Live data from Hacker News

LastPass requesting password reset after facing unknown anomaly

blog.lastpass.com

21–30 of 66 posts

Re: LastPass requesting password reset after facing unknown anomaly

#21
post #9

Suddenly, I'm glad I switched to 1Password.

Yeah 1Password is pretty awful when you consider the amount of features you get with LastPass like multi-factor authentication. 1Password relies on Dropbox. Your passwords are all stored on your computer. Granted they're in an encrypted format, but if you have a jerk for a room mate they could copy your encrypted files, key log your vault password, and have access to all your passwords. On the other hand, if you get…

Unfortunately, there's always potential security vulnerabilities: http://xkcd.com/538/

Re: LastPass requesting password reset after facing unknown anomaly

#22
post #16
post #14

Nice to see a company so transparent about situations which could easily have been hushed down.

I didn't think it was transparent at all. More like the minimum corpspeak required to inform their users that they should change their passwords Transparent would have been describing exactly what they saw

The blog post said that they detected traffic patterns in their network that they couldn't account for. They also said that they checked logs and checksums and found no intrusion yet.

So the post basically means: "we have no idea what's going on/went on, but here we are, informing you early. Here's the steps we have taken and here's the steps we are going to take"

You can't have everything: On one hand, everyone wants to be notified early (see playstation network breach), on the other hand, people want to know everything when they get the information.

I think that's asking a bit much. Either we get informed early ("we've seen something strange, but we have no idea what's going on") or you want all information ("we've discovered and researched a breach. here is what's happened", followed by a story that spans two weeks).

As lastpass contains potentially sensitive data, I'm happy they chose to inform early, even before they had a complete picture.

(disclaimer: I'm not using LastPass nor any other password manager as the risk of losing access to that and to all the services I used them with is too high for me)

Re: LastPass requesting password reset after facing unknown anomaly

#23
post #16
post #14

Nice to see a company so transparent about situations which could easily have been hushed down.

I didn't think it was transparent at all. More like the minimum corpspeak required to inform their users that they should change their passwords Transparent would have been describing exactly what they saw

What kind of additional information are you looking for that would be useful to you? Would be good to understand precisely what you're after.

Can you point out some examples of "corpspeak" in their notification?

Re: LastPass requesting password reset after facing unknown anomaly

#24
post #20

Earlier quoted context omitted.

And that, right there, highlights why all of my passwords aren't kept with their (or any) service - for many, it just introduced a single point of failure. Imagine being locked out of every website you have an account on, just like that. Nope. I'll make strong passwords on my own and encrypt my own copies, thanks.

just separately save your email password, all other services restore the password via email

Making your email password the weakest link...

Re: LastPass requesting password reset after facing unknown anomaly

#25
Interesting, it isn't prompting me to do any such thing.

Anyway, since many are mentioning 1Password - I used that for a couple years and switched to lastpass, because I was tired of having to install plugins across all the browsers on a platform and then having to find workarounds with Dropbox for syncing on additional machines and the lack of a Windows client, when I'm stuck working on Windows.

Also, since I use two-factor authentication, I wonder if that's the reason they have not asked me to change my password?

Re: LastPass requesting password reset after facing unknown anomaly

#26
post #11

That's not very smart considering that a lot of people won't be able to lockin to their email to verify their emails because they don't have access to the login details of their email because they haven't verified it. And why the hell didn't they use scrybt in the first place? For a company so paranoid, that seems to border on neglect.

LastPass make it pretty clear that your main email address is a point of recovery for your account. The two passwords I know are my LastPass master pass and my email password.

Re: LastPass requesting password reset after facing unknown anomaly

#27
post #15

Earlier quoted context omitted.

Yeah 1Password is pretty awful when you consider the amount of features you get with LastPass like multi-factor authentication. 1Password relies on Dropbox. Your passwords are all stored on your computer. Granted they're in an encrypted format, but if you have a jerk for a room mate they could copy your encrypted files, key log your vault password, and have access to all your passwords. On the other hand, if you get…

The there's somebody how can key log hardware you (think you can) trust, you're hosed whatever security you're relying on.

Negative, LastPass can generate one-time passwords which you can then use on computers you suspect to be insecure.

Re: LastPass requesting password reset after facing unknown anomaly

#29
post #16
post #14

Nice to see a company so transparent about situations which could easily have been hushed down.

I didn't think it was transparent at all. More like the minimum corpspeak required to inform their users that they should change their passwords Transparent would have been describing exactly what they saw

No, you're totally right.

This sounds exactly like the release we got from Sony a few weeks ago, detailing the points of entry, the volumes of data released from their servers, and estimates about who is and isn't affected. And who can forget when Sony told us all exactly what steps they were taking to make sure this wouldn't happen again?

/dumb

Post reply on HN