Live data from Hacker News

Last Pass Hacked

bloomberg.com

21–30 of 36 posts

Re: Last Pass Hacked

#21

Again? At this point, I would think the only people willing to use them are the people who don't keep up with this kind of news, which is a lot of people I guess.

I remember an early LastPass vulnerability exploiting a bug in URL regex parsing behavior of the LastPass browser extension. IIRC it basically gave RCE to any website in the browser extension context. That exploit is the reason I don’t use a browser extension for my password manager (which isn’t LastPass).

The tradeoff is basically copy/paste from password manager, vs input directly from browser extension. IMO, copy/paste clearly exposes the smaller attack surface, because it exposes max one password through the clipboard buffer (assuming no further chaining of exploits to escape extension or browser sandboxes). Whereas a browser extension must interface with the vault, which exposes potentially multiple passwords to compromise by methods only possible when the extension is installed.

(Incidentally, this logic might also explain the popular hesitancy of 1Password users to ~~upgrade~~ migrate to an electron version of the app.)

Re: Last Pass Hacked

#22
post #17

Earlier quoted context omitted.

Or KeePass/KeePassXC which requires no hosting and is also free.

Is there a convenient way to sync it across multiple devices?

Yeah, I just use Google Drive. I know Syncthing is also one option many people like.

Re: Last Pass Hacked

#23
post #13

Obligatory https://lock.cmpxchg8b.com/passmgrs.html#conclusion I don't follow the advice, and instead choose pass(1) with Yubikey touch-to-decrypt. Being offline, this removes a large attack surface.

Do you sync your passwords between devices?

Re: Last Pass Hacked

#24
post #23
post #13

Obligatory https://lock.cmpxchg8b.com/passmgrs.html#conclusion I don't follow the advice, and instead choose pass(1) with Yubikey touch-to-decrypt. Being offline, this removes a large attack surface.

Do you sync your passwords between devices?

No, my passwords are only on my desktop.

If I need to log into something on my phone, I have to be near my desktop.

I'd be happy to sync my passwords via git-over-ssh-over-wireguard if the need arose.

Re: Last Pass Hacked

#25
post #9

Earlier quoted context omitted.

Bitwarden should fit these requirements. It‘s also an all around much better product, in my experience.

Unfortunately 1Password is way better than Bitwarden from a usability perspective (autofill alone is a gamechanger).

Bitwarden has autofill

Re: Last Pass Hacked

#28
This is like the 4 or 5th time last pass has been hacked, or had a breach.

They might as well just shut down at this point, I can't imagine anyone but the uninformed would want to use them at this point.

Re: Last Pass Hacked

#29
post #3

I don't understand why anyone uses a proprietary password manager.

Them being proprietary means they can invest in marketing and UX and QA.

That's how you get a company of 500 employees to buy your product that "just works" in all browsers, operating systems and mobile devices over a free one that needs every single user to fiddle with a custom solution.

Spending $5 per user and month is way way way cheaper than wasting 1h of an employee's time even once.

Post reply on HN