I wanted!

Manually forward the magic mail to an address which you can use on your laptop/desktop for that purpose only.

Even though i understand your consideration of separating regular access and reset onto different devices, im am still more sceptical about smartphone security than anything else. What happens when someone gets access to your phone? They could redirect and use the magic mails too.

Re: LastPass notifies users of yet another data breach

#184
post #165

Earlier quoted context omitted.

You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.

I put my passwords in Google Sheets temporarily. Then I moved them to 1Password, except the throwaway stuff. Google accounts aren’t immune to being compromised, so I agree that it’s not a good home for passwords (without even the need to invoke internal threats) — but it felt safer than LastPass. Which ought to be an embarrassment.

your passwords are used to train LLMs now :3

Re: LastPass notifies users of yet another data breach

#185
post #55

Earlier quoted context omitted.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

1Password checks all these boxes and hasn't yet had a data breach. Their biggest security hole is probably somewhere in the operational pipeline between 1P browser client developers and the static file servers hosting them.

1P is open source now?

Re: LastPass notifies users of yet another data breach

#186
post #69

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.

KeePassXC might do what someone needs, and I really appreciate the work of its developers, but when advocating KeePassXC, I should also acknowledge that the "UX" is rough in parts:

1. It has lots of features and complexity, but doesn't always convey affordances for common use cases to the user.

2. Some of the UI design feels very incrementally developed (naturally), and the implementation a bit quirky in parts.

(For one of many examples, when I had to do something involving adding TOTP secrets, once I found where to add them, I had to be careful in which sequence I clicked things, or it would just discard the secret I already put in the right place. If I hadn't been watching carefully, I might not have noticed immediately that it did this, and not been able to restore the secret before it was lost.)

Of course, in an ideal world, one would like to do a great holistic rethinking of the UI design (while preserving the data model), but that's a ton of work.

When advocating it to a "technical" person (who is not scared of, say, a legacy IDE), I would say it might do everything they need. When advocating to an ordinary user, I would look at their use cases, and see what they are going to see, and how confusing or quirky that might be for them.

Re: LastPass notifies users of yet another data breach

#188
post #147

I, like many others, wanted to move off of LP but was too lazy. So I just exported my passwords and put them into Google Sheets. While I have rotated many of those passwords (especially the important ones) and put them into a better password manager, there are several I haven't — and they've remained safer in Google Sheets than in LP. The lesson here is to get off of LP ASAP, you can figure out where to go later.

You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.

Why those countries? Does google have weaker internal security for employees in those countries?

Re: LastPass notifies users of yet another data breach

#189

Earlier quoted context omitted.

Unfortunately it's one of the most bug-ridden and unreliable pieces of software I've ever used. I encounter issues with it on a daily basis, but the burden of switching and a lack of superior options keeps me locked in.

I stopped paying them when they killed local valuts, and secondarily when then moved away from native apps. I drifted along on the old 7.x client for awhile with local values. I've more or less switched to apple keychain/passwords at this point. I need a solution for linux, and have been thinking about some kind of simple 1-way sync issue that dumps stuff from keychain into some other tool for use on linux.

Curious if you have any gripes or concerns about using the Apple keychain/passwords setup. Aside from Apple devices, do you mostly also stick with Safari? Was it hard to transition things like TOTP or passkeys?

Re: LastPass notifies users of yet another data breach

#190

WTF is LastPasd doing, handing customer details to a market research company? Any such data should have been fully anonymized: no names, no specific addresses, etc.. For anyone looking for a recommendation: I use KeepassXC with Keepass2Android. Open source, with a local database that you can choose to sync (or not). I sync using Own cloud.

I've been using pwsafe for years. Also free and open source. Local-only vault. No cloud service to depend on that's going to incompetently lose your data. You can optionally store your vault in dropbox or iCloud drive, but why would you?
Post reply on HN