Live data from Hacker News

LastPass: Notice of Security Incident

blog.lastpass.com

21–30 of 141 posts

Re: LastPass: Notice of Security Incident

#21
For all of its warts, at least crypto has managed to come up with a clever little motto that correctly states the issue, in the form of "not your keys, not your crypto."

Putting your passwords in the hands of a third party drastically increases your threat surface and no amount of hand-wavy "but it's not as convenient" will change this fact.

Now, it may be true that the convenience factor is very strong right now, but the solution will never be "let's keep hoping real hard that the third parties are good at this." Not unless any of the third parties are willing to take on indemnification or liability.

The proper thing to do is to figure out how we can best empower people on their own. I know it's difficult, but that doesn't fundamentally cut into the fact that "this is what SHOULD be done."

Re: LastPass: Notice of Security Incident

#22
post #21

For all of its warts, at least crypto has managed to come up with a clever little motto that correctly states the issue, in the form of "not your keys, not your crypto." Putting your passwords in the hands of a third party drastically increases your threat surface and no amount of hand-wavy "but it's not as convenient" will change this fact. Now, it may be true that the convenience factor is very strong right now, bu…

My problem is that as an unskilled person - will I be any better at securing my own system?

Re: LastPass: Notice of Security Incident

#23
post #6

Suppose that LastPass is compromised. What can an attacker do? Passwords are encrypted, with keys on users’ side. Short of serving customers malicious JS code or an app to steal passwords, the production environment referred in the article can be made totally public, without secrets in vaults bring revealed, no?

I suppose you could phish people into leaking the master password

Maybe sneak in an altered copy of the LastPass app by offering it as a security update by email.

Re: LastPass: Notice of Security Incident

#24
post #21

For all of its warts, at least crypto has managed to come up with a clever little motto that correctly states the issue, in the form of "not your keys, not your crypto." Putting your passwords in the hands of a third party drastically increases your threat surface and no amount of hand-wavy "but it's not as convenient" will change this fact. Now, it may be true that the convenience factor is very strong right now, bu…

I find the saying very trite, but it's self evidently true - the cloud is just someone else's computer.

Re: LastPass: Notice of Security Incident

#25

I switched providers the last time this happened, or was it the one before that. Not a good look for an online password storage service.

Same, when I have to change my password for a service I know it's time to leave. Also it's so expensive €2.90/month to basically store text files. Office 365 is €7/month and includes 1TB of storage.

Re: LastPass: Notice of Security Incident

#26
post #21

For all of its warts, at least crypto has managed to come up with a clever little motto that correctly states the issue, in the form of "not your keys, not your crypto." Putting your passwords in the hands of a third party drastically increases your threat surface and no amount of hand-wavy "but it's not as convenient" will change this fact. Now, it may be true that the convenience factor is very strong right now, bu…

My problem is that as an unskilled person - will I be any better at securing my own system?

No, but there are easy-to-use, reliable and secure solutions, such as Bitwarden.

Re: LastPass: Notice of Security Incident

#28
post #21

For all of its warts, at least crypto has managed to come up with a clever little motto that correctly states the issue, in the form of "not your keys, not your crypto." Putting your passwords in the hands of a third party drastically increases your threat surface and no amount of hand-wavy "but it's not as convenient" will change this fact. Now, it may be true that the convenience factor is very strong right now, bu…

My problem is that as an unskilled person - will I be any better at securing my own system?

And my answer, as someone who doesn't work for a password company but is into this sort of thing, is "Yes, I believe one can be." -- or more precisely, "When you do it yourself, as opposed to a no-real-liability password company, you can get a better read on what the issues are."

Consider a classic "grandma" solution. A little notebook with good passwords kept in the purse or wallet. The issues here are more knowable than with LastPass or whatever.

Re: LastPass: Notice of Security Incident

#29
post #3
post #2

Not enough data to say what the impact of this is. Good for them disclosing it early while they investigate. > we have seen no evidence that this incident involved any access to customer data or encrypted password vaults. One way to prevent risk to your passwords in the event of a security breach is to not store them in the cloud at all. KeePass is great!

Most people use a work machine and a mobile device, so cloud syncing is absolutely necessary. LastPass and its competitors theoretically have zero-knowledge storage of everyone's passwords, so even a full breach of their servers would fail to leak passwords.

That "theoretically" is carrying significantly more water in this example than is smart to assume.

Re: LastPass: Notice of Security Incident

#30
post #12

Earlier quoted context omitted.

Yeah, again: all of this is great for you, but it doesn't change the fact that you are a very, very niche case. You can't just dismiss cloud syncing of passwords because you are the edge case who doesn't need it. > I keep a password database on the company network with all my work passwords and I have no need to keep a copy of those credentials on a bunch of my personal devices or cloud servers. That doesn't work for…

You've picked a strange subset of 'most' for the people you're imagining. They are savy enough to know what a password manager is, but not savy enough to deal with an offline one. Are you sure its not just a few people like you?

> They are savy enough to know what a password manager is, but not savy enough to deal with an offline one.

Not the person you responded to, but: I think that most people are savvy enough to know what a password manager is, and most people are not savvy enough to be interested in the work necessary to setup, personalize, and maintaining an offline password manager that functions well across multiple devices. That doesn't sound like a niche subset to me, but I could be way off.

Post reply on HN