How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
LastPass notifies users of yet another data breach
181–190 of 246 posts
Re: LastPass notifies users of yet another data breach
#182Note #1428 to self: Delete all data from LastPass already.
1password or Bitwarden is great alternative
Re: LastPass notifies users of yet another data breach
#183Earlier quoted context omitted.
This is why a lot of services have just moved to using email with magic links to log people in. In the end for a lot of services controlling your email is defacto controlling the login.
I am a vocal opponent to magic links via email (I am an unhinged person, in case it wasn't obvious before :) ). I NEVER log into my mail from my laptop/desktop. I access my email via my phone's mail app. So 1. try logging on via my laptop's browser 2. service sends a magic link to my email 3. click the link on my phone 4. now I'm logged in on my phone! not what I wanted!
Even though i understand your consideration of separating regular access and reset onto different devices, im am still more sceptical about smartphone security than anything else. What happens when someone gets access to your phone? They could redirect and use the magic mails too.
Re: LastPass notifies users of yet another data breach
#184Earlier quoted context omitted.
You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.
I put my passwords in Google Sheets temporarily. Then I moved them to 1Password, except the throwaway stuff. Google accounts aren’t immune to being compromised, so I agree that it’s not a good home for passwords (without even the need to invoke internal threats) — but it felt safer than LastPass. Which ought to be an embarrassment.
Re: LastPass notifies users of yet another data breach
#185Earlier quoted context omitted.
I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…
1Password checks all these boxes and hasn't yet had a data breach. Their biggest security hole is probably somewhere in the operational pipeline between 1P browser client developers and the static file servers hosting them.
Re: LastPass notifies users of yet another data breach
#186How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.
How does anyone trust ANY third party with all their passwords and encryption keys is beyond me. Setting up KeePassXC is trivial.
1. It has lots of features and complexity, but doesn't always convey affordances for common use cases to the user.
2. Some of the UI design feels very incrementally developed (naturally), and the implementation a bit quirky in parts.
(For one of many examples, when I had to do something involving adding TOTP secrets, once I found where to add them, I had to be careful in which sequence I clicked things, or it would just discard the secret I already put in the right place. If I hadn't been watching carefully, I might not have noticed immediately that it did this, and not been able to restore the secret before it was lost.)
Of course, in an ideal world, one would like to do a great holistic rethinking of the UI design (while preserving the data model), but that's a ton of work.
When advocating it to a "technical" person (who is not scared of, say, a legacy IDE), I would say it might do everything they need. When advocating to an ordinary user, I would look at their use cases, and see what they are going to see, and how confusing or quirky that might be for them.
Re: LastPass notifies users of yet another data breach
#187The companies responsible for these lapses of security should be paying, starting first with investors, then the C-suite. That'll put a stop to this negligence VERY quickly.
Re: LastPass notifies users of yet another data breach
#188I, like many others, wanted to move off of LP but was too lazy. So I just exported my passwords and put them into Google Sheets. While I have rotated many of those passwords (especially the important ones) and put them into a better password manager, there are several I haven't — and they've remained safer in Google Sheets than in LP. The lesson here is to get off of LP ASAP, you can figure out where to go later.
You put your passwords in Google Sheets? The data there is not encrypted at rest. Google has 191k employees in countries like China, India, and Pakistan who could potentially access your records. Make sure you use something that encrypts your data at rest, preferably on a device you own and control.
Re: LastPass notifies users of yet another data breach
#189Earlier quoted context omitted.
Unfortunately it's one of the most bug-ridden and unreliable pieces of software I've ever used. I encounter issues with it on a daily basis, but the burden of switching and a lack of superior options keeps me locked in.
I stopped paying them when they killed local valuts, and secondarily when then moved away from native apps. I drifted along on the old 7.x client for awhile with local values. I've more or less switched to apple keychain/passwords at this point. I need a solution for linux, and have been thinking about some kind of simple 1-way sync issue that dumps stuff from keychain into some other tool for use on linux.
Re: LastPass notifies users of yet another data breach
#190WTF is LastPasd doing, handing customer details to a market research company? Any such data should have been fully anonymized: no names, no specific addresses, etc.. For anyone looking for a recommendation: I use KeepassXC with Keepass2Android. Open source, with a local database that you can choose to sync (or not). I sync using Own cloud.