Earlier quoted context omitted.
I'm not too worried because anything important that I have in LP is protected by 2fa. It's notable that the author says his accounts are protected by 2fa, but I don't understand how LP being hacked would allow an attacker to defeat that.
Just for your consideration, I'd bet good money that the 2FA only protects against login credential stuffing, but the vault data is only protected by your master password and can be attacked offline and indefinitely
The situation at LastPass may be worse than they are letting on
21–30 of 436 posts
Re: The situation at LastPass may be worse than they are letting on
#22Is there any reason to use these cloud based solutions when open source alternatives like KeepassXC is available?
Yeah: they’re cloud based. Your passwords get synced to all your devices automatically. That’s kinda the entire draw.
Re: The situation at LastPass may be worse than they are letting on
#23If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?
Re: The situation at LastPass may be worse than they are letting on
#24If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?
Re: The situation at LastPass may be worse than they are letting on
#25If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?
There's a step in between LP and an air-gapped setup, it's called "not uploading your keys to the internet".
Re: The situation at LastPass may be worse than they are letting on
#26For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…
Re: The situation at LastPass may be worse than they are letting on
#27this sort of thing is why I append the name of the website + a unique identifier + password, so that I don't have to bother changing my password during such nonsense, ugh.
Re: The situation at LastPass may be worse than they are letting on
#28If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?
Re: The situation at LastPass may be worse than they are letting on
#29Earlier quoted context omitted.
There's a step in between LP and an air-gapped setup, it's called "not uploading your keys to the internet".
Print out the seed phrase
Re: The situation at LastPass may be worse than they are letting on
#30this sort of thing is why I append the name of the website + a unique identifier + password, so that I don't have to bother changing my password during such nonsense, ugh.
Append it where?
facebook.com$293MyPasswordYouKnowIt!!123
password to gmail would be
mail.google.com$113MyPasswordYouKnowIt!!123
only annoying thing is that the passwords are long. I guess it's secure, though.
edit: see child post for clarification. I do something above for spammy sites, but for something like gmail I probably wouldn't do that.