Live data from Hacker News

LastPass notifies users of yet another data breach

9to5mac.com

191–200 of 246 posts

Re: LastPass notifies users of yet another data breach

#191

Sitting here with my KeepassX and being happy, again.

For folks new to the KeePass ecosystem, it’s KeePassXC[0] now. The original KeePass is still developed as well, however KeePassXC is a cross-platform updated version. [0] https://keepassxc.org/

I recently tried KeePassXC. It is very good overall. I am not moving to it however because:

1. I have a side screen that is merely 360 pixels in height. KeePassXC does not work fine on it. KeePass2 does.

2. KeePass2 remembers the names of custom fields added and allows picking from those for a new entry. KeePassXC does not.

Re: LastPass notifies users of yet another data breach

#193
post #55

Earlier quoted context omitted.

I think a lot of people use products like LastPass because it makes storing passwords easier. Works on mobile, computer, tablet. Pretty good experience tbh. With something like LastPass it's also much easier to create unique strong passwords for other sites. Also, let's be real: > The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, inc…

> I'm pretty sure 99% of the people on exposed have already had their names, phone numbers, email and physical addresses leaked already. This has nothing to do with the security of your passwords stored in LP. They have some CRM, some person from their 800 employees clicked a sketchy link and it leaked that. It's not good, but its hardly an indictment of their product or usefulness Would you be okay will a public dat…

my ssn (usa) and my credit info (also usa) was already leaked in a data breach. i don't care about my encrypted blob in lastpass being leaked because it's computationally too expensive to crack it (assuming it's not a targeted attack with hostile nation-state level gpu capacity)

Re: LastPass notifies users of yet another data breach

#194
post #147

I, like many others, wanted to move off of LP but was too lazy. So I just exported my passwords and put them into Google Sheets. While I have rotated many of those passwords (especially the important ones) and put them into a better password manager, there are several I haven't — and they've remained safer in Google Sheets than in LP. The lesson here is to get off of LP ASAP, you can figure out where to go later.

this is... such a bad idea lol

Re: LastPass notifies users of yet another data breach

#195

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

I think most people use password managers for convenience, not security.

Re: LastPass notifies users of yet another data breach

#197

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

Enterprise IT is all about outsourcing enterprise IT

nobody cares, there’s like 2 people whose job it is to care, one works for your company and one works for the third party IT company - and maybe your company’s General Counsel but even they just care that your CTO said they care

everyone else just has whatever enteprise service was presented to them

Re: LastPass notifies users of yet another data breach

#198
As much as the collective dumping on LastPass for yet another breach, and how they're totally irresponsible for handing customer data to some third party is amusing.

I think if people took a moment to actually look at what happened, they might realise that the story everyone has in their heads is quite different from reality.

Klue is one of those CRM services that so many sales teams are using. Yes, you have to hand them customer records (email of the customer contacts, finance teams, etc). That show Klue delivers it's "market intelligence" thing about that customer.

If you go to your sales teams and see what random stuff they have hooked up to your systems, I bet you will find similar things.

Whether or not this is a good idea (I firmly dislike it), this is how sales teams work these days. If you try to take it away you will be fighting the entire sales organisation.

I am more surprised that these breaches don't happen more often.

It doesn't impact LastPass's actual password databases.

(No affiliation with any of the entities involved in this)

Re: LastPass notifies users of yet another data breach

#199

As much as the collective dumping on LastPass for yet another breach, and how they're totally irresponsible for handing customer data to some third party is amusing. I think if people took a moment to actually look at what happened, they might realise that the story everyone has in their heads is quite different from reality. Klue is one of those CRM services that so many sales teams are using. Yes, you have to hand…

> I am more surprised that these breaches don't happen more often.

They do.

Re: LastPass notifies users of yet another data breach

#200

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

As others have pointed out, LastPass is often chose for compliance. Not for security.
Post reply on HN