Live data from Hacker News

What’s in a PR statement: LastPass breach explained

palant.info

211–220 of 292 posts

Re: What’s in a PR statement: LastPass breach explained

#211

Earlier quoted context omitted.

> But migrating off is a HUGE pain It took less than 10mn to migrate to Bitwarden. What do you mean by migrate?

Moving passwords managers is easy, but if you assume LastPass lost your passwords you need to change every password.

But that isn't migrating, it's "changing all your passwords on all sites you use".

Even if you stayed on LastPass(!), you should still do that, right? It's a penalty for LastPass compromising them.

Re: What’s in a PR statement: LastPass breach explained

#212
post #177

Can someone point out a big flaw in my password management system? I have always felt kinda dumb for not using a PW manager but my system has worked for the last ~10+ years and I have never had any issues. I memorized a small function that takes the product name as input and spits out a password. it achieves the goal of having a unique pw for every service without having to write anything down (in software or on pape…

I used to do a similar thing, then I realized it was a potential problem. Let's say you have an account at AcmeCo. Let's say AcmeCo has a breach and I can see your password hash. Let's say the company uses a weak password hash (e.g. MD5), or no salt and it's easy to reference a rainbow table. From this rainbow table, I can look up your hash and see that your password is "lulzSecret2$AcmeCo". Now let's say you're in a…

Assume the function is a cryptographically appropriate hash function, you can reduce the risk of suggested attack to almost nil, considering the number of inputs you'd need for such attack

Re: What’s in a PR statement: LastPass breach explained

#213
post #193

Earlier quoted context omitted.

Migrating from LastPass to another password manager is actually a pretty easy process. Many password managers can import passwords from LastPass.

That's useless if you're migrating away because of security concerns. What you actually have to do is to go to all of the sites and change each of the passwords you have stored in LastPass.

As someone else - you should be doing this even if you're staying on lastpass.

It's what I've spent the last few days doing (hundreds of passwords), but then again, I'm also moving to bitwarden.

Re: What’s in a PR statement: LastPass breach explained

#214
post #19
post #6

I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database. Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ function…

Here is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPas…

If one uses an offline password manager then you want the stored passwords to be approximately as secure as memorized passwords. So how do you deal with emergency family access to memorized information in the deceased person's brain? Same deal.

Re: What’s in a PR statement: LastPass breach explained

#215

Earlier quoted context omitted.

> But migrating off is a HUGE pain It took less than 10mn to migrate to Bitwarden. What do you mean by migrate?

Moving passwords managers is easy, but if you assume LastPass lost your passwords you need to change every password.

In theory yes, but the risk associated every account is not equal.

Re: What’s in a PR statement: LastPass breach explained

#216

Earlier quoted context omitted.

I'm admittedly a hammer seeing everything as a nail, but as a designer, I see so many opportunities in FOSS lost to basic, unnecessary branding and usability oversights. Developers shouldn't expect themselves to be able to do good design work any more than designers should expect themselves to be able to make scalable, reliable, maintainable, production-ready code. It's a specialty for a reason! Incorporating designe…

> Developers shouldn't expect themselves to be able to do good design work Rude. People can learn to do multiple things without being pigeonholed, you know? > I see so many opportunities in FOSS lost to basic, unnecessary branding and usability oversights. It's FOSS. Feel free to contribute.

Speaking as someone who was mainly a "developer" for a while, one frequent problem I see from developers is that they assume they can excel at everything because they are good at coding. Since coding is a hard task that not everyone can do well, they think this talent applies to everything else.

Just a few weeks ago on here, there was a developer complaining about not getting any attention through his efforts on social media, and from what he said he did, it was easy to tell he did not know what he was doing and severely lacked the sophistication needed to succeed. Instead of paying for marketing, he decided to do it himself and was about to give up without even thinking about paying someone else to do it.

This is hubris that is commonly seen in developers.

Re: What’s in a PR statement: LastPass breach explained

#217
post #108

Earlier quoted context omitted.

More interesting to me is that this shouldn't be an issue, they should just lose out to the competition organically. And yet here we are.

Duopoly. Plus cost of switching away once you sign up. Network effects and monopolistic (anti-competitive) features allow bad companies to survive today. Monopolistic practices are probably a worse problem today than in the 1920s. In the 1920s governments used regulation to break up huge firms and defeat advantages due to cost of capital (hard to start a new railroad in the 20s because the cost of trains and tracks w…

All major browsers offer password management, then there's Apple Keychain, 1Password, KeePass, Bitwarden, and Lastpass. And that's just the ones I could think about while reading your comment.

Where is the the duopoly, and who's being forced out of the marketplace due to lack of government regulation of password managers?

Re: What’s in a PR statement: LastPass breach explained

#218

Earlier quoted context omitted.

I think the whole LastPass fiasco just shows why everyone wants to get into the SaaS business so bad - subscription revenue is the gift that keeps on giving. LastPass has proven they have no business safekeeping anyone else's credentials. Anyone who cares a modicum about their security will have migrated off. But migrating off is a HUGE pain (people will need hours to update hundreds of passwords), and LastPass's ann…

> But migrating off is a HUGE pain It took less than 10mn to migrate to Bitwarden. What do you mean by migrate?

Last time I migrated (many years ago), not all the data was in the export. And the secure notes especially were mostly missing or messed up.

I think others have posted on HN that they experienced the same last year when they attempted to migtate.

So you may have exported in 10m, but do not assume you got everything, go through the list and make sure everything is there (including verifying the contents).

Re: What’s in a PR statement: LastPass breach explained

#219
post #33

Why did people think that using a cloud based password manager (or for that matter: a closed source one) was ever a good idea?

This contributes nothing to the discussion, except giving you a reason to feel better than others for arbitrary reasons.

The gpost contributed to the discussion i am having with my kids, namely: avoid cloud-based pw storage. They're beginning to understand why, finally. We also discussed 'feeling better than others for arbitrary reasons '.

Re: What’s in a PR statement: LastPass breach explained

#220
post #55

It would be interesting to hear people’s life philosophy in this area. For me, lastpass always seemed like a bad idea as passwords are very important to me and giving someone else a copy of my passwords seems like a bad idea. Similarly, I don’t let any services know my bank passwords even if they super promise to protect them and not misuse them. Another similar seeming task that I can’t delegate is to read my bank s…

I would never put financial passwords in a cloud based password manager. Even if they do everything perfectly encryption-wise, no one can guarantee an attacker wouldn't alter the client-side code to leak your master password.

Having said that, it is still useful for less important logins like this website for example, where it isn't a big deal if someone manages to use the account.

However it is a huge privacy issue if people know what accounts you have. For example, I have a hackforums account and pretended to be a normal user there while only using it to scout attack vectors to patch. But to some people, they might assume that I was partaking in actual hacking which is not the case.

Post reply on HN