Live data from Hacker News

The situation at LastPass may be worse than they are letting on

twitter.com

21–30 of 436 posts

Re: The situation at LastPass may be worse than they are letting on

#21
post #19
post #11

Earlier quoted context omitted.

I'm not too worried because anything important that I have in LP is protected by 2fa. It's notable that the author says his accounts are protected by 2fa, but I don't understand how LP being hacked would allow an attacker to defeat that.

Just for your consideration, I'd bet good money that the 2FA only protects against login credential stuffing, but the vault data is only protected by your master password and can be attacked offline and indefinitely

I mean the individual accounts are protected by 2fa. I have an account or two where I know the password has been leaked but they're so unimportant that I can't be bothered to change the passwords. They still can't get in without my approval.

Re: The situation at LastPass may be worse than they are letting on

#22

Is there any reason to use these cloud based solutions when open source alternatives like KeepassXC is available?

Yeah: they’re cloud based. Your passwords get synced to all your devices automatically. That’s kinda the entire draw.

That and you get to centrally admin this for others (employees, family members), fine grained access controls for business use, you don't have to host and secure anything yourself (e.g. Bitwarden), pretty good UX on all your devices. I had to use a shared KeepassX file in git for a project and it was a frequent source of problems.

Re: The situation at LastPass may be worse than they are letting on

#23

If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?

Self-custody of keys. What's the point of trustless money if you trust someone with it?

Re: The situation at LastPass may be worse than they are letting on

#24

If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?

There's a step in between LP and an air-gapped setup, it's called "not uploading your keys to the internet".

Re: The situation at LastPass may be worse than they are letting on

#25

If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?

There's a step in between LP and an air-gapped setup, it's called "not uploading your keys to the internet".

Print out the seed phrase

Re: The situation at LastPass may be worse than they are letting on

#26
post #5

For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1] I haven't used LastPass in years, but the recent news made me wonder how Bitwar…

I wonder what 1password does

Re: The situation at LastPass may be worse than they are letting on

#28

If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?

I think lastpass is reputed to be bad compared to competitors like 1password. If you can’t secure your bike with a flimsy Kevlar belt, what’s left? A team of two armed guards?

Re: The situation at LastPass may be worse than they are letting on

#29

Earlier quoted context omitted.

There's a step in between LP and an air-gapped setup, it's called "not uploading your keys to the internet".

Print out the seed phrase

I handwrite them, stuff them in with a bunch of other handwritten notes and make it a bit less obvious that the words belong together as a phrase.

Re: The situation at LastPass may be worse than they are letting on

#30

this sort of thing is why I append the name of the website + a unique identifier + password, so that I don't have to bother changing my password during such nonsense, ugh.

Append it where?

e.g. password to facebook would be:

facebook.com$293MyPasswordYouKnowIt!!123

password to gmail would be

mail.google.com$113MyPasswordYouKnowIt!!123

only annoying thing is that the passwords are long. I guess it's secure, though.

edit: see child post for clarification. I do something above for spammy sites, but for something like gmail I probably wouldn't do that.

Post reply on HN