Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

191–200 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#191
post #81

Earlier quoted context omitted.

I’d love to hear the story about bypassing/resetting that 2FA setting? Sounds suspiciously like something that could be social engineered around by a sufficiently skilled attacker? I am very much of the opinion that if I fuck up my side of 2FA protection, the resources/accounts they’re protecting should be lost forever. (Or at the very least, a co-account holder might be able to reset some things, like my AWS IAM cre…

Any two factor that doesn’t require your firstborn or travelling in person to some frightening building to remove is basically a form of security theater. Most can be removed by support pretty easily just by asking.

Why would support be in the business of removing it just because someone asks? If I needed it removed I could take a call at my official phone number and photograph my actual ID.

My cell provider requires a photo ID in person or a long pin not stored in the same place as other passwords in order to assign my number to a new phone and 2FA to access account.

This raises the bar from knowing my password to knowing my password, knowing my ID, producing a fake facsimile of my ID, stealing my pin from its encrypted container on my desktop, taking over my phone number, then taking over my account.

I don't have a pile of crypto to steal ergo this would be a LOT of work to send spam as me until my email gets flagged. It would be like a heist movie only with the target being the $40 in my wallet. mission impossible themesong begins playing

Basically support just needs to exercise reasonable caution when removing or changing it.

Re: The situation at LastPass may be worse than they are letting on

#192

Earlier quoted context omitted.

Append it where?

e.g. password to facebook would be: facebook.com$293MyPasswordYouKnowIt!!123 password to gmail would be mail.google.com$113MyPasswordYouKnowIt!!123 only annoying thing is that the passwords are long. I guess it's secure, though. edit: see child post for clarification. I do something above for spammy sites, but for something like gmail I probably wouldn't do that.

This scheme as described is not secure, but with one more step it can be. Luckily, that step has already been automated:

https://www.lesspass.com/

Re: The situation at LastPass may be worse than they are letting on

#193

Earlier quoted context omitted.

Bitwarden, Keeper ($ but trusted at megacorps), and good ol' PasswordSafe are the safest solutions. I run BW with Yubikey 2FA and a local hosted sync server. KeePassX/C perhaps. Vault for secrets management. Never touched LastPass, 1Password or any of these other mickey-mouse commercial apps that invariably claim "military-grade encryption" or "unhackable" when their fundamental constructions are crap.

I see a lot of people mentioning bitwarden around here; is their actually a technical reason to believe they are better than Lastpass or any of their competition (have they like open sourced all their stuff?). There’s very little room for failure and learning in the online password safe field, so I generally assume these companies are in one of two states: * has unknown bugs waiting to be revealed * out of business

BitWarden is open source with some freemium features. It's what I use at the moment. I believe it has third party network audits.

As far as I know it's fully E2E encrypted, and has never had a data breach.

The only thing I don't like is the lack of SMS based 2FA, although I appreciate their commitment to maximum security by not allowing it .

Re: The situation at LastPass may be worse than they are letting on

#194

This is why Microsoft's requirement to drink a verification can was so genius. Imagine being a hacker and have to drink multiple verification cans to be able to proceed throughout multiple transactions. "Hacker dies from overdose due to ingestion of too much Doritos and Mountain Dew" https://imgur.com/dgGvgKF

It’s basically what modern ddos protection does - the WASM computational calculation is a digital dew can.

Wait, so you're telling me that Cloudflare interstitial is running some PoW check on my client? I always thought that was just a way to let the user know they're being rate limited on Cloudflare's end.

Re: The situation at LastPass may be worse than they are letting on

#195

Earlier quoted context omitted.

By your example, your passwords are a set of fixed or knowable data, plus a unique identifier that in your examples is three characters long. Therefore knowing one of your passwords gives all except three characters of every other password, thus making your effective password length three characters (substitute the actual length of your unique identifier if it's more than three).

you're right - i have clarified what I actually do. however I do something similar with a different password for sites I deem unsafe, or spammy.

Sure, that's slightly better, but you're putting in quite a lot of effort for minimal reward - there still isn't much entropy here compared to the size of the password, and you're relying on security through obscurity (that no-one will work out your method). Password crackers on modern GPUs can chew through many millions of guesses per second so having such a significant leg up would likely make your strategy trivial to break.

Also plenty of perfectly respectable sites have been compromised in the past so your estimation about how safe the site is unfortunately doesn't help much.

I really think you'd be better off using long randomly-generated strings and keeping multiple backups of your password database. There are lots of options that don't put you in the hands of a third party. All (?) sites offer password reset facilities in case of emergency, and you could memorise your email account password so that you can always at least get into that.

Re: The situation at LastPass may be worse than they are letting on

#196
post #36
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

I feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable. It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak.

How hard is it to store encrypted data that needs a locally held master key to decrypt? Pick any industry... You'd have to be willfully ignorant or outright corrupt to fail your core business promise, wouldn't you?

Re: The situation at LastPass may be worse than they are letting on

#197
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

> safe and secure with end-to-end encryption for all Vault data, including website URLs

end-to-end encryption means something like https, it's a communication quality between trusted parties

https://www.ibm.com/topics/end-to-end-encryption

Re: The situation at LastPass may be worse than they are letting on

#198
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

> safe and secure with end-to-end encryption for all Vault data, including website URLs end-to-end encryption means something like https, it's a communication quality between trusted parties https://www.ibm.com/topics/end-to-end-encryption

I would hope not... that term should be reserved to indicate that the data is encrypted on one of your devices and is merely passed encrypted through their servers to your other devices.

Re: The situation at LastPass may be worse than they are letting on

#199

I saw a class action filed. If the class is admitted I may opt out, I want compensation for each of the many hours I now have to spend rotating my hundreds of passwords. This is totally unacceptable.

You wouldn't normally be compensated for your own time lost in a matter that didn't actually cost you money eg actual time not hypothetical time lost from work.

Re: The situation at LastPass may be worse than they are letting on

#200
post #160

Best to just use pass ( https://www.passwordstore.org/ ) with your own gpg key rather than rely on any 3rd party service. Then set up a git repository on a (free) google cloud instance, (or even use github/gitlab), and you're set to sync your passwords to all your devices.

That is way too much work. Doing work means stuff is happening and stuff means sidechannel attacks that someone else hasn't audited, because it's not an integrated product anyone would bother auditing.

In particular, I don't see how 2FA is possible with this, so shoulder surfing is a bigger issue.

I definitely trust Google or BitWarden more than a password I can memorize plus my own constant vigilance.

Post reply on HN